diff --git a/backend/app/agents/qa_agent.py b/backend/app/agents/qa_agent.py index e5eb9bc..8f8e623 100644 --- a/backend/app/agents/qa_agent.py +++ b/backend/app/agents/qa_agent.py @@ -3,8 +3,8 @@ from langchain_openai import ChatOpenAI from langchain_core.messages import SystemMessage, HumanMessage import httpx from app.core.config import settings -from app.schemas.qa_report import QAEvaluation -from app.llm.prompts import QA_AGENT_PROMPT +from app.schemas.qa_report import QAEvaluation, StructureEvaluation +from app.llm.prompts import QA_AGENT_PROMPT, QA_STRUCTURE_AGENT_PROMPT from app.sandbox.qa_client import run_project_qa logger = logging.getLogger(__name__) @@ -15,8 +15,9 @@ async_client = httpx.AsyncClient(verify=False) async def run_qa_agent(project_title: str, dev_output: dict) -> QAEvaluation: """ Agent QA : - Analyse le code généré à l'aide de l'API externe de la Sandbox (Semgrep uniquement) - et produit le rapport d'évaluation structuré final. + Analyse le code généré à l'aide de l'API externe de la Sandbox (Semgrep uniquement), + valide la structure minimale du projet à l'aide d'un second appel LLM, + puis produit le rapport d'évaluation fusionné. """ logger.info(f"[QA Agent] Début du processus d'audit statique pour le projet : {project_title}") @@ -39,12 +40,12 @@ async def run_qa_agent(project_title: str, dev_output: dict) -> QAEvaluation: http_async_client=async_client, ) - # 2. Exécution de l'analyse statique via le service Sandbox indépendant + # 1. Exécution de l'analyse statique via le service Sandbox indépendant try: repo_name = repo_url.rstrip("/").split("/")[-1] logger.info(f"[QA Agent] Envoi du dépôt '{repo_name}' au conteneur d'analyse statique...") - raw_results = await run_project_qa(repo_name=repo_name) + raw_results = await run_project_qa(repo_url=repo_url) logger.info(f"[QA Agent] 📊 Retour Sandbox Statis - Status : {'Succès' if raw_results.is_executable else 'Échec'}") logger.info(f"[QA Agent] 📊 Retour Sandbox - Nombre d'alertes de sécurité/qualité (Semgrep): {len(raw_results.issues)}") @@ -57,46 +58,84 @@ async def run_qa_agent(project_title: str, dev_output: dict) -> QAEvaluation: technical_feedback=[f"L'API de la sandbox a échoué : {type(e).__name__}: {str(e)}"] ) - # 3. Génération de l'évaluation finale via LLM - structured_llm = llm.with_structured_output(QAEvaluation, strict=True) - - messages = [ - SystemMessage(content=QA_AGENT_PROMPT), - ] - - # Le prompt est nettoyé des mentions relatives à l'exécution de tests dynamiques - user_content = f"PROJET À AUDITER : {project_title}\n" - user_content += f"LIEN DU DÉPÔT : {repo_url}\n" - user_content += f"RÉSULTATS DE L'ANALYSE STATIQUE DU CODE (Semgrep) :\n" - user_content += f"{raw_results.model_dump_json(indent=2)}\n\n" - user_content += "Analyse ces failles, vulnérabilités et défauts de qualité de code, puis génère ton évaluation de sécurité au format structuré demandé." - - messages.append(HumanMessage(content=user_content)) - + # 2. Premier appel LLM : Audit de sécurité (Semgrep) + qa_evaluation = None try: - qa_evaluation = await structured_llm.ainvoke(messages) - logger.info(f"[QA Agent] 📝 Justification du LLM : {qa_evaluation.global_summary}") + logger.info("[QA Agent] Lancement de l'audit de sécurité et de qualité (Semgrep)...") + structured_security_llm = llm.with_structured_output(QAEvaluation, strict=True) + + security_messages = [ + SystemMessage(content=QA_AGENT_PROMPT), + HumanMessage(content=( + f"PROJET À AUDITER : {project_title}\n" + f"LIEN DU DÉPÔT : {repo_url}\n" + f"RÉSULTATS DE L'ANALYSE STATIQUE DU CODE (Semgrep) :\n" + f"{raw_results.model_dump_json(indent=2)}\n\n" + f"Analyse ces failles, vulnérabilités et défauts de qualité de code, puis génère ton évaluation de sécurité au format structuré demandé." + )) + ] + + qa_evaluation = await structured_security_llm.ainvoke(security_messages) - if not qa_evaluation: - logger.error("[QA Agent] Le LLM a renvoyé une réponse vide (None).") - return QAEvaluation( - is_complete_and_safe=False, - global_summary="Erreur de formatage de l'évaluation par l'IA.", - technical_feedback=["L'évaluation automatique n'a pas pu être structurée correctement."] - ) - - if qa_evaluation.is_complete_and_safe: - logger.info(f"[QA Agent] ✅ Projet '{project_title}' VALIDÉ (Analyse statique propre).") - else: - reason = "Erreur d'exécution ou non-conformité" if "exit_code" in str(qa_evaluation) else "Failles de sécurité" - logger.warning(f"[QA Agent] ❌ Projet '{project_title}' REJETÉ ({reason}).") - - return qa_evaluation + except Exception as e: + logger.error(f"[QA Agent] ❌ Échec lors de l'audit de sécurité LLM : {type(e).__name__}: {str(e)}") + qa_evaluation = QAEvaluation( + is_complete_and_safe=False, + global_summary="Erreur lors de la génération du rapport de sécurité par le LLM.", + technical_feedback=[f"Le module de sécurité a échoué : {type(e).__name__}"] + ) + + # 3. Second appel LLM : Validation de la structure minimale (Arborescence) + structure_evaluation = None + try: + logger.info("[QA Agent] Lancement de l'audit de conformité de l'arborescence...") + structured_structure_llm = llm.with_structured_output(StructureEvaluation, strict=True) + + repo_structure = raw_results.runtime.stdout or "Arborescence non détectée ou vide." + + structure_messages = [ + SystemMessage(content=QA_STRUCTURE_AGENT_PROMPT), + HumanMessage(content=( + f"PROJET À ANALYSER : {project_title}\n" + f"ARBORESCENCE DU RÉPERTOIRE CLONÉ :\n" + f"{repo_structure}\n\n" + f"Vérifie si la structure respecte les exigences minimales et fournis ton évaluation structurée." + )) + ] + + structure_evaluation = await structured_structure_llm.ainvoke(structure_messages) + logger.info(f"[QA Agent] 📁 Structure détectée : {structure_evaluation.detected_language} | Valide : {structure_evaluation.is_valid}") except Exception as e: - logger.error(f"[QA Agent] ❌ Échec critique lors de l'analyse LLM : {type(e).__name__}: {str(e)}") - return QAEvaluation( - is_complete_and_safe=False, - global_summary="Erreur interne de l'Agent QA lors de la génération du rapport LLM.", - technical_feedback=[f"Le LLM a crashé avec l'erreur : {type(e).__name__}."] - ) \ No newline at end of file + logger.error(f"[QA Agent] ❌ Échec lors de la validation de structure LLM : {type(e).__name__}: {str(e)}") + structure_evaluation = StructureEvaluation( + is_valid=False, + detected_language="Inconnu", + missing_elements=["Erreur d'analyse structurelle"], + feedback="Le module d'analyse d'arborescence a rencontré une erreur de traitement." + ) + + # 4. Fusion des résultats des deux audits + final_is_complete_and_safe = qa_evaluation.is_complete_and_safe and structure_evaluation.is_valid + final_feedback = list(qa_evaluation.technical_feedback) + if not structure_evaluation.is_valid: + for missing in structure_evaluation.missing_elements: + final_feedback.append(f"[Structure] Élément obligatoire manquant : {missing}") + + final_summary = ( + f"{qa_evaluation.global_summary}\n\n" + f"--- 📁 Validation de la Structure ({structure_evaluation.detected_language}) ---\n" + f"Statut : {'Conforme' if structure_evaluation.is_valid else 'Non conforme'}\n" + f"Feedback : {structure_evaluation.feedback}" + ) + + if final_is_complete_and_safe: + logger.info(f"[QA Agent] ✅ Projet '{project_title}' VALIDÉ (Sécurité & Structure OK).") + else: + logger.warning(f"[QA Agent] ❌ Projet '{project_title}' REJETÉ (Non-conformité détectée).") + + return QAEvaluation( + is_complete_and_safe=final_is_complete_and_safe, + global_summary=final_summary, + technical_feedback=final_feedback + ) \ No newline at end of file diff --git a/backend/app/llm/prompts.py b/backend/app/llm/prompts.py index 8873ad5..0e9320c 100644 --- a/backend/app/llm/prompts.py +++ b/backend/app/llm/prompts.py @@ -436,4 +436,17 @@ Tu disposes des données brutes suivantes : ### Ton Style de Feedback : Sois ultra-précis et technique. Ne dis pas "Il y a une erreur dans le code", dis plutôt : "La fonction X à la ligne Y lève une exception de type ValueError car la variable Z est passée à None". Traduis chaque erreur technique brute en une instruction claire et actionnable pour l'Agent Dev. +""" + +QA_STRUCTURE_AGENT_PROMPT = """ +Tu es un agent expert en architecture et standardisation logicielle. +Ton rôle est d'analyser l'arborescence de fichiers d'un dépôt Git et de valider si la structure respecte rigoureusement les standards minimaux de livraison. + +Critères stricts d'un projet conforme : +1. DOCUMENTATION : Présence obligatoire d'un fichier de documentation (ex: README.md, README.txt). +2. DÉPENDANCES : Présence obligatoire d'un fichier de gestion des dépendances adapté au langage (ex: requirements.txt ou pyproject.toml pour Python, package.json pour Node, go.mod pour Go, cargo.toml pour Rust, etc.). Ce fichier doit exister à la racine, même s'il est vide. +3. POINT D'ENTRÉE : Un script principal ou fichier de démarrage cohérent (ex: main.py/app.py pour Python, index.js/server.js pour Node, main.go pour Go, etc.). +4. SUITE DE TESTS : Présence obligatoire d'un dossier dédié aux tests (généralement nommé 'tests' ou 'test') contenant au moins un script de test (ex: test_script.py, app.test.js, etc.). + +IMPORTANT : Sois intransigeant sur ces quatre piliers. Si le fichier de dépendances est absent (même si le script n'a pas de dépendances externes) ou si le dossier 'tests' est manquant ou vide, le projet doit être déclaré NON conforme (is_valid = False). """ \ No newline at end of file diff --git a/backend/app/sandbox/Dockerfile.qa b/backend/app/sandbox/Dockerfile.qa index 4d5ae98..139c2cc 100644 --- a/backend/app/sandbox/Dockerfile.qa +++ b/backend/app/sandbox/Dockerfile.qa @@ -3,7 +3,7 @@ FROM semgrep/semgrep:latest USER root RUN sed -i 's/https/http/g' /etc/apk/repositories && \ - apk update && apk add --no-cache python3 py3-pip + apk update && apk add --no-cache python3 py3-pip git RUN pip install --no-cache-dir \ --trusted-host pypi.org \ @@ -13,6 +13,10 @@ RUN pip install --no-cache-dir \ WORKDIR /app +# COPY r2c-security-audit.yaml /app/r2c-security-audit.yaml +COPY rules/ /app/rules/ +RUN sed -i 's/adjust_for_docker()/pass/g' /usr/lib/python3.12/site-packages/semgrep/commands/scan.py + COPY main.py . EXPOSE 8004 diff --git a/backend/app/sandbox/main.py b/backend/app/sandbox/main.py index b58623e..046a700 100644 --- a/backend/app/sandbox/main.py +++ b/backend/app/sandbox/main.py @@ -1,85 +1,179 @@ import subprocess import json import time -from fastapi import FastAPI +import tempfile +import os import logging +import traceback +from fastapi import FastAPI app = FastAPI() +logging.basicConfig(level=logging.INFO) logger = logging.getLogger(__name__) -SEMGREP_TIMEOUT = 300.0 -@app.post("/scan/{repo_name}") -async def scan_repository(repo_name: str): - repo_path = f"/src/{repo_name}" - issues_list = [] +SEMGREP_TIMEOUT = 300.0 +SEMGREP_RULES_DIR = "/app/rules/" + +def generate_tree_string(path: str, max_depth: int = 3) -> str: + """Génère une représentation visuelle de l'arborescence (exclut le bruit).""" + lines = [] + exclude_dirs = {".git", "__pycache__", "node_modules", "venv", ".venv", "env"} + + def _walk(current_path, depth): + if depth > max_depth: + return + try: + entries = sorted(os.listdir(current_path)) + except Exception: + return + + for entry in entries: + if entry in exclude_dirs or entry.startswith('.'): + continue + full_path = os.path.join(current_path, entry) + indent = " " * depth + if os.path.isdir(full_path): + lines.append(f"{indent}📁 {entry}/") + _walk(full_path, depth + 1) + else: + lines.append(f"{indent}📄 {entry}") + + _walk(path, 0) + return "\n".join(lines) + +@app.post("/scan") +async def scan_repository(repo_url: str): start_time = time.time() + issues_list = [] try: - secure_command = f"ulimit -f 10240 && semgrep scan --config=p/r2c-security-audit --json --quiet {repo_path}" - - result = subprocess.run( - secure_command, - shell=True, - capture_output=True, - text=True, - timeout=SEMGREP_TIMEOUT - ) - - duration = round(time.time() - start_time, 2) - exit_code = result.returncode - stderr_output = result.stderr - timeout_triggered = False - is_executable = True + # 1. CRÉATION DU DOSSIER TEMPORAIRE ET CLONAGE DU PROJET À SCANNER + with tempfile.TemporaryDirectory() as tmp_dir: + repo_path = os.path.join(tmp_dir, "repo") + logger.info(f"[Sandbox] Clonage dynamique du projet {repo_url} dans {repo_path}...") + + clone_cmd = f"git clone --depth 1 {repo_url} {repo_path}" + clone_result = subprocess.run(clone_cmd, shell=True, capture_output=True, text=True) + + if clone_result.returncode != 0: + logger.error(f"[Sandbox] Échec du git clone du projet : {clone_result.stderr}") + return { + "results": { + "is_executable": False, + "runtime": { + "exit_code": clone_result.returncode, + "stdout": "", + "stderr": f"Impossible de cloner le projet : {clone_result.stderr}", + "duration_seconds": round(time.time() - start_time, 2), + "timeout_triggered": False + }, + "issues": [] + } + } + + repo_tree = generate_tree_string(repo_path) + + try: + cloned_files = os.listdir(repo_path) + logger.info(f"[Sandbox] 📁 Fichiers récupérés après clone : {cloned_files}") + if not cloned_files or cloned_files == ['.git']: + logger.warning("[Sandbox] ⚠️ Le dossier cloné est vide (ou ne contient que .git) !") + except Exception as dir_err: + logger.error(f"[Sandbox] Impossible de lister le contenu du dossier cloné : {dir_err}") - except subprocess.TimeoutExpired as te: - logger.error(f"[Sandbox] Semgrep a dépassé le timeout sur {repo_name}") - duration = round(time.time() - start_time, 2) - exit_code = -1 - stderr_output = f"L'analyse statique a été coupée : Timeout de {SEMGREP_TIMEOUT}s dépassé." - timeout_triggered = True - is_executable = False + # 2. EXÉCUTION DE SEMGREP AVEC LA RÈGLE UNIQUE + try: + if os.path.exists(SEMGREP_RULES_DIR): + logger.info(f"[Sandbox] Répertoire de règles détecté : {SEMGREP_RULES_DIR}") + else: + logger.error(f"[Sandbox] ❌ Répertoire de règles introuvable à l'emplacement : {SEMGREP_RULES_DIR}") + + logger.info(f"[Sandbox] Lancement du scan Semgrep avec l'audit unique ({SEMGREP_RULES_DIR})...") + secure_command = f"semgrep scan --config={SEMGREP_RULES_DIR} --json --quiet ." + + result = subprocess.run( + secure_command, + shell=True, + cwd=repo_path, + capture_output=True, + text=True, + timeout=SEMGREP_TIMEOUT + ) + + duration = round(time.time() - start_time, 2) + exit_code = result.returncode + stderr_output = result.stderr + timeout_triggered = False + + except subprocess.TimeoutExpired: + logger.error("[Sandbox] Timeout Semgrep dépassé.") + return { + "results": { + "is_executable": False, + "runtime": { + "exit_code": -1, + "stdout": "", + "stderr": "L'analyse statique a dépassé le timeout global.", + "duration_seconds": round(time.time() - start_time, 2), + "timeout_triggered": True + }, + "issues": [] + } + } + + # 3. PARSING DES RÉSULTATS + try: + if result.returncode == 0: + is_executable = True + stdout_msg = f"Scan statique réussi.\n\n[STRUCTURE DETECTEE] :\n{repo_tree}" + if result.stdout.strip(): + scan_data = json.loads(result.stdout) + for item in scan_data.get("results", []): + issues_list.append({ + "tool": "Semgrep", + "file": item.get("path", "").replace(f"{repo_path}/", ""), + "line": item.get("start", {}).get("line"), + "code": item.get("check_id"), + "severity": item.get("extra", {}).get("severity", "MEDIUM").upper(), + "message": item.get("extra", {}).get("message", "") + }) + else: + is_executable = False + stdout_msg = f"Échec du moteur de scan Semgrep (Exit code {result.returncode})." + logger.error(f"[Sandbox] Semgrep a échoué ! Code: {result.returncode}\nSTDOUT: {result.stdout}\nSTDERR: {result.stderr}") + + except Exception as e: + is_executable = False + stdout_msg = "Erreur lors du traitement des résultats du scan." + stderr_output = f"Erreur parsing JSON Semgrep: {str(e)}\n{result.stderr}" + + return { + "results": { + "is_executable": is_executable, + "runtime": { + "exit_code": exit_code, + "stdout": stdout_msg, + "stderr": stderr_output, + "duration_seconds": duration, + "timeout_triggered": timeout_triggered + }, + "issues": issues_list + } + } + + except Exception as global_e: + error_trace = traceback.format_exc() + logger.error(f"[Sandbox] CRASH INTERNE CRITIQUE :\n{error_trace}") return { "results": { - "is_executable": is_executable, + "is_executable": False, "runtime": { - "exit_code": exit_code, - "stdout": "", - "stderr": stderr_output, - "duration_seconds": duration, - "timeout_triggered": timeout_triggered + "exit_code": -99, + "stdout": "Crash critique du conteneur de la Sandbox.", + "stderr": f"Exception Python : {str(global_e)}\n\nTraceback complet :\n{error_trace}", + "duration_seconds": round(time.time() - start_time, 2), + "timeout_triggered": False }, "issues": [] } - } - - try: - if result.stdout.strip(): - scan_data = json.loads(result.stdout) - for item in scan_data.get("results", []): - issues_list.append({ - "tool": "Semgrep", - "file": item.get("path", "").replace(f"{repo_path}/", ""), - "line": item.get("start", {}).get("line"), - "code": item.get("check_id"), - "severity": item.get("extra", {}).get("severity", "MEDIUM").upper(), - "message": item.get("extra", {}).get("message", "") - }) - is_executable = True - stderr_output = result.stderr - except Exception as e: - is_executable = False - stderr_output = f"Erreur parsing JSON Semgrep: {str(e)}\n{result.stderr}" - - return { - "results": { - "is_executable": is_executable, - "runtime": { - "exit_code": exit_code, - "stdout": "Scan statique universel effectué avec succès.", - "stderr": stderr_output, - "duration_seconds": duration, - "timeout_triggered": timeout_triggered - }, - "issues": issues_list - } - } \ No newline at end of file + } \ No newline at end of file diff --git a/backend/app/sandbox/qa_client.py b/backend/app/sandbox/qa_client.py index b7e53e4..1f09b50 100644 --- a/backend/app/sandbox/qa_client.py +++ b/backend/app/sandbox/qa_client.py @@ -4,23 +4,42 @@ from app.core.config import settings from app.schemas.qa_report import QARawResults, RuntimeOutput logger = logging.getLogger(__name__) - async_client = httpx.AsyncClient(verify=False) -async def run_project_qa(repo_name: str) -> QARawResults: +async def run_project_qa(repo_url: str) -> QARawResults: """ - Sollicite l'API du conteneur persistant arc-sandbox pour effectuer - une analyse de qualité et sécurité statique (Semgrep). + Sollicite l'API du conteneur arc-sandbox pour effectuer + une analyse de qualité et sécurité statique (Semgrep) en clonant le dépôt. """ - sandbox_url = f"http://arc-sandbox:8004/scan/{repo_name}" - logger.info(f"[QA Client] Envoi de la requête de scan à la sandbox : {sandbox_url}") + sandbox_url = "http://arc-sandbox:8004/scan" + logger.info(f"[QA Client] Envoi de la requête de scan pour le dépôt : {repo_url}") try: - response = await async_client.post(sandbox_url, timeout=120.0) + response = await async_client.post(sandbox_url, params={"repo_url": repo_url}, timeout=150.0) if response.status_code == 200: data = response.json() - return QARawResults.model_validate(data.get("results")) + + if data is None: + logger.error("[QA Client] ❌ La Sandbox a répondu 200 OK mais a renvoyé une réponse vide (null).") + return QARawResults( + is_executable=False, + runtime=RuntimeOutput( + exit_code=-1, + stdout="", + stderr="Erreur interne Sandbox : Réponse JSON vide.", + duration_seconds=0, + timeout_triggered=False + ), + issues=[] + ) + + results = data.get("results", {}) + if not results.get("is_executable"): + logger.error(f"[QA Client] ❌ Erreur interne Sandbox (Semgrep STDERR) : {results.get('runtime', {}).get('stderr')}") + + return QARawResults.model_validate(results) + else: logger.error(f"[QA Client] Erreur de la Sandbox (Status {response.status_code}): {response.text}") return QARawResults( diff --git a/backend/app/sandbox/rules/ci.yaml b/backend/app/sandbox/rules/ci.yaml new file mode 100644 index 0000000..cc5dcb3 --- /dev/null +++ b/backend/app/sandbox/rules/ci.yaml @@ -0,0 +1,10094 @@ +rules: +- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version + patterns: + - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; + - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; + - pattern-not: ssl_protocols TLSv1.2; + - pattern-not: ssl_protocols TLSv1.3; + - pattern: ssl_protocols ...; + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 + and TLS1.3; older versions are known to be broken and are susceptible to attacks. + Prefer use of TLSv1.2 or later. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ + category: security + technology: + - nginx + confidence: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + shortlink: https://sg.run/gLKy + semgrep.dev: + rule: + r_id: 9041 + rv_id: 1262676 + rule_id: WAUo9k + version_id: vdT06O4 + url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + origin: community +- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + shortlink: https://sg.run/J9yZ + semgrep.dev: + rule: + r_id: 9090 + rv_id: 1262916 + rule_id: PeUZ4X + version_id: YDTZeZB + url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + origin: community + message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This + creates a connection without encryption to a gRPC server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Instead, + establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' + function. You can create a create credentials using a ''tls.Config{}'' struct + with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' + languages: + - go + severity: ERROR + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + shortlink: https://sg.run/5Q5l + semgrep.dev: + rule: + r_id: 9091 + rv_id: 1262917 + rule_id: JDUy0B + version_id: 6xT2923 + url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + origin: community + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. + This allows for a connection without encryption to this server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Include + credentials derived from an SSL certificate in order to create a secure gRPC connection. + You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", + "cert.key")'. + languages: + - go + severity: ERROR + mode: taint + pattern-sinks: + - requires: OPTIONS and not CREDS + pattern: grpc.NewServer($OPT, ...) + - requires: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() +- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + shortlink: https://sg.run/Gej1 + semgrep.dev: + rule: + r_id: 9092 + rv_id: 1262919 + rule_id: 5rUOWQ + version_id: zyTb2bz + url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + origin: community + languages: + - go + severity: ERROR + patterns: + - pattern-either: + - pattern-inside: | + import "github.com/golang-jwt/jwt" + ... + - pattern-inside: | + import "github.com/dgrijalva/jwt-go" + ... + - pattern-either: + - pattern: | + jwt.SigningMethodNone + - pattern: jwt.UnsafeAllowNoneSignatureType +- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + message: '`MinVersion` is missing from this TLS configuration. By default, as of + Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications + should default to TLS 1.3 with all other protocols disabled. Only where it is + known that a web server must support legacy clients with unsupported an insecure + browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 + to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration + to bump the minimum version to TLS 1.3.' + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + shortlink: https://sg.run/oxEN + semgrep.dev: + rule: + r_id: 9116 + rv_id: 1262924 + rule_id: NbUk4X + version_id: 1QTypyp + url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern: | + tls.Config{ $...CONF } + - pattern-not: | + tls.Config{..., MinVersion: ..., ...} + fix: | + tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 } +- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, + SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + shortlink: https://sg.run/zvE1 + semgrep.dev: + rule: + r_id: 9117 + rv_id: 1262926 + rule_id: kxUkJ2 + version_id: yeTxpxj + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + origin: community + languages: + - go + severity: WARNING + fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered + weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. + See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other + cipher suites to use. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: HIGH + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + shortlink: https://sg.run/px8N + semgrep.dev: + rule: + r_id: 9118 + rv_id: 1262927 + rule_id: wdUJYk + version_id: rxTAKAZ + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} +- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + shortlink: https://sg.run/9oY4 + semgrep.dev: + rule: + r_id: 9123 + rv_id: 1262932 + rule_id: d8UjY3 + version_id: xyTjz8L + url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + rsa.GenerateKey(..., $BITS) + - pattern: | + rsa.GenerateMultiPrimeKey(..., $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 + - focus-metavariable: + - $BITS + fix: | + 2048 +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + message: Detected a network listener listening on 0.0.0.0 or an empty string. This + could unexpectedly expose the server publicly as it binds to all available interfaces. + Instead, specify another IP address that is not 0.0.0.0 nor the empty string. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: HIGH + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdE0 + semgrep.dev: + rule: + r_id: 9125 + rv_id: 1262939 + rule_id: nJUz3J + version_id: ExTExoK + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + origin: community + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) +- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + technology: + - java + - secrets + - jwt + category: security + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + shortlink: https://sg.run/RoDK + semgrep.dev: + rule: + r_id: 9149 + rv_id: 1262980 + rule_id: oqUeAn + version_id: d6Tyx8j + url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - pattern: | + (Algorithm $ALG) = $ALGO.$HMAC("$Y"); + - pattern: | + $SECRET = "$Y"; + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + - pattern: | + class $CLASS { + ... + $TYPE $SECRET = "$Y"; + ... + $RETURNTYPE $FUNC (...) { + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + ... + } + ... + } + - focus-metavariable: $Y + - metavariable-regex: + metavariable: $HMAC + regex: (HMAC384|HMAC256|HMAC512) +- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + shortlink: https://sg.run/Av14 + semgrep.dev: + rule: + r_id: 9150 + rv_id: 1262981 + rule_id: zdUkzR + version_id: ZRTKADq + url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + origin: community + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $JWT.sign(com.auth0.jwt.algorithms.Algorithm.none()); + - pattern: | + $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $JWT.sign($NONE); + - pattern: |- + class $CLASS { + ... + $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $RETURNTYPE $FUNC (...) { + ... + $JWT.sign($NONE); + ... + } + ... + } +- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + shortlink: https://sg.run/9o74 + semgrep.dev: + rule: + r_id: 9167 + rv_id: 1262989 + rule_id: d8UjJ3 + version_id: 3ZT4X2r + url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + origin: community + message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits + or more, or switch to use AES instead. + severity: WARNING + languages: + - java + patterns: + - pattern: | + $KEYGEN = KeyGenerator.getInstance("Blowfish"); + ... + $KEYGEN.init($SIZE); + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 128 +- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A + malicious actor could discern the difference between plaintext with valid or invalid + padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' + instead. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE + references: + - https://capec.mitre.org/data/definitions/463.html + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY + category: security + technology: + - java + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + shortlink: https://sg.run/ydxr + semgrep.dev: + rule: + r_id: 9168 + rv_id: 1262990 + rule_id: ZqU5oD + version_id: 44TEjbE + url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + origin: community + severity: WARNING + fix: | + "AES/GCM/NoPadding" + languages: + - java + patterns: + - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") + - pattern: | + "=~/.*\/CBC\/PKCS5Padding/" +- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context + shortlink: https://sg.run/4x7E + semgrep.dev: + rule: + r_id: 9188 + rv_id: 1263050 + rule_id: KxUb1k + version_id: 5PTo1rW + url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context + origin: community + message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL + versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") + for the best security. + severity: WARNING + languages: + - java + patterns: + - pattern-not: SSLContext.getInstance("TLSv1.3") + - pattern-not: SSLContext.getInstance("TLSv1.2") + - pattern: SSLContext.getInstance("...") + fix-regex: + regex: (.*?)\.getInstance\(.*?\) + replacement: \1.getInstance("TLSv1.2") +- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + message: DES is considered deprecated. AES is the recommended cipher. Upgrade to + use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + for more information. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + shortlink: https://sg.run/5Q73 + semgrep.dev: + rule: + r_id: 9191 + rv_id: 1262996 + rule_id: PeUZNg + version_id: A8TgdEn + url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") + - pattern-inside: $CIPHER.getInstance("DES") + - pattern-either: + - pattern: | + "=~/DES/.*/" + - pattern: | + "DES" + fix: | + "AES/GCM/NoPadding" + languages: + - java + - kt +- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended + cipher. Upgrade to use AES. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE + references: + - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + shortlink: https://sg.run/Geqn + semgrep.dev: + rule: + r_id: 9192 + rv_id: 1262997 + rule_id: JDUy8J + version_id: BjTkZyQ + url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $CIPHER.getInstance("=~/DESede.*/") + - pattern: | + $CRYPTO.KeyGenerator.getInstance("DES") + languages: + - java + - kt +- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + shortlink: https://sg.run/Ro9K + semgrep.dev: + rule: + r_id: 9193 + rv_id: 1262998 + rule_id: 5rUOb6 + version_id: DkTRbwL + url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + origin: community + message: Cipher in ECB mode is detected. ECB mode produces the same output for the + same input each time which allows an attacker to intercept and replay the data. + Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + severity: WARNING + languages: + - java + patterns: + - pattern: | + Cipher $VAR = $CIPHER.getInstance($MODE); + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* +- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + patterns: + - pattern-either: + - pattern: new NullCipher(...); + - pattern: new javax.crypto.NullCipher(...); + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + shortlink: https://sg.run/AvA4 + semgrep.dev: + rule: + r_id: 9194 + rv_id: 1263001 + rule_id: GdU7pw + version_id: K3TKkgB + url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + message: Initialization Vectors (IVs) for block ciphers should be randomly generated + each time they are used. Using a static IV means the same plaintext encrypts to + the same ciphertext every time, weakening the strength of the encryption. + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cwe.mitre.org/data/definitions/329.html + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + shortlink: https://sg.run/BkB5 + semgrep.dev: + rule: + r_id: 9195 + rv_id: 1263002 + rule_id: ReUgj1 + version_id: qkTR7vP + url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + byte[] $IV = { + ... + }; + ... + new IvParameterSpec($IV, ...); + - pattern: | + class $CLASS { + byte[] $IV = { + ... + }; + ... + $METHOD(...) { + ... + new IvParameterSpec($IV, ...); + ... + } + } +- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING + references: + - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + - kotlin + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + shortlink: https://sg.run/DoOj + semgrep.dev: + rule: + r_id: 9196 + rv_id: 1263003 + rule_id: AbUzoj + version_id: l4TJRpK + url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + origin: community + message: Using RSA without OAEP mode weakens the encryption. + severity: WARNING + languages: + - java + - kt + pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") +- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + metadata: + functional-categories: + - net::search::crypto-config::java.net + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + shortlink: https://sg.run/W8zA + semgrep.dev: + rule: + r_id: 9197 + rv_id: 1263008 + rule_id: BYUN3X + version_id: RGT0LEj + url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + origin: community + message: Detected use of a Java socket that is not encrypted. As a result, the traffic + could be read by an attacker intercepting the network traffic. Use an SSLSocket + created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. + severity: WARNING + languages: + - java + pattern-either: + - pattern: new ServerSocket(...) + - pattern: new Socket(...) +- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::key-length::java.security + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/4x6x + semgrep.dev: + rule: + r_id: 9200 + rv_id: 1263019 + rule_id: 0oU5P5 + version_id: o5TbDLY + url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern: | + KeyPairGenerator $KEY = $G.getInstance("RSA"); + ... + $KEY.initialize($BITS); + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) + in an AngularJS application could provide additional attack surface for XSS vulnerabilities. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + shortlink: https://sg.run/N4DG + semgrep.dev: + rule: + r_id: 9227 + rv_id: 1263094 + rule_id: EwU20Z + version_id: 5PTo1EW + url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern: | + $sceProvider.enabled(false); +- id: javascript.browser.security.open-redirect.js-open-redirect + message: The application accepts potentially user-controlled input `$PROP` which + can control the location of the current window context. This can lead two types + of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript + URIs. It is recommended to validate user-controllable input before allowing it + to control the redirection. + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.1 Insecue Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + version: '4' + category: security + confidence: HIGH + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + technology: + - browser + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect + shortlink: https://sg.run/3xRe + semgrep.dev: + rule: + r_id: 9243 + rv_id: 1263122 + rule_id: WAUopl + version_id: pZT03x0 + url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + new URLSearchParams($WINDOW. ... .location.search).get('...') + - pattern: | + new URLSearchParams(location.search).get('...') + - pattern: | + new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') + - pattern: | + new URLSearchParams(location.hash.substring(1)).get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.hash.substring(1)) + ... + - pattern: $PROPS.get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URL($WINDOW. ... .location.href) + ... + - pattern-inside: | + $PROPS = new URL(location.href) + ... + - pattern: $PROPS.searchParams.get('...') + - patterns: + - pattern-either: + - pattern: | + new URL($WINDOW. ... .location.href).searchParams.get('...') + - pattern: | + new URL(location.href).searchParams.get('...') + pattern-sinks: + - patterns: + - pattern-either: + - pattern: location.href = $SINK + - pattern: $THIS. ... .location.href = $SINK + - pattern: location.replace($SINK) + - pattern: $THIS. ... .location.replace($SINK) + - pattern: location = $SINK + - pattern: $WINDOW. ... .location = $SINK + - focus-metavariable: $SINK + - metavariable-pattern: + patterns: + - pattern-not: | + "..." + $VALUE + - pattern-not: | + `...${$VALUE}` + metavariable: $SINK +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + shortlink: https://sg.run/Do1d + semgrep.dev: + rule: + r_id: 9252 + rv_id: 1263166 + rule_id: pKUOjy + version_id: pZT03Q0 + url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern-inside: | + import $JWT from 'express-jwt'; + ... + - pattern-inside: | + import * as $JWT from 'express-jwt'; + ... + - pattern-inside: | + import { ..., $JWT, ... } from 'express-jwt'; + ... + - pattern-either: + - pattern: | + $JWT({...,secret: "$Y",...},...) + - pattern: | + $OPTS = "$Y"; + ... + $JWT({...,secret: $OPTS},...); + - focus-metavariable: $Y +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/Ro1g + semgrep.dev: + rule: + r_id: 9293 + rv_id: 1263182 + rule_id: JDUyRl + version_id: d6TyxbX + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JOSE = require("jose"); + ... + - pattern-either: + - pattern-inside: | + var {JWT} = $JOSE; + ... + - pattern-inside: | + var {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + const {JWT} = $JOSE; + ... + - pattern-inside: | + const {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + let {JWT} = $JOSE; + ... + - pattern-inside: | + let {JWK, JWT} = $JOSE; + ... + - pattern-either: + - pattern: | + JWT.verify($P, "...", ...); + - pattern: | + JWT.sign($P, "...", ...); + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: | + $JWT.sign($P, JWK.asKey("..."), ...); + options: + symbolic_propagation: true + interfile: true +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + shortlink: https://sg.run/AvRL + semgrep.dev: + rule: + r_id: 9294 + rv_id: 1263183 + rule_id: 5rUOGN + version_id: ZRTKAyb + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern-either: + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + var $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + JWT.verify($P, JWK.None,...); +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - javascript + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/4xN9 + semgrep.dev: + rule: + r_id: 9300 + rv_id: 1263189 + rule_id: WAUon7 + version_id: gETB75D + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,"...",...); + - pattern-inside: | + $JWT.verify($DATA,"...",...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $JWT = require("jsonwebtoken") + ... + - pattern-inside: | + import $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import * as $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import {...,$JWT,...} from "jsonwebtoken" + ... + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,$VALUE,...); + - pattern-inside: | + $JWT.verify($DATA,$VALUE,...); + - focus-metavariable: $VALUE +- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - nodejs + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + shortlink: https://sg.run/vz70 + semgrep.dev: + rule: + r_id: 9333 + rv_id: 1263225 + rule_id: QrUzq6 + version_id: X0TzyoE + url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + {..., clientSecret: "...", ...} + - pattern: | + {..., secretOrKey: "...", ...} + - pattern: | + {..., consumerSecret: "...", ...} + - patterns: + - pattern-inside: | + $OBJ = {} + ... + - pattern-either: + - pattern: | + $OBJ.clientSecret = "..." + - pattern: | + $OBJ.secretOrKey = "..." + - pattern: | + $OBJ.consumerSecret = "..." + - pattern: $OBJ + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern: | + {..., clientSecret: $SECRET, ...} + - pattern: | + {..., secretOrKey: $SECRET, ...} + - pattern: | + {..., consumerSecret: $SECRET, ...} + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern-inside: | + $VALUE = {..., clientSecret: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., secretOrKey: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., consumerSecret: $SECRET, ...} + ... + - pattern: $VALUE + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $F = require("$I").Strategy + ... + - pattern-inside: | + $F = require("$I") + ... + - pattern-inside: | + import { $STRAT as $F } from '$I' + ... + - pattern-inside: | + import $F from '$I' + ... + - metavariable-regex: + metavariable: $I + regex: (passport-.*) + - pattern-inside: | + new $F($VALUE,...) + - focus-metavariable: $VALUE +- id: php.lang.security.assert-use.assert-use + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + - patterns: + - pattern: | + Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... }) + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern: assert($SINK, ...); + - pattern-not: assert("...", ...); + - pattern: $SINK + message: Calling assert with user input is equivalent to eval'ing. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + references: + - https://www.php.net/manual/en/function.assert + - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php + category: security + technology: + - php + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use + shortlink: https://sg.run/3xXW + semgrep.dev: + rule: + r_id: 9387 + rv_id: 1263272 + rule_id: DbUpjk + version_id: 9lT4bLx + url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use + origin: community + languages: + - php + severity: ERROR +- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + message: Running flask app with host 0.0.0.0 could expose the server publicly. + metadata: + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - flask + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + shortlink: https://sg.run/eLby + semgrep.dev: + rule: + r_id: 9532 + rv_id: 1263414 + rule_id: L1Uy1n + version_id: BjTkZOY + url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + origin: community + languages: + - python + severity: WARNING + pattern-either: + - pattern: app.run(..., host="0.0.0.0", ...) + - pattern: app.run(..., "0.0.0.0", ...) +- id: python.flask.security.audit.debug-enabled.debug-enabled + patterns: + - pattern-inside: | + import flask + ... + - pattern: $APP.run(..., debug=True, ...) + message: Detected Flask app with debug=True. Do not deploy to production with this + flag enabled as it will leak sensitive information. Instead, consider using Flask + configuration variables or setting 'debug' using system environment variables. + metadata: + cwe: + - 'CWE-489: Active Debug Code' + owasp: A06:2017 - Security Misconfiguration + references: + - https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ + category: security + technology: + - flask + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled + shortlink: https://sg.run/dKrd + semgrep.dev: + rule: + r_id: 9534 + rv_id: 946206 + rule_id: gxU1bd + version_id: 8KTKjwR + url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled + origin: community + severity: WARNING + languages: + - python +- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + shortlink: https://sg.run/l2E9 + semgrep.dev: + rule: + r_id: 9557 + rv_id: 1263452 + rule_id: X5U8P5 + version_id: PkTR3X3 + url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + origin: community + patterns: + - pattern: | + jwt.encode($_, "...", ...) + languages: + - python + severity: ERROR +- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose + the server publicly as it binds to all available interfaces. Consider instead + getting correct address from an environment variable or configuration file. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - python + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdln + semgrep.dev: + rule: + r_id: 9669 + rv_id: 1263505 + rule_id: OrU3og + version_id: 0bTKzDL + url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + origin: community + languages: + - python + severity: INFO + pattern-either: + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("0.0.0.0", ...)) + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("::", ...)) + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("", ...)) +- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + message: Detected an insufficient key size for DSA. NIST recommends a key size of + 2048 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://www.pycryptodome.org/src/public_key/dsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + shortlink: https://sg.run/4y8l + semgrep.dev: + rule: + r_id: 9688 + rv_id: 1263554 + rule_id: AbUWje + version_id: JdTzxbQ + url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + origin: community + options: + symbolic_propagation: true + languages: + - python + severity: WARNING + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.DSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 +- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + message: Detected an insufficient key size for RSA. NIST recommends a key size of + 3072 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://www.pycryptodome.org/src/public_key/rsa#rsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/PprY + semgrep.dev: + rule: + r_id: 9689 + rv_id: 1263555 + rule_id: BYUBWe + version_id: 5PTo1jL + url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + options: + symbolic_propagation: true + languages: + - python + severity: WARNING + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.RSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 3072 +- id: ruby.lang.security.force-ssl-false.force-ssl-false + message: Checks for configuration setting of force_ssl to false. Force_ssl forces + usage of HTTPS, which could lead to network interception of unencrypted application + traffic. To fix, set config.force_ssl = true. + metadata: + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false + shortlink: https://sg.run/YgkW + semgrep.dev: + rule: + r_id: 9714 + rv_id: 1263605 + rule_id: 2ZU4lx + version_id: WrTqKB3 + url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false + origin: community + languages: + - ruby + severity: WARNING + pattern: config.force_ssl = false + fix-regex: + regex: =\s*false + replacement: = true +- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + patterns: + - pattern-inside: | + class $CONTROLLER < ApplicationController + ... + http_basic_authenticate_with ..., :password => "$SECRET", ... + end + - focus-metavariable: $SECRET + message: Detected hardcoded password used in basic authentication in a controller + class. Including this password in version control could expose this credential. + Consider refactoring to use environment variables or configuration files. + severity: WARNING + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown + category: security + technology: + - ruby + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + shortlink: https://sg.run/6r0w + semgrep.dev: + rule: + r_id: 9715 + rv_id: 1263606 + rule_id: X5UZWK + version_id: 0bTKzNK + url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + origin: community + languages: + - ruby +- id: yaml.docker-compose.security.privileged-service.privileged-service + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + $SERVICE: + ... + privileged: $TRUE + - focus-metavariable: $TRUE + - metavariable-regex: + metavariable: $TRUE + regex: (true) + fix: | + false + message: Service '$SERVICE' is running in privileged mode. This grants the container + the equivalent of root capabilities on the host machine. This can lead to container + escapes, privilege escalation, and other security concerns. Remove the 'privileged' + key to disable this capability. + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html + - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ + category: security + technology: + - docker-compose + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service + shortlink: https://sg.run/AlX0 + semgrep.dev: + rule: + r_id: 10006 + rv_id: 1263922 + rule_id: DbUW17 + version_id: 0bTKzXZ + url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service + origin: community + languages: + - yaml + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + category: security + technology: + - .net + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + shortlink: https://sg.run/ZeXW + semgrep.dev: + rule: + r_id: 11135 + rv_id: 1262635 + rule_id: bwUOjK + version_id: nWT2LGp + url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + origin: community + message: The BinaryFormatter type is dangerous and is not recommended for data processing. + Applications should stop using BinaryFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. BinaryFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Binary; + ... + - pattern: | + new BinaryFormatter(); +- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + metadata: + functional-categories: + - crypto::search::randomness::javax.crypto + cwe: + - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' + category: security + source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM + technology: + - java + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + shortlink: https://sg.run/Dww2 + semgrep.dev: + rule: + r_id: 11908 + rv_id: 1263000 + rule_id: GdUZZ3 + version_id: 0bTKzGk + url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + origin: community + languages: + - java + message: 'GCM IV/nonce is reused: encryption can be totally useless' + patterns: + - pattern-either: + - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); + - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., + $NONCE, ...); + severity: ERROR +- id: javascript.lang.security.audit.code-string-concat.code-string-concat + message: Found data from an Express or Next web request flowing to `eval`. If this + data is user-controllable this can lead to execution of arbitrary system commands + in the context of your application process. Avoid `eval` whenever possible. + options: + interfile: true + metadata: + interfile: true + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval + - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback + - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ + - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html + category: security + technology: + - node.js + - Express + - Next.js + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat + shortlink: https://sg.run/96Yk + semgrep.dev: + rule: + r_id: 13023 + rv_id: 1263192 + rule_id: DbUKEz + version_id: 44TEjYX + url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) + {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + import { ...,$IMPORT,... } from 'next/router' + ... + - pattern-inside: | + import $IMPORT from 'next/router'; + ... + - pattern-either: + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern-either: + - pattern-inside: | + const { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + var { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + let { ...,$PROPS,... } = $ROUTER.query + ... + - focus-metavariable: $PROPS + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern: "$ROUTER.query.$VALUE \n" + - patterns: + - pattern: $IMPORT().query.$VALUE + pattern-sinks: + - patterns: + - pattern: | + eval(...) +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `run:` step could allow an attacker to inject their own code into the runner. + This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate + environment variable with `env:` to store the data and use the environment variable + in the `run:` script. Be sure to use double-quotes the environment variable, like + this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + shortlink: https://sg.run/pkzk + semgrep.dev: + rule: + r_id: 13162 + rv_id: 1423395 + rule_id: v8UjQj + version_id: GxTl1DQ + url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `pull_request_target` and checks + out code from the incoming pull request. When using `pull_request_target`, the + Action runs in the context of the target repository, which includes access to + all repository secrets. Normally, this is safe because the Action only runs code + from the target repository, not the incoming PR. However, by checking out the + incoming PR code, you're now using the incoming code for the rest of the action. + You may be inadvertently executing arbitrary code from the incoming PR with access + to repository secrets, which would let an attacker steal repository secrets. This + normally happens by running build scripts (e.g., `npm build` and `make`) or dependency + installation scripts (e.g., `python setup.py install`). Audit your workflow file + to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + for additional mitigations. + metadata: + category: security + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + shortlink: https://sg.run/jkdn + semgrep.dev: + rule: + r_id: 13365 + rv_id: 1413423 + rule_id: d8Ulkd + version_id: O9TQ2nX + url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + origin: community + patterns: + - pattern-either: + - pattern-inside: | + on: + ... + pull_request_target: ... + ... + ... + - pattern-inside: | + on: [..., pull_request_target, ...] + ... + - pattern-inside: | + on: pull_request_target + ... + - pattern-inside: | + jobs: + ... + $JOBNAME: + ... + steps: + ... + - pattern: | + ... + uses: "$ACTION" + with: + ... + ref: $EXPR + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern-inside: ${{ ... }} + - pattern-either: + - pattern: github.event.pull_request ... + - pattern: github.head_ref ... + severity: ERROR +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can + lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing + sensitive data. It is recommend where possible to not allow user-input to craft + the base request, but to be treated as part of the path or query parameter. When + user-input is necessary to craft the request, it is recommended to follow OWASP + best practices to prevent abuse, including using an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/5DjW + semgrep.dev: + rule: + r_id: 14391 + rv_id: 1262970 + rule_id: AbUQLr + version_id: yeTxpOj + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $CLIENT := &http.Client{...} + ... + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: | + http.NewRequest("$METHOD", $URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + severity: WARNING +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) + or a safe library. + options: + interfile: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/PbEq + semgrep.dev: + rule: + r_id: 14689 + rv_id: 1409388 + rule_id: PeUoqy + version_id: nWTQ5qD + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + severity: ERROR + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern-inside: | + var $SB strings.Builder + ... + - pattern-inside: | + $SB.WriteString("$SQLSTR") + ... + $SB.String(...) + - pattern: | + $SB.WriteString(...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) +- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + languages: + - scala + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + metadata: + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + shortlink: https://sg.run/Z40o + semgrep.dev: + rule: + r_id: 15079 + rv_id: 1263691 + rule_id: OrU6W1 + version_id: 7ZTE3kr + url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + origin: community + pattern-either: + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC256("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC384("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC512("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + ... + } + ... + } + severity: ERROR +- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version + = "1.2"` in your resource block. + patterns: + - pattern: min_tls_version = $ANYTHING + - pattern-inside: | + resource "azurerm_app_service" "$NAME" { + ... + } + - pattern-not-inside: min_tls_version = "1.2" + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + shortlink: https://sg.run/AXRp + semgrep.dev: + rule: + r_id: 15106 + rv_id: 1263759 + rule_id: YGUDbZ + version_id: RGT0L4x + url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + origin: community + languages: + - hcl + severity: ERROR +- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - kt + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - kotlin + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/krq7 + semgrep.dev: + rule: + r_id: 15128 + rv_id: 1263269 + rule_id: nJUZNL + version_id: X0TzypE + url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + $KEY = $G.getInstance("RSA") + ... + $KEY.initialize($BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 +- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set + metadata: + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - scala + - cryptography + resources: + - https://blog.codacy.com/9-scala-security-issues/ + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + shortlink: https://sg.run/GO5p + semgrep.dev: + rule: + r_id: 15192 + rv_id: 1263677 + rule_id: 3qUj1Q + version_id: yeTxpoX + url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + origin: community + message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken + encryption. This could lead to sensitive data exposure. Instead, use RSA with + `OAEPWithMD5AndMGF1Padding` instead. + severity: WARNING + languages: + - scala + patterns: + - pattern: | + $VAR = $CIPHER.getInstance($MODE) + - metavariable-regex: + metavariable: $MODE + regex: .*RSA/.*/NoPadding.* +- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - ci + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell + shortlink: https://sg.run/4l9l + semgrep.dev: + rule: + r_id: 16200 + rv_id: 1262664 + rule_id: gxUJrJ + version_id: jQTn5QE + url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell + origin: community + message: Semgrep found a bash reverse shell + severity: ERROR + languages: + - generic + pattern-either: + - pattern: | + sh -i >& /dev/udp/.../... 0>&1 + - pattern: | + <...>/dev/tcp/.../...; sh <&... >&... 2>& + - pattern: | + <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done + - pattern: | + sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& +- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::java.security + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + shortlink: https://sg.run/ryJn + semgrep.dev: + rule: + r_id: 17325 + rv_id: 1263013 + rule_id: KxU5lW + version_id: 0bTKzGX + url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + origin: community + patterns: + - pattern: | + java.security.MessageDigest.getInstance($ALGO, ...); + - metavariable-regex: + metavariable: $ALGO + regex: (?i)(.MD5.) + - focus-metavariable: $ALGO + fix: | + "SHA-512" +- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/bXNp + semgrep.dev: + rule: + r_id: 17326 + rv_id: 1263016 + rule_id: qNUWNn + version_id: l4TJRpL + url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + origin: community + pattern-either: + - patterns: + - pattern: | + java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: | + $DU.getSha1Digest().digest(...) +- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + message: Detected input from a HTTPServletRequest going into a SQL sink or statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use parameterized SQL queries or properly sanitize user input instead. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://owasp.org/www-community/attacks/SQL_Injection + subcategory: + - vuln + technology: + - sql + - java + - servlets + - spring + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/Lg56 + semgrep.dev: + rule: + r_id: 18239 + rv_id: 1409390 + rule_id: oqUBJG + version_id: 7ZTKJNj + url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + languages: + - java + mode: taint + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + ... + $OUTPUT = $STMT.$FUNC(...); + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - pattern: | + (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + shortlink: https://sg.run/4Dv5 + semgrep.dev: + rule: + r_id: 18244 + rv_id: 1263057 + rule_id: j2UrJ8 + version_id: 0bTKzgX + url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + origin: community + message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external + entity declarations, this is vulnerable to XML external entity attacks. Disable + this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + false); + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/PYBz + semgrep.dev: + rule: + r_id: 18245 + rv_id: 1263058 + rule_id: 10UPQB + version_id: K3TKk80 + url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This + is vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, + allow DOCTYPE declarations and only prohibit external entities declarations. This + can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = DocumentBuilderFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newDocumentBuilder(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newDocumentBuilder(); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + shortlink: https://sg.run/JgPy + semgrep.dev: + rule: + r_id: 18246 + rv_id: 1263059 + rule_id: 9AUJ6r + version_id: qkTR7Lk + url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + false); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + shortlink: https://sg.run/5Lv0 + semgrep.dev: + rule: + r_id: 18247 + rv_id: 1263060 + rule_id: yyUNeo + version_id: l4TJRoL + url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + false); + languages: + - java +- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli + mode: taint + metadata: + references: + - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values + - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - slick + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + shortlink: https://sg.run/k9K2 + semgrep.dev: + rule: + r_id: 18328 + rv_id: 1263687 + rule_id: GdUDWO + version_id: d6TyxJe + url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + origin: community + message: Detected a tainted SQL statement. This could lead to SQL injection if variables + in the SQL statement are not properly sanitized. Avoid using using user input + for generating SQL strings. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.overrideSql(...) + - pattern: sql"..." + - pattern-inside: | + import slick.$DEPS + ... + severity: ERROR + languages: + - scala +- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + patterns: + - pattern-either: + - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); + - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); + - metavariable-comparison: + metavariable: $M + comparison: re.match(".*-CBC",$M) + message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext + attacks against encrypted data. + languages: + - php + severity: ERROR + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + references: + - https://csrc.nist.gov/publications/detail/sp/800-38a/final + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + technology: + - php + - openssl + category: security + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + shortlink: https://sg.run/LgWJ + semgrep.dev: + rule: + r_id: 19039 + rv_id: 1263295 + rule_id: DbUGbE + version_id: JdTzxOD + url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + origin: community +- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + patterns: + - pattern-inside: | + import pdi.jwt.$DEPS + ... + - pattern-either: + - pattern: $JWT.encode($X, "...", ...) + - pattern: $JWT.decode($X, "...", ...) + - pattern: $JWT.decodeRawAll($X, "...", ...) + - pattern: $JWT.decodeRaw($X, "...", ...) + - pattern: $JWT.decodeAll($X, "...", ...) + - pattern: $JWT.validate($X, "...", ...) + - pattern: $JWT.isValid($X, "...", ...) + - pattern: $JWT.decodeJson($X, "...", ...) + - pattern: $JWT.decodeJsonAll($X, "...", ...) + - patterns: + - pattern-either: + - pattern: $JWT.encode($X, $KEY, ...) + - pattern: $JWT.decode($X, $KEY, ...) + - pattern: $JWT.decodeRawAll($X, $KEY, ...) + - pattern: $JWT.decodeRaw($X, $KEY, ...) + - pattern: $JWT.decodeAll($X, $KEY, ...) + - pattern: $JWT.validate($X, $KEY, ...) + - pattern: $JWT.isValid($X, $KEY, ...) + - pattern: $JWT.decodeJson($X, $KEY, ...) + - pattern: $JWT.decodeJsonAll($X, $KEY, ...) + - pattern: $JWT.encode($X, this.$KEY, ...) + - pattern: $JWT.decode($X, this.$KEY, ...) + - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) + - pattern: $JWT.decodeRaw($X, this.$KEY, ...) + - pattern: $JWT.decodeAll($X, this.$KEY, ...) + - pattern: $JWT.validate($X, this.$KEY, ...) + - pattern: $JWT.isValid($X, this.$KEY, ...) + - pattern: $JWT.decodeJson($X, this.$KEY, ...) + - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) + - pattern-either: + - pattern-inside: | + class $CL { + ... + $KEY = "..." + ... + } + - pattern-inside: | + object $CL { + ... + $KEY = "..." + ... + } + - metavariable-pattern: + metavariable: $JWT + patterns: + - pattern-either: + - pattern: Jwt + - pattern: JwtArgonaut + - pattern: JwtCirce + - pattern: JwtJson4s + - pattern: JwtJson + - pattern: JwtUpickle + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + languages: + - scala + severity: WARNING + metadata: + references: + - https://jwt-scala.github.io/jwt-scala/ + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - scala + confidence: HIGH + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + shortlink: https://sg.run/8zE7 + semgrep.dev: + rule: + r_id: 19040 + rv_id: 1263669 + rule_id: WAUdK0 + version_id: o5TbDA8 + url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + origin: community +- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + patterns: + - pattern-either: + - pattern: | + $DF = DocumentBuilderFactory.newInstance(...) + ... + $DB = $DF.newDocumentBuilder(...) + - patterns: + - pattern: $DB = DocumentBuilderFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $DB.newDocumentBuilder(...) + - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: Document Builder being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + shortlink: https://sg.run/gRQn + semgrep.dev: + rule: + r_id: 19041 + rv_id: 1263673 + rule_id: 0oUwzP + version_id: X0TzyRq + url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + origin: community +- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + patterns: + - pattern-either: + - pattern: $SR = new SAXReader(...) + - pattern: | + $SF = SAXParserFactory.newInstance(...) + ... + $SR = $SF.newSAXParser(...) + - patterns: + - pattern: $SR = SAXParserFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $SR.newSAXParser(...) + - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) + - pattern: $SR = new SAXBuilder(...) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: XML processor being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Parsers can result in XML Internal Entity Processing vulnerabilities like + the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + shortlink: https://sg.run/QbYP + semgrep.dev: + rule: + r_id: 19042 + rv_id: 1263678 + rule_id: KxUrkq + version_id: rxTAKWY + url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + origin: community +- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + patterns: + - pattern-not-inside: | + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) + - pattern-either: + - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) + - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) + - pattern: $XMLFACTORY = new XMLInputFactory(...) + message: XMLInputFactory being instantiated without calling the setProperty functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + shortlink: https://sg.run/3BEb + semgrep.dev: + rule: + r_id: 19043 + rv_id: 1263683 + rule_id: qNUQ7w + version_id: xyTjzkA + url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + origin: community +- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + domain_endpoint_options { + ... + enforce_https = true + tls_security_policy = "Policy-Min-TLS-1-0-2019-07" + ... + } + ... + } + message: Detected an AWS Elasticsearch domain using an insecure version of TLS. + To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07". + languages: + - terraform + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - aws + - terraform + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + shortlink: https://sg.run/PYlq + semgrep.dev: + rule: + r_id: 19045 + rv_id: 1263718 + rule_id: YGUle7 + version_id: DkTRbA5 + url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + origin: community +- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/BeW9 + semgrep.dev: + rule: + r_id: 20051 + rv_id: 1263688 + rule_id: 0oUpon + version_id: ZRTKAoG + url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern: s"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) +- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + message: Found the use of an hardcoded passphrase for RSA. The passphrase can be + easily discovered, and therefore should not be stored in source-code. It is recommended + to remove the passphrase from source-code, and use system environment variables + or a restricted configuration file. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - secrets + category: security + references: + - https://cwe.mitre.org/data/definitions/522.html + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + shortlink: https://sg.run/xPEe + semgrep.dev: + rule: + r_id: 20730 + rv_id: 1263607 + rule_id: bwULyN + version_id: K3TKkEo + url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') + - patterns: + - pattern-inside: | + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + - pattern-either: + - pattern: | + $OPENSSL.export(...,'...') + - pattern: | + $OPENSSL.to_pem(...,'...') + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + end + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + def $METHOD(...) + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + $ASSIGN = '...' + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) +- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended + to use a key length of 2048 or higher. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + category: security + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/O4Re + semgrep.dev: + rule: + r_id: 20731 + rv_id: 1263608 + rule_id: NbUe4N + version_id: qkTR76v + url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) + - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = $SIZE + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = $SIZE + ... + end + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 +- id: java.spring.security.injection.tainted-file-path.tainted-file-path + languages: + - java + severity: ERROR + message: Detected user input controlling a file path. An attacker could control + the location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + options: + interfile: true + metadata: + cwe: + - 'CWE-23: Relative Path Traversal' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - java + - spring + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path + shortlink: https://sg.run/x9o0 + semgrep.dev: + rule: + r_id: 22074 + rv_id: 1263084 + rule_id: lBUxok + version_id: ExTEx6Y + url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new File(...) + - pattern: new java.io.File(...) + - pattern: new FileReader(...) + - pattern: new java.io.FileReader(...) + - pattern: new FileInputStream(...) + - pattern: new java.io.FileInputStream(...) + - pattern: (Paths $PATHS).get(...) + - patterns: + - pattern: | + $CLASS.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(getResourceAsStream|getResource)$ + - patterns: + - pattern-either: + - pattern: new ClassPathResource($FILE, ...) + - pattern: ResourceUtils.getFile($FILE, ...) + - pattern: new FileOutputStream($FILE, ...) + - pattern: new java.io.FileOutputStream($FILE, ...) + - pattern: new StreamSource($FILE, ...) + - pattern: new javax.xml.transform.StreamSource($FILE, ...) + - pattern: FileUtils.openOutputStream($FILE, ...) + - focus-metavariable: $FILE + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) +- id: java.spring.security.injection.tainted-system-command.tainted-system-command + languages: + - java + severity: ERROR + mode: taint + pattern-propagators: + - pattern: (StringBuilder $STRB).append($INPUT) + from: $INPUT + to: $STRB + label: CONCAT + requires: INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $SOURCE + - pattern: $SOURCE + $Y + - pattern: String.format("...", ..., $SOURCE, ...) + - pattern: String.join("...", ..., $SOURCE, ...) + - pattern: (String $STR).concat($SOURCE) + - pattern: $SOURCE.concat(...) + - pattern: $X += $SOURCE + - pattern: $SOURCE += $X + label: CONCAT + requires: INPUT + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (Process $P) = new Process(...); + - pattern: | + (ProcessBuilder $PB).command(...); + - patterns: + - pattern-either: + - pattern: | + (Runtime $R).$EXEC(...); + - pattern: | + Runtime.getRuntime(...).$EXEC(...); + - metavariable-regex: + metavariable: $EXEC + regex: (exec|loadLibrary|load) + - patterns: + - pattern: | + (ProcessBuilder $PB).command(...).$ADD(...); + - metavariable-regex: + metavariable: $ADD + regex: (add|addAll) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $BUILDER = new ProcessBuilder(...); + ... + - pattern: $BUILDER.start(...) + - pattern: | + new ProcessBuilder(...). ... .start(...); + requires: CONCAT + message: 'Detected user input entering a method which executes a system command. + This could result in a command injection vulnerability, which allows an attacker + to inject an arbitrary system command onto the server. The attacker could download + malware onto or steal data from the server. Instead, use ProcessBuilder, separating + the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", + targetDirectory)`. Further, make sure you hardcode or allowlist the actual command + so that attackers can''t run arbitrary commands.' + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - java + - spring + confidence: HIGH + references: + - https://www.stackhawk.com/blog/command-injection-java/ + - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html + - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command + shortlink: https://sg.run/epY0 + semgrep.dev: + rule: + r_id: 22076 + rv_id: 1263087 + rule_id: 6JUxGN + version_id: 8KT5rnP + url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command + origin: community +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + message: The libxml library processes user-input with the `noent` attribute is set + to `true` which can lead to being vulnerable to XML External Entities (XXE) type + attacks. It is recommended to set `noent` to `false` when using this feature to + ensure you are protected. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + shortlink: https://sg.run/Z75x + semgrep.dev: + rule: + r_id: 22079 + rv_id: 1263138 + rule_id: pKUNeD + version_id: d6TyxpX + url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('$IMPORT') + ... + - pattern-inside: | + import $XML from '$IMPORT' + ... + - pattern-inside: | + import * as $XML from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-open-redirect.express-open-redirect + message: The application redirects to a URL specified by user-supplied input `$REQ` + that is not validated. This could redirect users to malicious locations. Consider + using an allow-list approach to validate URLs, or warn users they are being redirected + to a third-party website. + metadata: + technology: + - express + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect + shortlink: https://sg.run/EpoP + semgrep.dev: + rule: + r_id: 22081 + rv_id: 1263140 + rule_id: X5ULkq + version_id: nWT2L0v + url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + options: + taint_unify_mvars: true + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $HTTP + regex: ^https?:\/\/$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ. ... .$VALUE) + - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ.$VALUE['...']) + - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) + - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) + - pattern: $REQ.$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ.$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" + - pattern-either: + - pattern: $RES.redirect($ASSIGN) + - pattern: $RES.redirect($ASSIGN + $...FOO) + - pattern: $RES.redirect(`${$ASSIGN}...`) + - focus-metavariable: $ASSIGN +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + shortlink: https://sg.run/LYvG + semgrep.dev: + rule: + r_id: 22083 + rv_id: 1263143 + rule_id: 10Uo39 + version_id: LjTkgle + url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern-inside: | + import $SESSION from 'express-session' + ... + - pattern-inside: | + import {..., $SESSION, ...} from 'express-session' + ... + - pattern-inside: | + import * as $SESSION from 'express-session' + ... + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: | + $SECRET = $VALUE + ... + $APP.use($SESSION($SECRET)) + - pattern: | + secret: '$Y' +- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + message: The following function call $SER.$FUNC accepts user controlled data which + can result in Remote Code Execution (RCE) through Object Deserialization. It is + recommended to use secure data processing alternatives such as JSON.parse() and + Buffer.from(). + options: + interfile: true + metadata: + interfile: true + technology: + - express + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + shortlink: https://sg.run/8W5j + semgrep.dev: + rule: + r_id: 22084 + rv_id: 1263145 + rule_id: 9AUyqj + version_id: gETB7nD + url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $SER = require('$IMPORT') + ... + - pattern-inside: | + import $SER from '$IMPORT' + ... + - pattern-inside: | + import * as $SER from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + message: Detected a sequelize statement that is tainted by user-input. This could + lead to SQL injection if the variable is user-controlled and is not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. + options: + interfile: true + metadata: + interfile: true + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + category: security + technology: + - express + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + shortlink: https://sg.run/gjoe + semgrep.dev: + rule: + r_id: 22085 + rv_id: 1263241 + rule_id: yyU0GX + version_id: nWT2Llx + url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) +- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + message: Detected usage of dangerous method $METHOD which does not escape inputs + (see link in references). If the argument is user-controlled, this can lead to + SQL injection. When using $METHOD function, do not trust user-submitted data and + only allow approved list of input (possibly, use an allowlist approach). + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-inside: | + import ("gorm.io/gorm") + ... + - patterns: + - pattern-inside: | + func $VAL(..., $GORM *gorm.DB,... ) { + ... + } + - pattern-either: + - pattern: | + $GORM. ... .$METHOD($VALUE) + - pattern: | + $DB := $GORM. ... .$ANYTHING(...) + ... + $DB. ... .$METHOD($VALUE) + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) + options: + interfile: true + metadata: + category: security + technology: + - gorm + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://gorm.io/docs/security.html#SQL-injection-Methods + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + shortlink: https://sg.run/R4qg + semgrep.dev: + rule: + r_id: 24693 + rv_id: 1262915 + rule_id: AbU5o3 + version_id: l4TJRJK + url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + origin: community +- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + patterns: + - pattern: $APP.UseDeveloperExceptionPage(...); + - pattern-not-inside: | + if ($ENV.IsDevelopment(...)) { + ... + } + - pattern-not-inside: | + if ($ENV.EnvironmentName == "Development") { + ... + } + message: Stacktrace information is displayed in a non-Development environment. Accidentally + disclosing sensitive stack trace information in a production environment aids + an attacker in reconnaissance and information gathering. + metadata: + category: security + technology: + - csharp + owasp: + - A06:2017 - Security Misconfiguration + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-209: Generation of Error Message Containing Sensitive Information' + references: + - https://cwe.mitre.org/data/definitions/209.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + shortlink: https://sg.run/XvkA + semgrep.dev: + rule: + r_id: 26720 + rv_id: 1262653 + rule_id: lBU6Dv + version_id: 0bTKzrB + url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + origin: community + languages: + - csharp + severity: WARNING +- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + patterns: + - pattern-either: + - patterns: + - pattern: $LIFETIME = $FALSE + - pattern-inside: new TokenValidationParameters {...} + - patterns: + - pattern: | + (TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE + - metavariable-regex: + metavariable: $LIFETIME + regex: (RequireExpirationTime|ValidateLifetime) + - metavariable-regex: + metavariable: $FALSE + regex: (false) + - focus-metavariable: $FALSE + fix: | + true + message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the + JWT tokens lifetime is not validated. This can lead to an JWT token being used + after it has expired, which has security implications. It is recommended to validate + the JWT lifetime to ensure only valid tokens are used. + metadata: + category: security + technology: + - csharp + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-613: Insufficient Session Expiration' + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://cwe.mitre.org/data/definitions/613.html + - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + shortlink: https://sg.run/KA0d + semgrep.dev: + rule: + r_id: 28955 + rv_id: 1262628 + rule_id: bwU5kK + version_id: w8TRolJ + url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + origin: community + languages: + - csharp + severity: WARNING +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(..., $REQUEST, ...): + ... + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + shortlink: https://sg.run/49BE + semgrep.dev: + rule: + r_id: 31144 + rv_id: 1263388 + rule_id: EwUepx + version_id: 7ZTE3qK + url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + origin: community +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + shortlink: https://sg.run/5gW3 + semgrep.dev: + rule: + r_id: 31147 + rv_id: 1263433 + rule_id: 8GU3qp + version_id: bZT53gQ + url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + origin: community +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `actions/github-script`''s `script:` step could allow an attacker to inject + their own code into the runner. This would allow them to steal secrets and code. + `github` context data can have arbitrary user input and should be treated as untrusted. + Instead, use an intermediate environment variable with `env:` to store the data + and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + technology: + - github-actions + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + shortlink: https://sg.run/g1G0 + semgrep.dev: + rule: + r_id: 31441 + rv_id: 1423394 + rule_id: OrUQvK + version_id: 5PT7Zyw + url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + uses: $ACTION + ... + - pattern-inside: | + with: + ... + script: ... + ... + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + shortlink: https://sg.run/dlOE + semgrep.dev: + rule: + r_id: 33634 + rv_id: 1263545 + rule_id: JDUGnK + version_id: ExTExln + url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.Blowfish.new(...) + - pattern: Crypto.Cipher.Blowfish.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + message: Detected DES cipher or Triple DES algorithm which is considered insecure. + This algorithm is not cryptographically secure and can be reversed easily. Use + a secure symmetric cipher from the cryptodome package instead. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + shortlink: https://sg.run/Z5bw + semgrep.dev: + rule: + r_id: 33635 + rv_id: 1263546 + rule_id: 5rUr73 + version_id: 7ZTE3G7 + url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.DES.new(...) + - pattern: Crypto.Cipher.DES.new(...) + - pattern: Cryptodome.Cipher.DES3.new(...) + - pattern: Crypto.Cipher.DES3.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + message: Detected RC2 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + shortlink: https://sg.run/nAbY + semgrep.dev: + rule: + r_id: 33636 + rv_id: 1263547 + rule_id: GdUYlW + version_id: LjTkgn6 + url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC2.new(...) + - pattern: Crypto.Cipher.ARC2.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + shortlink: https://sg.run/Eo6N + semgrep.dev: + rule: + r_id: 33637 + rv_id: 1263548 + rule_id: ReUnEB + version_id: 8KT5rXY + url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC4.new(...) + - pattern: Crypto.Cipher.ARC4.new(...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + shortlink: https://sg.run/7JP2 + semgrep.dev: + rule: + r_id: 33638 + rv_id: 1263550 + rule_id: AbU0Ex + version_id: QkTGqD8 + url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD2.new(...) + - pattern: Cryptodome.Hash.MD2.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + shortlink: https://sg.run/Lve6 + semgrep.dev: + rule: + r_id: 33639 + rv_id: 1263551 + rule_id: BYUJy4 + version_id: 3ZT4Xnp + url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD4.new(...) + - pattern: Cryptodome.Hash.MD4.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/85JN + semgrep.dev: + rule: + r_id: 33640 + rv_id: 1263552 + rule_id: DbUXwo + version_id: 44TEjpk + url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD5.new(...) + - pattern: Cryptodome.Hash.MD5.new (...) +- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode + message: Usage of the insecure ECB mode detected. You should use an authenticated + encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + shortlink: https://sg.run/wj9n + semgrep.dev: + rule: + r_id: 36773 + rv_id: 1262623 + rule_id: 0oUqWP + version_id: yeTxpPw + url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + origin: community + languages: + - csharp + patterns: + - pattern-either: + - pattern: ($KEYTYPE $KEY).EncryptEcb(...); + - pattern: ($KEYTYPE $KEY).DecryptEcb(...); + - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 +- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + message: You are using an insecure random number generator (RNG) to create a cryptographic + key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator + instead. + severity: ERROR + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + shortlink: https://sg.run/xjrA + semgrep.dev: + rule: + r_id: 36774 + rv_id: 1262624 + rule_id: KxU3Nq + version_id: rxTAK2O + url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... + - pattern: $KEY + pattern-sinks: + - pattern-either: + - patterns: + - pattern: ($KEYTYPE $CIPHER).Key = $SINK; + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 + - pattern: new AesGcm(...) + - pattern: new AesCcm(...) + - pattern: new ChaCha20Poly1305(...) +- id: html.security.plaintext-http-link.plaintext-http-link + metadata: + category: security + technology: + - html + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + confidence: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/319.html + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link + shortlink: https://sg.run/RA5q + semgrep.dev: + rule: + r_id: 39193 + rv_id: 1262976 + rule_id: AbUnNo + version_id: xyTjzRL + url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link + origin: community + patterns: + - pattern: ... + - metavariable-regex: + metavariable: $URL + regex: ^(?i)http:// + message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL + if possible. + severity: WARNING + languages: + - html +- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::org.apache.commons + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + shortlink: https://sg.run/AWL2 + semgrep.dev: + rule: + r_id: 39194 + rv_id: 1263012 + rule_id: BYUGK0 + version_id: WrTqK7K + url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + origin: community + patterns: + - pattern: | + $DU.$GET_ALGO().digest(...) + - metavariable-pattern: + metavariable: $GET_ALGO + pattern: getMd5Digest + - metavariable-pattern: + metavariable: $DU + pattern: DigestUtils + - focus-metavariable: $GET_ALGO + fix: | + getSha512Digest +- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + pattern-either: + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + account_aggregation_source { + ... + regions = ... + ... + } + ... + } + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + organization_aggregation_source { + ... + regions = ... + ... + } + ... + } + message: The AWS configuration aggregator does not aggregate all AWS Config region. + This may result in unmonitored configuration in regions that are thought to be + unused. Configure the aggregator with all_regions for the source. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + shortlink: https://sg.run/O6A7 + semgrep.dev: + rule: + r_id: 47275 + rv_id: 1263703 + rule_id: DbUo7v + version_id: A8Tgdwv + url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + origin: community +- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + pattern: $CIPHER.getInstance("=~/AES/ECB.*/") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + shortlink: https://sg.run/dB2Y + semgrep.dev: + rule: + r_id: 48734 + rv_id: 1263009 + rule_id: WAU2yA + version_id: A8TgdEo + url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + origin: community + message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality + and is not semantically secure so should not be used. Instead, use a strong, + secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + pattern: $CIPHER.getInstance("Blowfish") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + shortlink: https://sg.run/ZE4n + semgrep.dev: + rule: + r_id: 48735 + rv_id: 1263010 + rule_id: 0oUR28 + version_id: BjTkZy0 + url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + origin: community + message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes + it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead, + use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + import javax; + ... + - pattern-either: + - pattern: javax.crypto.Cipher.getInstance("AES") + - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.*; + ... + - pattern-inside: | + import javax.crypto; + ... + - pattern-either: + - pattern: crypto.Cipher.getInstance("AES") + - pattern: (crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.crypto.*; + ... + - pattern-inside: | + import javax.crypto.Cipher; + ... + - pattern-either: + - pattern: Cipher.getInstance("AES") + - pattern: (Cipher $CIPHER).getInstance("AES") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + shortlink: https://sg.run/nzKO + semgrep.dev: + rule: + r_id: 48736 + rv_id: 1263011 + rule_id: KxUB7Z + version_id: DkTRbwy + url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + origin: community + message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses + ECB mode. ECB doesn''t provide message confidentiality and is not semantically + secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + pattern: $CIPHER.getInstance("RC2") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + shortlink: https://sg.run/EEvA + semgrep.dev: + rule: + r_id: 48737 + rv_id: 1263014 + rule_id: qNUzXG + version_id: K3TKkg0 + url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + origin: community + message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and + is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + pattern: $CIPHER.getInstance("RC4") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + shortlink: https://sg.run/7OYR + semgrep.dev: + rule: + r_id: 48738 + rv_id: 1263015 + rule_id: lBUw8k + version_id: qkTR7vk + url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + origin: community + message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including + stream cipher attacks and bit flipping attacks. Instead, use a strong, secure + cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: clojure.lang.security.use-of-md5.use-of-md5 + languages: + - clojure + severity: WARNING + message: MD5 hash algorithm detected. This is not collision resistant and leads + to easily-cracked password hashes. Replace with current recommended hashing algorithms. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + author: Gabriel Marquet + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 + shortlink: https://sg.run/BgPx + semgrep.dev: + rule: + r_id: 52195 + rv_id: 1262609 + rule_id: nJU1ep + version_id: 0bTKz2B + url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 + origin: community + pattern-either: + - pattern: (MessageDigest/getInstance "MD5") + - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance "MD5") + - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) +- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + patterns: + - pattern: | + resource "aws_lambda_permission" $ANYTHING { + ... + principal = "$PRINCIPAL" + ... + } + - pattern-not: | + resource "aws_lambda_permission" $ANYTHING { + ... + source_arn = ... + ... + } + - metavariable-regex: + metavariable: $PRINCIPAL + regex: .*[.]amazonaws[.]com$ + message: The AWS Lambda permission has an AWS service principal but does not specify + a source ARN. If you grant permission to a service principal without specifying + the source, other accounts could potentially configure resources in their account + to invoke your Lambda function. Set the source_arn value to the ARN of the AWS + resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule, + API Gateway, or SNS topic. + languages: + - hcl + severity: ERROR + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission + - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + shortlink: https://sg.run/kOP7 + semgrep.dev: + rule: + r_id: 54772 + rv_id: 1263732 + rule_id: OrU9Ox + version_id: 1QTypq5 + url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + origin: community +- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/Gj32 + semgrep.dev: + rule: + r_id: 59048 + rv_id: 1263061 + rule_id: j2Udpk + version_id: YDTZeko + url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` + and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - + The previous links are not meant to be clicked. They are the literal config key + values that are supposed to be used to disable these features. For more information, + see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = SAXParserFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newSAXParser(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newSAXParser(); + languages: + - java +- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + shortlink: https://sg.run/1wyQ + semgrep.dev: + rule: + r_id: 59622 + rv_id: 1263062 + rule_id: v8UeQ1 + version_id: 6xT29GK + url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + origin: community + message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" + and "accessExternalStylesheet" to "". + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = TransformerFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newTransformer(...); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + $FACTORY.newTransformer(...); + languages: + - java +- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + patterns: + - pattern: | + RUN sudo ... + message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can + help reduce the potential impact of configuration errors and security vulnerabilities. + metadata: + category: security + technology: + - dockerfile + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/250.html + - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + shortlink: https://sg.run/80Q7 + semgrep.dev: + rule: + r_id: 66384 + rv_id: 1262661 + rule_id: kxUlx1 + version_id: pZT03zY + url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + origin: community + languages: + - dockerfile + severity: WARNING +- id: swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + message: Webviews were observed that explictly allow JavaScript in an WKWebview + to open windows automatically. Consider disabling this functionality if not required, + following the principle of least privelege. + severity: WARNING + metadata: + likelihood: LOW + impact: LOW + confidence: HIGH + category: security + cwe: + - 'CWE-272: Least Privilege Violation' + masvs: + - 'MASVS-PLATFORM-2: The app uses WebViews securely' + references: + - https://mas.owasp.org/MASVS/controls/MASVS-PLATFORM-2/ + - https://developer.apple.com/documentation/webkit/wkpreferences/1536573-javascriptcanopenwindowsautomati + subcategory: + - audit + technology: + - ios + - macos + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + shortlink: https://sg.run/YWLd + semgrep.dev: + rule: + r_id: 66514 + rv_id: 946637 + rule_id: lBUOZk + version_id: 9lTy1KE + url: https://semgrep.dev/playground/r/9lTy1KE/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + origin: community + languages: + - swift + patterns: + - pattern: | + $P = WKPreferences() + ... + - pattern-either: + - patterns: + - pattern-inside: | + $P.JavaScriptCanOpenWindowsAutomatically = $FALSE + ... + $P.JavaScriptCanOpenWindowsAutomatically = $TRUE + - pattern-not-inside: | + ... + $P.JavaScriptCanOpenWindowsAutomatically = $TRUE + ... + $P.JavaScriptCanOpenWindowsAutomatically = $FALSE + - pattern: | + $P.JavaScriptCanOpenWindowsAutomatically = true + - metavariable-regex: + metavariable: $TRUE + regex: ^(true)$ + - metavariable-regex: + metavariable: $TRUE + regex: (.*(?!true)) + - patterns: + - pattern: | + $P.JavaScriptCanOpenWindowsAutomatically = true + - pattern-not-inside: | + ... + $P.JavaScriptCanOpenWindowsAutomatically = ... + ... + $P.JavaScriptCanOpenWindowsAutomatically = ... +- id: solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + message: $VAULT.getPoolTokens() call on a Balancer pool is not protected from the + read-only reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376 + - https://hackmd.io/@sentimentxyz/SJCySo1z2 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + shortlink: https://sg.run/803Q + semgrep.dev: + rule: + r_id: 67640 + rv_id: 946602 + rule_id: kxUl7x + version_id: e1T98xQ + url: https://semgrep.dev/playground/r/e1T98xQ/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + origin: community + patterns: + - pattern-either: + - pattern: | + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + - metavariable-pattern: + metavariable: $RETURN + pattern-regex: .*uint256\[].* + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + ... + } + - pattern-not: | + function $F(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + - pattern-not: | + function $F(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + - pattern-not-inside: | + contract LinearPool { + ... + } + - pattern-not-inside: | + contract ComposableStablePool { + ... + } + - pattern-not-inside: "contract BalancerQueries {\n ...\n} \n" + - pattern-not-inside: | + contract ManagedPool { + ... + } + - pattern-not-inside: "contract BaseWeightedPool {\n ...\n} \n" + - pattern-not-inside: | + contract ComposableStablePoolStorage { + ... + } + - pattern-not-inside: | + contract RecoveryModeHelper { + ... + } + - focus-metavariable: + - $VAULT + languages: + - solidity + severity: ERROR +- id: solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + message: $VAR.getRate() call on a Balancer pool is not protected from the read-only + reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://forum.balancer.fi/t/reentrancy-vulnerability-scope-expanded/4345 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + shortlink: https://sg.run/g9e5 + semgrep.dev: + rule: + r_id: 67641 + rv_id: 946603 + rule_id: wdUx3D + version_id: vdTGn2l + url: https://semgrep.dev/playground/r/vdTGn2l/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + origin: community + patterns: + - pattern: | + function $F(...) { + ... + $VAR.getRate(); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + - pattern-not-inside: | + function _updateTokenRateCache(...) { + ... + } + - pattern-not-inside: | + contract PoolRecoveryHelper { + ... + } + - pattern-not-inside: | + contract ComposableStablePoolRates { + ... + } + - pattern-not-inside: | + contract WeightedPoolProtocolFees { + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $VAR.getRate(); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $VAR.getRate(); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $VAR.getRate(); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $VAR.getRate(); + ... + } + ... + } + - focus-metavariable: $VAR + languages: + - solidity + severity: ERROR +- id: solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + message: Function borrowFresh() in Compound performs state update after doTransferOut() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1509431646818234369 + - https://twitter.com/blocksecteam/status/1509466576848064512 + - https://slowmist.medium.com/another-day-another-reentrancy-attack-5cde10bbb2b4 + - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + shortlink: https://sg.run/4A19 + semgrep.dev: + rule: + r_id: 67644 + rv_id: 946606 + rule_id: eqUkx4 + version_id: nWTpz74 + url: https://semgrep.dev/playground/r/nWTpz74/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + origin: community + patterns: + - pattern-inside: | + function borrowFresh(...) { + ... + } + - pattern-not-inside: | + accountBorrows[borrower].interestIndex = borrowIndex; + ... + - pattern: doTransferOut(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + message: $POOL.get_virtual_price() call on a Curve pool is not protected from the + read-only reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://chainsecurity.com/heartbreaks-curve-lp-oracles/ + - https://chainsecurity.com/curve-lp-oracle-manipulation-post-mortem/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + shortlink: https://sg.run/Jk5P + semgrep.dev: + rule: + r_id: 67646 + rv_id: 946608 + rule_id: d8UGDL + version_id: 7ZTrQO3 + url: https://semgrep.dev/playground/r/7ZTrQO3/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + origin: community + patterns: + - pattern: | + $POOL.get_virtual_price() + - pattern-not-inside: | + function $F(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $POOL.get_virtual_price(); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + ... + function $F(...) { + ... + $POOL.get_virtual_price(); + ... + $CHECKFUNC(...); + ... + } + ... + } + languages: + - solidity + severity: ERROR +- id: solidity.security.encode-packed-collision.encode-packed-collision + message: abi.encodePacked hash collision with variable length arguments in $F() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-20: Improper Input Validation' + confidence: HIGH + likelihood: MEDIUM + impact: MEDIUM + subcategory: + - vuln + references: + - https://swcregistry.io/docs/SWC-133 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/solidity.security.encode-packed-collision.encode-packed-collision + shortlink: https://sg.run/Gr46 + semgrep.dev: + rule: + r_id: 67648 + rv_id: 946610 + rule_id: nJU47w + version_id: 8KTKjb1 + url: https://semgrep.dev/playground/r/8KTKjb1/solidity.security.encode-packed-collision.encode-packed-collision + origin: community + patterns: + - pattern-either: + - pattern-inside: | + function $F(..., bytes $A, ..., bytes $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., string $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., string $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., bytes $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., address[] $A, ..., address[] $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., uint256[] $A, ..., uint256[] $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., bytes $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., string $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., string $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., bytes $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., address[] $A, ..., address[] $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., uint256[] $A, ..., uint256[] $B, ...) external { + ... + } + - pattern-either: + - pattern: | + keccak256(abi.encodePacked(..., $A, $B, ...)) + - pattern: | + $X = abi.encodePacked(..., $A, $B, ...); + ... + keccak256($X); + languages: + - solidity + severity: ERROR +- id: solidity.security.erc677-reentrancy.erc677-reentrancy + message: ERC677 callAfterTransfer() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1509431646818234369 + - https://twitter.com/blocksecteam/status/1509466576848064512 + - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 + - https://explorer.fuse.io/address/0x5De15b5543c178C111915d6B8ae929Af01a8cC58 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc677-reentrancy.erc677-reentrancy + shortlink: https://sg.run/BXnR + semgrep.dev: + rule: + r_id: 67651 + rv_id: 946613 + rule_id: L1Ub0L + version_id: 3ZTOPdd + url: https://semgrep.dev/playground/r/3ZTOPdd/solidity.security.erc677-reentrancy.erc677-reentrancy + origin: community + patterns: + - pattern-inside: | + function transfer(...) { + ... + } + - pattern: callAfterTransfer(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.erc721-reentrancy.erc721-reentrancy + message: ERC721 onERC721Received() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://blocksecteam.medium.com/when-safemint-becomes-unsafe-lessons-from-the-hypebears-security-incident-2965209bda2a + - https://etherscan.io/address/0x14e0a1f310e2b7e321c91f58847e98b8c802f6ef + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc721-reentrancy.erc721-reentrancy + shortlink: https://sg.run/WBoE + semgrep.dev: + rule: + r_id: 67653 + rv_id: 946615 + rule_id: gxU2qG + version_id: PkTQZYA + url: https://semgrep.dev/playground/r/PkTQZYA/solidity.security.erc721-reentrancy.erc721-reentrancy + origin: community + patterns: + - pattern: _checkOnERC721Received(...) + languages: + - solidity + severity: WARNING +- id: solidity.security.erc777-reentrancy.erc777-reentrancy + message: ERC777 tokensReceived() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://mirror.xyz/baconcoin.eth/LHaPiX38mnx8eJ2RVKNXHttHfweQMKNGmEnX4KUksk0 + - https://etherscan.io/address/0xf53f00f844b381963a47fde3325011566870b31f + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc777-reentrancy.erc777-reentrancy + shortlink: https://sg.run/0Jpw + semgrep.dev: + rule: + r_id: 67654 + rv_id: 946616 + rule_id: QrUrJj + version_id: JdTDyg1 + url: https://semgrep.dev/playground/r/JdTDyg1/solidity.security.erc777-reentrancy.erc777-reentrancy + origin: community + patterns: + - pattern: $X.tokensReceived(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + message: blockhash(block.number) and blockhash(block.number + N) always returns + 0. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-341: Predictable from Observable State' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: + - vuln + references: + - https://blog.positive.com/predicting-random-numbers-in-ethereum-smart-contracts-e5358c6b8620 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + shortlink: https://sg.run/qvPO + semgrep.dev: + rule: + r_id: 67656 + rv_id: 946618 + rule_id: 4bUPoB + version_id: GxTP7wj + url: https://semgrep.dev/playground/r/GxTP7wj/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + origin: community + patterns: + - pattern-either: + - pattern: blockhash(block.number) + - pattern: blockhash(block.number + $N) + - pattern: blockhash(block.number * $N) + - pattern: block.blockhash(block.number) + - pattern: block.blockhash(block.number + $N) + - pattern: block.blockhash(block.number * $N) + severity: ERROR + languages: + - solidity +- id: solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + message: Keep3rV2.current() call has high data freshness, but it has low security, an + exploiter simply needs to manipulate 2 data points to be able to impact the feed. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-682: Incorrect Calculation' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1510232640338608131 + - https://twitter.com/FrankResearcher/status/1510239094777032713 + - https://twitter.com/larry0x/status/1510263618180464644 + - https://andrecronje.medium.com/keep3r-network-on-chain-oracle-price-feeds-3c67ed002a9 + - https://etherscan.io/address/0x210ac53b27f16e20a9aa7d16260f84693390258f + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + shortlink: https://sg.run/lkEo + semgrep.dev: + rule: + r_id: 67657 + rv_id: 946619 + rule_id: PeUrYv + version_id: RGTAgvQ + url: https://semgrep.dev/playground/r/RGTAgvQ/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + origin: community + patterns: + - pattern: $KEEPER.current($TOKENIN, $AMOUNTIN, $TOKENOUT); + languages: + - solidity + severity: WARNING +- id: solidity.security.no-bidi-characters.no-bidi-characters + message: The code must not contain any of Unicode Direction Control Characters + metadata: + category: security + technology: + - solidity + cwe: 'CWE-837: Improper Enforcement of a Single, Unique Action' + confidence: HIGH + likelihood: LOW + impact: LOW + subcategory: + - audit + references: + - https://entethalliance.org/specs/ethtrust-sl/v1/#req-1-unicode-bdo + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.no-bidi-characters.no-bidi-characters + shortlink: https://sg.run/6DyK + semgrep.dev: + rule: + r_id: 67659 + rv_id: 946622 + rule_id: 5rUD6Z + version_id: DkTNp8K + url: https://semgrep.dev/playground/r/DkTNp8K/solidity.security.no-bidi-characters.no-bidi-characters + origin: community + patterns: + - pattern-either: + - pattern-regex: "\u202A" + - pattern-regex: "\u202B" + - pattern-regex: "\u202D" + - pattern-regex: "\u202E" + - pattern-regex: "\u2066" + - pattern-regex: "\u2067" + - pattern-regex: "\u2068" + - pattern-regex: "\u202C" + - pattern-regex: "\u2069" + languages: + - solidity + severity: WARNING +- id: solidity.security.proxy-storage-collision.proxy-storage-collision + message: Proxy declares a state var that may override a storage slot of the implementation + metadata: + category: security + technology: + - solidity + cwe: 'CWE-787: Out-of-bounds Write' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://blog.audius.co/article/audius-governance-takeover-post-mortem-7-23-22 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.proxy-storage-collision.proxy-storage-collision + shortlink: https://sg.run/2GXr + semgrep.dev: + rule: + r_id: 67663 + rv_id: 946626 + rule_id: BYU0EL + version_id: qkT4jqp + url: https://semgrep.dev/playground/r/qkT4jqp/solidity.security.proxy-storage-collision.proxy-storage-collision + origin: community + patterns: + - pattern-either: + - pattern: | + contract $CONTRACT is ..., $PROXY, ... { + ... + $TYPE $VAR; + ... + constructor(...) { + ... + } + ... + } + - pattern: | + contract $CONTRACT is ..., $PROXY, ... { + ... + $TYPE $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE immutable $VAR; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE immutable $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE constant $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - metavariable-regex: + metavariable: $CONTRACT + regex: ^(?!AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy).*$ + - metavariable-regex: + metavariable: $PROXY + regex: (UpgradeabilityProxy|AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy|TransparentUpgradeableProxy|ERC1967Proxy) + - focus-metavariable: $PROXY + languages: + - solidity + severity: WARNING +- id: solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + message: transferFrom() can steal allowance of other accounts + metadata: + category: security + technology: + - solidity + cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://medium.com/immunefi/redacted-cartel-custom-approval-logic-bugfix-review-9b2d039ca2c5 + - https://etherscan.io/address/0x186E55C0BebD2f69348d94C4A27556d93C5Bd36C + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + shortlink: https://sg.run/XDzj + semgrep.dev: + rule: + r_id: 67664 + rv_id: 946627 + rule_id: DbU0Qb + version_id: l4Tx9Px + url: https://semgrep.dev/playground/r/l4Tx9Px/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + origin: community + patterns: + - pattern-inside: | + function transferFrom(...) { + ... + } + - pattern: _approve(..., allowance(sender, recipient).sub(amount, ...), ...); + languages: + - solidity + severity: ERROR +- id: solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + message: setMultipleAllowances() is missing onlyOwner modifier + metadata: + category: security + technology: + - solidity + cwe: 'CWE-284: Improper Access Control' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/danielvf/status/1494317265835147272 + - https://etherscan.io/address/0x876b9ebd725d1fa0b879fcee12560a6453b51dc8 + - https://play.secdim.com/game/dapp/challenge/rigoownsol + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + shortlink: https://sg.run/jbZP + semgrep.dev: + rule: + r_id: 67665 + rv_id: 946628 + rule_id: WAUpbw + version_id: YDTvRP2 + url: https://semgrep.dev/playground/r/YDTvRP2/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + origin: community + patterns: + - pattern: function setMultipleAllowances(...) {...} + - pattern-not: function setMultipleAllowances(...) onlyOwner {...} + languages: + - solidity + severity: ERROR +- id: solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + message: A specially crafted calldata may be used to impersonate other accounts + metadata: + category: security + technology: + - solidity + cwe: 'CWE-20: Improper Input Validation' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://rekt.news/superfluid-rekt/ + - https://medium.com/superfluid-blog/08-02-22-exploit-post-mortem-15ff9c97cdd + - https://polygonscan.com/address/0x07711bb6dfbc99a1df1f2d7f57545a67519941e7 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + shortlink: https://sg.run/9KNy + semgrep.dev: + rule: + r_id: 67667 + rv_id: 946630 + rule_id: KxUqld + version_id: o5TZexb + url: https://semgrep.dev/playground/r/o5TZexb/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + origin: community + patterns: + - pattern: $T.decodeCtx(ctx); + - pattern-not-inside: | + require($T.isCtxValid(...), "..."); + ... + languages: + - solidity + severity: ERROR +- patterns: + - pattern-either: + - pattern: | + provisioner "remote-exec" { + ... + } + - pattern: | + provisioner "local-exec" { + ... + } + - pattern-inside: | + resource "aws_instance" "..." { + ... + } + id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + message: Provisioners are a tool of last resort and should be avoided where possible. + Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute + arbitrary shell commands by design. + languages: + - terraform + severity: WARNING + metadata: + category: security + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command + Injection'')' + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + subcategory: + - audit + confidence: HIGH + likelihood: HIGH + impact: MEDIUM + technology: + - terraform + references: + - https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec + - https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + shortlink: https://sg.run/7EjQ + semgrep.dev: + rule: + r_id: 70982 + rv_id: 1263736 + rule_id: EwUxO1 + version_id: bZT53j1 + url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + origin: community +- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + languages: + - clojure + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://xerces.apache.org/xerces2-j/features.html + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml + category: security + technology: + - clojure + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + shortlink: https://sg.run/v7An + semgrep.dev: + rule: + r_id: 71533 + rv_id: 1262608 + rule_id: bwU3Gj + version_id: WrTqKyD + url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + origin: community + message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. + Without prohibiting external entity declarations, this is vulnerable to XML external + entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern-inside: | + (ns ... (:require [clojure.xml :as ...])) + ... + - pattern-either: + - pattern-inside: | + (def ... ... ( ... )) + - pattern-inside: | + (defn ... ... ( ... )) + - pattern-either: + - pattern: (clojure.xml/parse $INPUT) + - patterns: + - pattern-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) + - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" + false) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ...) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ...) +- id: clojure.lang.security.use-of-sha1.use-of-sha1 + languages: + - clojure + severity: WARNING + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-328: Use of Weak Hash' + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/dvwX + semgrep.dev: + rule: + r_id: 71534 + rv_id: 1262610 + rule_id: NbUy12 + version_id: K3TKk7E + url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 + origin: community + patterns: + - pattern-either: + - pattern: (MessageDigest/getInstance $ALGO) + - pattern: (java.security.MessageDigest/getInstance $ALGO) + - metavariable-regex: + metavariable: $ALGO + regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) +- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + languages: + - generic + severity: INFO + message: Visualforce Pages must have the cspHeader attribute set to true. This attribute + is available in API version 55 or higher. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + shortlink: https://sg.run/yoj8 + semgrep.dev: + rule: + r_id: 72424 + rv_id: 1262907 + rule_id: DbUj7d + version_id: RGT0L0r + url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + origin: community + patterns: + - pattern: ... + - pattern-not: ... + - pattern-not: ...... + - pattern-not: ...... + paths: + include: + - '*.page' +- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + languages: + - generic + severity: WARNING + message: Visualforce Pages must use API version 55 or higher for required use of + the cspHeader attribute set to true. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + shortlink: https://sg.run/rWr6 + semgrep.dev: + rule: + r_id: 72425 + rv_id: 1262908 + rule_id: WAUwJW + version_id: A8Tgdgn + url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + origin: community + patterns: + - pattern-inside: + - pattern-either: + - pattern-regex: '[>][0-9].[0-9][<]' + - pattern-regex: '[>][1-4][0-9].[0-9][<]' + - pattern-regex: '[>][5][0-4].[0-9][<]' + paths: + include: + - '*.page-meta.xml' +- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret + languages: + - python + message: The Django secret key is used as salt in HashIDs. The HashID mechanism + is not secure. By observing sufficient HashIDs, the salt used to construct them + can be recovered. This means the Django secret key can be obtained by attackers, + through the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - django + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret + shortlink: https://sg.run/bxeZ + semgrep.dev: + rule: + r_id: 72426 + rv_id: 946163 + rule_id: 0oUXqy + version_id: 0bT15nn + url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) + - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) + severity: ERROR +- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + languages: + - python + message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is + not secure. By observing sufficient HashIDs, the salt used to construct them can + be recovered. This means the Flask secret key can be obtained by attackers, through + the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - flask + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + shortlink: https://sg.run/N0Rx + semgrep.dev: + rule: + r_id: 72427 + rv_id: 946220 + rule_id: KxUX3z + version_id: 0bT15Px + url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) + - patterns: + - pattern-inside: | + $APP = flask.Flask(...) + ... + - pattern-either: + - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) + severity: ERROR +- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + patterns: + - pattern: | + "*" + - pattern-inside: | + resources: $A + ... + - pattern-inside: | + verbs: $A + ... + - pattern-inside: | + - apiGroups: [""] + ... + - pattern-inside: | + apiVersion: rbac.authorization.k8s.io/v1 + ... + - pattern-inside: | + kind: ClusterRole + ... + message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. + Attaching excessive permissions to a ClusterRole associated with the core namespace + allows the V1 API to perform arbitrary actions on arbitrary resources attached + to the cluster. Prefer explicit allowlists of verbs/resources when configuring + the core API namespace. ' + languages: + - yaml + severity: WARNING + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole + - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups + category: security + technology: + - kubernetes + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + shortlink: https://sg.run/x6Dz + semgrep.dev: + rule: + r_id: 73474 + rv_id: 1263935 + rule_id: GdUR2A + version_id: 9lT4bw7 + url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + origin: community +- id: go.lang.security.injection.open-redirect.open-redirect + languages: + - go + severity: WARNING + message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This + can lead to open redirect vulnerabilities, potentially allowing attackers to redirect + users to malicious web sites. It is recommend where possible to not allow user-input + to craft the redirect URL. When user-input is necessary to craft the request, + it is recommended to follow OWASP best practices to restrict the URL to domains + in an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + references: + - https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html + category: security + technology: + - go + confidence: HIGH + description: An HTTP redirect was found to be crafted from user-input leading + to an open redirect vulnerability + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect + shortlink: https://sg.run/2ZW45 + semgrep.dev: + rule: + r_id: 113619 + rv_id: 945608 + rule_id: DbU6RlN + version_id: GxTP7J7 + url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern: http.Redirect($W, $REQ, $URL, ...) + - focus-metavariable: $URL +- id: php.lang.security.base-convert-loses-precision.base-convert-loses-precision + message: The function base_convert uses 64-bit numbers internally, and does not + correctly convert large numbers. It is not suitable for random tokens such as + those used for session tokens or CSRF tokens. + metadata: + references: + - https://www.php.net/base_convert + - https://www.sjoerdlangkemper.nl/2017/03/15/dont-use-base-convert-on-random-tokens/ + category: security + technology: + - php + cwe: + - 'CWE-190: Integer Overflow or Wraparound' + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/php.lang.security.base-convert-loses-precision.base-convert-loses-precision + shortlink: https://sg.run/kxpGo + semgrep.dev: + rule: + r_id: 115928 + rv_id: 945988 + rule_id: 7KUgBAk + version_id: yeT0n4K + url: https://semgrep.dev/playground/r/yeT0n4K/php.lang.security.base-convert-loses-precision.base-convert-loses-precision + origin: community + languages: + - php + severity: WARNING + mode: taint + pattern-sources: + - pattern: hash(...) + - pattern: hash_hmac(...) + - pattern: sha1(...) + - pattern: md5(...) + - patterns: + - pattern: random_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + - patterns: + - pattern: openssl_random_pseudo_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + - patterns: + - pattern: $OBJ->get_random_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + pattern-sinks: + - pattern: base_convert(...) + pattern-sanitizers: + - patterns: + - pattern: substr(..., $LENGTH) + - metavariable-comparison: + metavariable: $LENGTH + comparison: $LENGTH <= 7 +- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + message: Detected the decoding of a JWT token without a verify step. JWT tokens + must be verified before use, otherwise the token's integrity is unknown. This + means a malicious actor could forge a JWT token with any claims. Set 'verify' + to `true` before using the token. + severity: ERROR + metadata: + owasp: + - A05:2021 - Security Misconfiguration + - A07:2021 - Identification and Authentication Failures + - A02:2025 - Security Misconfiguration + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + - 'CWE-345: Insufficient Verification of Data Authenticity' + - 'CWE-347: Improper Verification of Cryptographic Signature' + category: security + subcategory: + - vuln + technology: + - jwt-simple + - jwt + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + references: + - https://www.npmjs.com/package/jwt-simple + - https://cwe.mitre.org/data/definitions/287 + - https://cwe.mitre.org/data/definitions/345 + - https://cwe.mitre.org/data/definitions/347 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Improper Authentication + source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + shortlink: https://sg.run/zdjod + semgrep.dev: + rule: + r_id: 120561 + rv_id: 1263191 + rule_id: r6UyNLy + version_id: 3ZT4Xxv + url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + origin: community + languages: + - javascript + - typescript + patterns: + - pattern-inside: | + $JWT = require('jwt-simple'); + ... + - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) + - metavariable-pattern: + metavariable: $NOVERIFY + patterns: + - pattern-either: + - pattern: | + true + - pattern: | + "..." +- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + languages: + - solidity + message: Missing check for 'from' and 'to' being the same before updating balances + could lead to incorrect balance manipulation on self-transfers. Include a check + to ensure 'from' and 'to' are not the same before updating balances to prevent + balance manipulation during self-transfers. + severity: ERROR + metadata: + category: security + technology: + - blockchain + - solidity + cwe: 'CWE-682: Incorrect Calculation' + subcategory: + - vuln + confidence: HIGH + likelihood: HIGH + impact: HIGH + owasp: + - A7:2021 Identification and Authentication Failures + references: + - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities + - https://x.com/shoucccc/status/1757777764646859121 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + shortlink: https://sg.run/Or6X7 + semgrep.dev: + rule: + r_id: 133075 + rv_id: 946620 + rule_id: 6JUv7Nz + version_id: A8TJzYz + url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + origin: community + patterns: + - pattern-either: + - pattern: | + _balances[$FROM] = $FROM_BALANCE - value; + - pattern: | + _balances[$TO] = $TO_BALANCE + value; + - pattern-not-inside: | + if ($FROM != $TO) { + ... + _balances[$FROM] = $FROM_BALANCE - value; + ... + _balances[$TO] = $TO_BALANCE + value; + ... + } + - pattern-inside: | + function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual { + ... + } +- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + languages: + - yaml + message: Basic authentication is considered weak and should be avoided. Use a different + authentication scheme, such of OAuth2, OpenID Connect, or mTLS. + severity: ERROR + patterns: + - pattern-inside: | + openapi: $VERSION + ... + components: + ... + securitySchemes: + ... + $SCHEME: + ... + - metavariable-regex: + metavariable: $VERSION + regex: 3.* + - pattern: | + type: http + ... + scheme: basic + metadata: + category: security + subcategory: + - vuln + technology: + - openapi + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + cwe: 'CWE-287: Improper Authentication' + owasp: + - A04:2021 Insecure Design + - A07:2021 Identification and Authentication Failures + references: + - https://cwe.mitre.org/data/definitions/287.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + shortlink: https://sg.run/v8wNW + semgrep.dev: + rule: + r_id: 133077 + rv_id: 947072 + rule_id: zdUKgEX + version_id: 0bT1ErG + url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + origin: community +- id: generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + pattern-regex: (?:api_live(?:_[a-zA-Z]{2})?\.[a-zA-Z0-9-_]{11}\.[-_a-zA-Z0-9]{32}) + languages: + - regex + message: Onfido live API Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - onfido + confidence: HIGH + references: + - https://documentation.onfido.com/api/latest/#api-tokens + subcategory: + - audit + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + shortlink: https://sg.run/lBoKD + semgrep.dev: + rule: + r_id: 141957 + rv_id: 945509 + rule_id: WAUW9q3 + version_id: A8TJzE2 + url: https://semgrep.dev/playground/r/A8TJzE2/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + origin: community +- id: dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + message: The Dockerfile(image) mounts docker.sock to the container which may allow + an attacker already inside of the container to escape container and execute arbitrary + commands on the host machine. + languages: + - dockerfile + - yaml + severity: ERROR + metadata: + cwe: + - 'CWE-862: Missing Authorization' + - 'CWE-269: Improper Privilege Management' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - audit + technology: + - dockerfile + category: security + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html + - https://redfoxsec.com/blog/insecure-volume-mounts-in-docker/ + - https://blog.quarkslab.com/why-is-exposing-the-docker-socket-a-really-bad-idea.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + shortlink: https://sg.run/10AAQ + semgrep.dev: + rule: + r_id: 146566 + rv_id: 945266 + rule_id: oqUgAAk + version_id: WrTEoEq + url: https://semgrep.dev/playground/r/WrTEoEq/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + origin: community + pattern-either: + - patterns: + - pattern: VOLUME $X + - metavariable-regex: + metavariable: $X + regex: /var/run/docker.sock + - patterns: + - pattern-regex: '- "/var/run/docker.sock:.*"' + - pattern-inside: | + volumes: + ... +- id: javascript.node-crypto.security.aead-no-final.aead-no-final + message: The 'final' call of a Decipher object checks the authentication tag in + a mode for authenticated encryption. Failing to call 'final' will invalidate all + integrity guarantees of the released ciphertext. + metadata: + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final + shortlink: https://sg.run/r6EEA + semgrep.dev: + rule: + r_id: 146569 + rv_id: 1263222 + rule_id: 2ZUz884 + version_id: zyTb2X0 + url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.update(...) + - pattern-not-inside: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.final(...) + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ +- id: javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + message: The deprecated functions 'createCipher' and 'createDecipher' generate the + same initialization vector every time. For counter modes such as CTR, GCM, or + CCM this leads to break of both confidentiality and integrity, if the key is used + more than once. Other modes are still affected in their strength, though they're + not completely broken. Use 'createCipheriv' or 'createDecipheriv' instead. + metadata: + cwe: + - 'CWE-1204: Generation of Weak Initialization Vector (IV)' + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://nodejs.org/api/crypto.html#cryptocreatecipheralgorithm-password-options + - https://nodejs.org/api/crypto.html#cryptocreatedecipheralgorithm-password-options + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + shortlink: https://sg.run/bw33r + semgrep.dev: + rule: + r_id: 146570 + rv_id: 945898 + rule_id: X5UQRR7 + version_id: ZRT3510 + url: https://semgrep.dev/playground/r/ZRT3510/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-either: + - pattern: | + $CRYPTO.createCipher(...) + - pattern: | + $CRYPTO.createDecipher(...) +- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + languages: + - yaml + message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method: + $METHOD $PATH. This Action configuration will enable the ''Always Allow'' option + for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk + of a user selecting the ''Always Allow'' button is that the agent could perform + unintended actions on behalf of the user. When working with sensitive functionality, + it is always best to include a Human In The Loop (HITL) type of control. Consider + the trade-off between security and user friction and then make a risk-based decision + about this function.' + severity: WARNING + pattern-either: + - pattern-inside: | + post: + ... + x-openai-isConsequential: false + - pattern-inside: | + put: + ... + x-openai-isConsequential: false + - pattern-inside: | + patch: + ... + x-openai-isConsequential: false + - pattern-inside: | + delete: + ... + x-openai-isConsequential: false + metadata: + category: security + subcategory: + - audit + technology: + - openapi + - openai + likelihood: HIGH + impact: HIGH + confidence: HIGH + cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' + owasp: + - A04:2021 Insecure Design + - LLM08:2023 - Excessive Agency + references: + - https://platform.openai.com/docs/actions/consequential-flag + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + shortlink: https://sg.run/x8EEP + semgrep.dev: + rule: + r_id: 146574 + rv_id: 947071 + rule_id: yyURooD + version_id: WrTEZN8 + url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + origin: community +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + pattern-either: + - patterns: + - pattern-inside: | + import "crypto/sha256" + ... + - pattern-either: + - pattern: | + sha256.New224() + - pattern: | + sha256.Sum224(...) + - patterns: + - pattern-inside: | + import "golang.org/x/crypto/sha3" + ... + - pattern-either: + - pattern: | + sha3.New224() + - pattern: | + sha3.Sum224(...) + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + category: security + technology: + - go + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + shortlink: https://sg.run/ReJwY + semgrep.dev: + rule: + r_id: 151749 + rv_id: 1262925 + rule_id: GdUvElR + version_id: 9lT4b4w + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + origin: community +- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + shortlink: https://sg.run/Ab2KQ + semgrep.dev: + rule: + r_id: 151750 + rv_id: 1263017 + rule_id: ReUDGEz + version_id: YDTZewo + url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + origin: community + pattern-either: + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) + - patterns: + - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: php.lang.security.audit.sha224-hash.sha224-hash + pattern-either: + - pattern: hash('sha224', ...); + - pattern: hash('sha512/224', ...); + - pattern: hash('sha3-224', ...); + - pattern: hash_hmac('sha224', ...); + - pattern: hash_hmac('sha512/224', ...); + - pattern: hash_hmac('sha3-224', ...); + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - php + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/BYXqv + semgrep.dev: + rule: + r_id: 151751 + rv_id: 1263275 + rule_id: AbU97EA + version_id: bZT53Jo + url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - php + severity: WARNING +- id: python.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/Db1Yv + semgrep.dev: + rule: + r_id: 151752 + rv_id: 1263511 + rule_id: BYUX0y9 + version_id: 5PTo1QL + url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: hashlib.sha224(...) + - pattern: hashlib.sha3_224(...) +- id: ruby.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/WABbo + semgrep.dev: + rule: + r_id: 151753 + rv_id: 1263592 + rule_id: DbU60wQ + version_id: 8KT5rRY + url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - ruby + severity: WARNING + pattern-either: + - pattern: Digest::SHA224.$FUNC + - pattern: OpenSSL::Digest::SHA224.$FUNC + - pattern: SHA3::Digest::SHA224(...) + - patterns: + - pattern-either: + - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) + - pattern: OpenSSL::HMAC.digest("$ALGO", ...) + - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") + - pattern: OpenSSL::Digest.digest("$ALGO", ...) + - pattern: OpenSSL::Digest.new("$ALGO", ...) + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + message: Function `flask.url_for` with `_external=True` argument will generate URLs + using the `Host` header of the HTTP request, which may lead to security risks + such as Host header injection + metadata: + cwe: + - 'CWE-673: External Influence of Sphere Definition' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/latest/api/#flask.url_for + - https://portswigger.net/kb/issues/00500300_host-header-injection + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + shortlink: https://sg.run/gEGeR + semgrep.dev: + rule: + r_id: 191541 + rv_id: 1263418 + rule_id: JDU5oql + version_id: K3TKk6n + url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-not: flask.url_for(..., _external=False, ...) + - pattern-not: url_for(..., _external=False, ...) + - pattern-either: + - pattern: flask.url_for(..., _external=$VAR, ...) + - pattern: url_for(..., _external=$VAR, ...) +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action + with the name `discussion.yaml`. + paths: + include: + - '**/.github/workflows/discussion.yaml' + metadata: + category: security + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + shortlink: https://sg.run/JdYPZ + semgrep.dev: + rule: + r_id: 238946 + rv_id: 1263927 + rule_id: 7KUDRPj + version_id: 6xT29ol + url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, + which can lead to security vulnerabilities (CWE-502). Use a concrete struct type + instead. + severity: WARNING + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + category: security + technology: + - go + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/502.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + shortlink: https://sg.run/6WbKL + semgrep.dev: + rule: + r_id: 274359 + rv_id: 1409387 + rule_id: 4bUAQDG + version_id: ZRTDkjk + url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + origin: community + patterns: + - pattern-either: + - pattern: | + var $VAR interface{} + ... + json.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + yaml.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + xml.Unmarshal($DATA, &$VAR) +- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch + names can be silently repointed by the action owner, enabling supply-chain attacks + \u2014 as seen in the trivy-action and kics-github-action compromises. Pin the + reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`." + severity: WARNING + languages: + - yaml + metadata: + category: security + cwe: + - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' + - 'CWE-353: Missing Support for Integrity Check' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + shortlink: https://sg.run/2LgAL + semgrep.dev: + rule: + r_id: 288863 + rv_id: 1413422 + rule_id: GdUxYDx + version_id: xyTRDAd + url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + origin: community + patterns: + - pattern-inside: '{steps: ...}' + - pattern: | + uses: "$ACTION" + - metavariable-pattern: + metavariable: $ACTION + language: generic + patterns: + - pattern-not-regex: ^\./ + - pattern-not-regex: ^docker:// + - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' +- id: yaml.github-actions.security.secrets-inherit.secrets-inherit + languages: + - yaml + severity: ERROR + message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s + secrets to a reusable workflow. This violates the principle of least privilege + because the called workflow receives access to every secret in the repository, + not just the ones it needs. If the called workflow is compromised or sourced from + a third party, an attacker gains access to all repository secrets. Instead, explicitly + pass only the secrets that the called workflow requires using the `secrets:` map, + e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.' + metadata: + category: security + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow + - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit + shortlink: https://sg.run/X2PZB + semgrep.dev: + rule: + r_id: 288864 + rv_id: 1413424 + rule_id: ReUQnKg + version_id: e1T42L1 + url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit + origin: community + patterns: + - pattern-inside: | + jobs: + ... + - pattern: 'secrets: inherit' +- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*minimumReleaseAge) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: minimumReleaseAge\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 604800 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ + message: 'This bunfig.toml does not set a minimum release age or sets it too low. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge + = 604800` under the `[install]` section to wait 7 days before resolving newly + published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/bunfig.toml' + - '**/.bunfig.toml' + metadata: + category: security + technology: + - bun + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://bun.sh/docs/runtime/bunfig + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + shortlink: https://sg.run/JqPrR + semgrep.dev: + rule: + r_id: 291646 + rv_id: 1423385 + rule_id: oqUyJOb + version_id: BjTyRe5 + url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + origin: community +- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + pattern-either: + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + - package-ecosystem: $ECOSYSTEM + ... + - pattern-not: | + - package-ecosystem: $ECOSYSTEM + ... + cooldown: + ... + ... + - patterns: + - pattern-inside: | + updates: + ... + - pattern-regex: default-days\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + cooldown: + default-days: $DAYS + - metavariable-regex: + metavariable: $DAYS + regex: ^\D + - focus-metavariable: $DAYS + message: 'This Dependabot configuration does not set a cooldown period. Newly published + packages can be malicious or unstable. Add a `cooldown` block with `default-days: + 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing + updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.github/dependabot.yml' + - '**/.github/dependabot.yaml' + metadata: + category: security + technology: + - dependabot + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + shortlink: https://sg.run/5WvGK + semgrep.dev: + rule: + r_id: 291647 + rv_id: 1423386 + rule_id: zdUArOL + version_id: DkTwEGl + url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + origin: community +- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) + - pattern-not-regex: min-release-age + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: min-release-age\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)min-release-age\s*=\s*$ + message: 'This .npmrc does not set a minimum release age or sets it too low. Newly + published packages can be malicious or unstable. Add `min-release-age = 7` to + wait 7 days before resolving newly published package versions. Added in: v11.10 + Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/.npmrc' + metadata: + category: security + technology: + - npm + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ + - https://github.com/npm/cli/pull/8965 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + shortlink: https://sg.run/GRo1z + semgrep.dev: + rule: + r_id: 291648 + rv_id: 1423387 + rule_id: pKU6A82 + version_id: WrT7LdL + url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` + to transitive dependencies from being installed from untrusted sources. Added + in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + blockExoticSubdeps: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!true$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#blockexoticsubdeps + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + shortlink: https://sg.run/RrWRv + semgrep.dev: + rule: + r_id: 291649 + rv_id: 1423388 + rule_id: 2ZUQEZ5 + version_id: 0bTGnwj + url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + origin: community +- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + message: 'This pnpm workspace configuration does not set a minimum release age. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge: + 10080` (minutes) to wait at least seven days before installing newly published + package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 10080 + - focus-metavariable: $AGE + - patterns: + - pattern: | + minimumReleaseAge: $AGE + - metavariable-regex: + metavariable: $AGE + regex: ^\D + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + shortlink: https://sg.run/Aj0o0 + semgrep.dev: + rule: + r_id: 291650 + rv_id: 1423389 + rule_id: X5Uwn1n + version_id: K3TgxrW + url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent + malicious package updates from downgrading security settings. Added in: v10.21.0 + Reference: https://pnpm.io/settings#trustpolicy' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + trustPolicy: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!no-downgrade$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + shortlink: https://sg.run/B2Kz7 + semgrep.dev: + rule: + r_id: 291651 + rv_id: 1423390 + rule_id: j2U6J8N + version_id: qkTvDQn + url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + origin: community +- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-either: + - pattern: | + { ..., "matchPackageNames": [...], ... } + - pattern: | + { ..., "matchPackagePatterns": [...], ... } + - pattern: | + { ..., "matchDepTypes": [...], ... } + - pattern-not: | + { + ..., + "minimumReleaseAge": $AGE, + ... + } + - pattern-not: | + { + ..., + "minimumReleaseAge": false, + ... + } + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern: | + "minimumReleaseAge": "$AGE" + - metavariable-regex: + metavariable: $AGE + regex: ^(?!\d+ days?$) + - focus-metavariable: $AGE + message: 'This Renovate configuration does not set a minimum release age. Newly + published packages can be malicious or unstable. Add `"minimumReleaseAge": "7 + days"` within a `packageRules` entry to wait 7 days before proposing updates to + newly published package versions. Set `"minimumReleaseAge": false` to set an exception + for minimal release age for the package rule. Added in: v42' + languages: + - json + severity: MEDIUM + paths: + include: + - '**/renovate.json' + - '**/renovate.json5' + - '**/.renovaterc' + - '**/.renovaterc.json' + - '**/.renovaterc.json5' + metadata: + category: security + technology: + - renovate + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.renovatebot.com/configuration-options/#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + shortlink: https://sg.run/D8l2q + semgrep.dev: + rule: + r_id: 291652 + rv_id: 1443454 + rule_id: 10UbQrX + version_id: jQT1KAX + url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + origin: community +- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + pattern-either: + - patterns: + - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*exclude-newer) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P\d+) days?" + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" + - metavariable-regex: + metavariable: $VAL + regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T) + - focus-metavariable: $VAL + message: 'This pyproject.toml configures uv but does not set a dependency cooldown. + Newly published packages can be malicious or unstable. Add `exclude-newer = "7 + days"` under `[tool.uv]` to wait 7 days before resolving newly published package + versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/pyproject.toml' + - '**/uv.toml' + metadata: + category: security + technology: + - uv + - python + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + shortlink: https://sg.run/WeY0Z + semgrep.dev: + rule: + r_id: 291653 + rv_id: 1423392 + rule_id: 9AUo6vE + version_id: YDTwLle + url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + origin: community +- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) + - metavariable-regex: + metavariable: $VAL + regex: ^(?!['"]?\d+d['"]?$) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ + message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly + published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"` + to wait 7 days before resolving newly published package versions. Added in: 4.10 + Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.yarnrc.yml' + metadata: + category: security + technology: + - yarn + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + shortlink: https://sg.run/0gvNq + semgrep.dev: + rule: + r_id: 291654 + rv_id: 1423393 + rule_id: yyUBeEz + version_id: JdTnXlj + url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + origin: community +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell + interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote + server is compromised or the URL is hijacked, an attacker can execute arbitrary + code in your CI runner. Consider downloading the file first, verifying its checksum + or signature, and then executing it." + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + technology: + - github-actions + - bash + - curl + cwe2021-top25: true + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + shortlink: https://sg.run/GR8K1 + semgrep.dev: + rule: + r_id: 309392 + rv_id: 1443456 + rule_id: x8UAgrE + version_id: 9lT3zYb + url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + message: Dangerously accepting invalid TLS information + pattern-either: + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true) + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true) + metadata: + references: + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs + technology: + - reqwest + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + shortlink: https://sg.run/DqrG + semgrep.dev: + rule: + r_id: 40108 + rv_id: 946551 + rule_id: qNUKDg + version_id: 7ZTrQLJ + url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + origin: community + languages: + - rust + severity: WARNING +- id: rust.lang.security.rustls-dangerous.rustls-dangerous + message: Dangerous client config used, ensure SSL verification + pattern-either: + - pattern: rustls::client::DangerousClientConfig + - pattern: $CLIENT.dangerous().set_certificate_verifier(...) + - pattern: | + let $CLIENT = rustls::client::ClientConfig::dangerous(...); + ... + $CLIENT.set_certificate_verifier(...); + metadata: + references: + - https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html + - https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous + technology: + - rustls + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous + shortlink: https://sg.run/01Rw + semgrep.dev: + rule: + r_id: 40110 + rv_id: 946553 + rule_id: YGU8LK + version_id: 8KTKjdO + url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous + origin: community + languages: + - rust + severity: WARNING +- id: rust.lang.security.ssl-verify-none.ssl-verify-none + message: SSL verification disabled, this allows for MitM attacks + pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE) + metadata: + references: + - https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify + technology: + - openssl + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none + shortlink: https://sg.run/K2Pn + semgrep.dev: + rule: + r_id: 40111 + rv_id: 946554 + rule_id: 6JU0Bl + version_id: gETe1bo + url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none + origin: community + languages: + - rust + severity: WARNING diff --git a/backend/app/sandbox/rules/cwe-top-25.yaml b/backend/app/sandbox/rules/cwe-top-25.yaml new file mode 100644 index 0000000..fab9c49 --- /dev/null +++ b/backend/app/sandbox/rules/cwe-top-25.yaml @@ -0,0 +1,20054 @@ +rules: +- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + pattern-regex: rk_live_[0-9a-zA-Z]{24} + languages: + - regex + message: Stripe Restricted API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - stripe + confidence: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + shortlink: https://sg.run/ZvdL + semgrep.dev: + rule: + r_id: 9079 + rv_id: 1262900 + rule_id: 5rUOWq + version_id: K3TKkKj + url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + origin: community +- id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + patterns: + - pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END + - metavariable-regex: + metavariable: $...USERNAME + regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z + - metavariable-regex: + metavariable: $...PASSWORD + regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32} + - metavariable-regex: + metavariable: $PROTOCOL + regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*) + languages: + - generic + message: Username and password in URI detected + severity: ERROR + metadata: + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + shortlink: https://sg.run/8yA4 + semgrep.dev: + rule: + r_id: 9084 + rv_id: 1262903 + rule_id: DbUple + version_id: YDTZeZE + url: https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + origin: community +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - jwt + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + shortlink: https://sg.run/Rod2 + semgrep.dev: + rule: + r_id: 9093 + rv_id: 1262920 + rule_id: GdU7Ny + version_id: pZT0305 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + origin: community + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + []byte("$F") + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $TOKEN.SignedString($F) + - focus-metavariable: $F +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + patterns: + - pattern-either: + - patterns: + - pattern: | + exec.Cmd {...,Path: $CMD,...} + - pattern-not: | + exec.Cmd {...,Path: "...",...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: $ARGS,...} + - pattern-not: | + exec.Cmd {...,Args: []string{...},...} + - pattern-not-inside: | + $ARGS = []string{"...",...}; + ... + - pattern-not-inside: | + $CMD = "..."; + ... + $ARGS = []string{$CMD,...}; + ... + - pattern-not-inside: | + $CMD = exec.LookPath("..."); + ... + $ARGS = []string{$CMD,...}; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,...},...} + - pattern-not: | + exec.Cmd {...,Args: []string{"...",...},...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern-either: + - pattern: | + exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...} + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...} + - pattern-inside: | + $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); + ... + - pattern-not: | + exec.Cmd {...,Args: []string{"...","...","...",...},...} + - pattern-not-inside: | + $EXE = "..."; + ... + - pattern-inside: | + import "os/exec" + ... + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + shortlink: https://sg.run/Dorj + semgrep.dev: + rule: + r_id: 9108 + rv_id: 1262934 + rule_id: 2ZUb8l + version_id: e1Tyjeg + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + origin: community + severity: ERROR + languages: + - go +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. If user data can reach this template, you may have a XSS vulnerability. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + category: security + technology: + - go + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + shortlink: https://sg.run/weE0 + semgrep.dev: + rule: + r_id: 9129 + rv_id: 1262943 + rule_id: 8GUjDW + version_id: gETB7Pe + url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTML($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTML($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTML($OTHER, ...) +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + patterns: + - pattern-inside: | + func $FUNC(..., $W http.ResponseWriter, ...) { + ... + var $TEMPLATE = "..." + ... + $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) + ... + } + - pattern-either: + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) + message: Found data going from url query parameters into formatted data written + to ResponseWriter. This could be XSS and should not be done. If you must do this, + ensure your data is sanitized or escaped. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + shortlink: https://sg.run/Zvon + semgrep.dev: + rule: + r_id: 9135 + rv_id: 1262949 + rule_id: JDUyXB + version_id: 5PTo1qr + url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + origin: community + severity: WARNING + languages: + - go +- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + technology: + - java + - secrets + - jwt + category: security + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + shortlink: https://sg.run/RoDK + semgrep.dev: + rule: + r_id: 9149 + rv_id: 1262980 + rule_id: oqUeAn + version_id: d6Tyx8j + url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - pattern: | + (Algorithm $ALG) = $ALGO.$HMAC("$Y"); + - pattern: | + $SECRET = "$Y"; + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + - pattern: | + class $CLASS { + ... + $TYPE $SECRET = "$Y"; + ... + $RETURNTYPE $FUNC (...) { + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + ... + } + ... + } + - focus-metavariable: $Y + - metavariable-regex: + metavariable: $HMAC + regex: (HMAC384|HMAC256|HMAC512) +- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - jax-rs + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + shortlink: https://sg.run/DoWj + semgrep.dev: + rule: + r_id: 9152 + rv_id: 1262984 + rule_id: 2ZUb9l + version_id: 7ZTE3KW + url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } + - pattern: |- + $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } +- id: java.jboss.security.session_sqli.find-sql-string-concatenation + message: In $METHOD, $X is used to construct a SQL query via string concatenation. + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + Session $SESSION = ...; + ... + String $QUERY = ... + $X + ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + String $QUERY = ... + $X + ...; + ... + Session $SESSION = ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + metadata: + category: security + technology: + - jboss + confidence: MEDIUM + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation + shortlink: https://sg.run/W8kA + semgrep.dev: + rule: + r_id: 9153 + rv_id: 1262986 + rule_id: X5U8rQ + version_id: 8KT5r3v + url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation + origin: community +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + shortlink: https://sg.run/oxXN + semgrep.dev: + rule: + r_id: 9160 + rv_id: 1263064 + rule_id: NbUk7X + version_id: zyTb2rq + url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (java.io.File $FILE) = ... + - pattern: | + (java.io.FileOutputStream $FOS) = ... + - pattern: | + new java.io.FileInputStream(...) + severity: ERROR + languages: + - java +- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.3 Insecue Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + shortlink: https://sg.run/zvO1 + semgrep.dev: + rule: + r_id: 9161 + rv_id: 1263065 + rule_id: kxUk12 + version_id: pZT03A1 + url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + origin: community + message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling + of the message payload when ObjectMessage.getObject() is called. Deserialization + of untrusted data can lead to security flaws; a remote attacker could via a crafted + JMS ObjectMessage to execute arbitrary code with the permissions of the application + listening/consuming JMS Messages. In this case, the JMS MessageListener consume + an ObjectMessage type received inside the onMessage method, which may lead to + arbitrary code execution when calling the $Y.getObject method. + patterns: + - pattern-inside: | + public class $JMS_LISTENER implements MessageListener { + ... + public void onMessage(Message $JMS_MSG) { + ... + } + } + - pattern-either: + - pattern-inside: $X = $Y.getObject(...); + - pattern-inside: $X = ($Z) $Y.getObject(...); +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + message: 'Cross-site scripting detected in HttpServletResponse writer with variable + ''$VAR''. User input was detected going directly from the HttpServletRequest into + output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + ''Encode.forHtml($VAR)''.' + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + shortlink: https://sg.run/pxjN + semgrep.dev: + rule: + r_id: 9162 + rv_id: 1263066 + rule_id: wdUJOk + version_id: 2KTv2EG + url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + origin: community + severity: ERROR + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: | + $WRITER = $RESP.getWriter(...); + ... + $WRITER.write(..., $VAR, ...); + languages: + - java +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + shortlink: https://sg.run/XBwA + semgrep.dev: + rule: + r_id: 9164 + rv_id: 1263069 + rule_id: OrU35O + version_id: 1QTypQZ + url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + origin: community + message: XML external entities are not explicitly disabled for this XMLInputFactory. + This could be vulnerable to XML external entity vulnerabilities. Explicitly disable + external entities by setting "javax.xml.stream.isSupportingExternalEntities" to + false. + patterns: + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); + ... + } + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + languages: + - java +- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps + - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string + shortlink: https://sg.run/OPXp + semgrep.dev: + rule: + r_id: 9175 + rv_id: 1409389 + rule_id: QrUzxR + version_id: ExTeyBP + url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + $ANNOT $FUNC (..., $INPUT, ...) { + ... + } + - pattern: (String $INPUT) + - focus-metavariable: $INPUT + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $INPUT + - pattern: $X += $INPUT + - pattern: String.format(..., $INPUT, ...) + - pattern: String.join(..., $INPUT, ...) + - pattern: (String $STR).concat($INPUT) + - pattern: $INPUT.concat(...) + - patterns: + - pattern-either: + - pattern: $STRB.append($INPUT) + - pattern: new $STRB(..., $INPUT, ...) + - metavariable-type: + metavariable: $STRB + type: StringBuilder + label: CONCAT + requires: INPUT + pattern-propagators: + - pattern: (StringBuffer $S).append($X) + from: $X + to: $S + - pattern: (StringBuilder $S).append($X) + from: $X + to: $S + pattern-sinks: + - patterns: + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) + - pattern-either: + - pattern: (Statement $S).$SQLFUNC(...) + - pattern: (PreparedStatement $P).$SQLFUNC(...) + - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) + - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) + - pattern: (EntityManager $EM).$SQLFUNC(...) + - metavariable-regex: + metavariable: $SQLFUNC + regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare + requires: CONCAT + pattern-sanitizers: + - patterns: + - pattern: (CriteriaBuilder $CB).$ANY(...) + severity: ERROR + languages: + - java +- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + message: Detected a request with potential user-input going into a OutputStream + or Writer object. This bypasses any view or template environments, including HTML + escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. + Consider using a view technology such as JavaServer Faces (JSFs) which automatically + escapes HTML views. + severity: WARNING + options: + interfile: true + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html + subcategory: + - vuln + technology: + - java + - servlets + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + shortlink: https://sg.run/KlRL + semgrep.dev: + rule: + r_id: 9211 + rv_id: 1263055 + rule_id: j2Uv7B + version_id: DkTRbXy + url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + origin: community + languages: + - java + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...) + - pattern: | + (HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...) + - pattern: | + (java.io.PrintWriter $WRITER).$WRITE(...) + - pattern: | + (PrintWriter $WRITER).$WRITE(...) + - pattern: | + (javax.servlet.ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (java.io.OutputStream $WRITER).$WRITE(...) + - pattern: | + (OutputStream $WRITER).$WRITE(...) + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) + - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) + - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) + - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) +- id: java.spring.security.audit.spring-sqli.spring-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: $ARG + - pattern-inside: | + public $T $M (..., String $ARG,...){...} + pattern-sanitizers: + - not_conflicting: true + pattern-either: + - patterns: + - focus-metavariable: $A + - pattern-inside: | + new $TYPE(...,$A,...); + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - focus-metavariable: $A + - pattern: | + new PreparedStatementCreatorFactory($A,...); + - patterns: + - focus-metavariable: $A + - pattern: | + (JdbcTemplate $T).$M($A,...) + - patterns: + - pattern: (String $A) + - pattern-inside: | + (JdbcTemplate $T).batchUpdate(...) + - patterns: + - focus-metavariable: $A + - pattern: | + NamedParameterBatchUpdateUtils.$M($A,...) + - patterns: + - focus-metavariable: $A + - pattern: | + BatchUpdateUtils.$M($A,...) + message: Detected a string argument from a public method contract in a raw SQL statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You + can obtain a PreparedStatement using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - spring + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli + shortlink: https://sg.run/1Z3x + semgrep.dev: + rule: + r_id: 9222 + rv_id: 1263082 + rule_id: eqU8N2 + version_id: ZRTKAWW + url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli + origin: community +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) + in an AngularJS application could provide additional attack surface for XSS vulnerabilities. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + shortlink: https://sg.run/N4DG + semgrep.dev: + rule: + r_id: 9227 + rv_id: 1263094 + rule_id: EwU20Z + version_id: 5PTo1EW + url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern: | + $sceProvider.enabled(false); +- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + message: The use of $sce.trustAs can be dangerous if unsanitized user input flows + through this API. + metadata: + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + shortlink: https://sg.run/OPW2 + semgrep.dev: + rule: + r_id: 9231 + rv_id: 1263098 + rule_id: gxU1QX + version_id: BjTkZv0 + url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + app.controller(..., function($scope,$sce) { + ... + }); + - pattern: $scope.$X + pattern-sinks: + - pattern: $sce.trustAs(...) + - pattern: $sce.trustAsHtml(...) +- id: javascript.browser.security.raw-html-concat.raw-html-concat + message: User controlled data in a HTML string may result in XSS + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/xss/ + category: security + technology: + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat + shortlink: https://sg.run/4xAx + semgrep.dev: + rule: + r_id: 9244 + rv_id: 1263123 + rule_id: 0oU5b5 + version_id: 2KTv2wp + url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $STRING + $EXPR + - pattern-not: $STRING + "..." + - metavariable-pattern: + patterns: + - pattern: <$TAG ... + - pattern-not: <$TAG ...>...... + metavariable: $STRING + language: generic + - patterns: + - pattern: $EXPR + $STRING + - pattern-not: '"..." + $STRING' + - metavariable-pattern: + patterns: + - pattern: '... + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('node-expat') + ... + - pattern-inside: | + import $XML from 'node-expat' + ... + - pattern-inside: | + import * as $XML from 'node-expat' + ... + - pattern-either: + - pattern-inside: | + $PARSER = new $XML.Parser(...); + ... + - pattern-either: + - pattern: $PARSER.parse($QUERY) + - pattern: $PARSER.write($QUERY) + - focus-metavariable: $QUERY +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + shortlink: https://sg.run/Do1d + semgrep.dev: + rule: + r_id: 9252 + rv_id: 1263166 + rule_id: pKUOjy + version_id: pZT03Q0 + url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern-inside: | + import $JWT from 'express-jwt'; + ... + - pattern-inside: | + import * as $JWT from 'express-jwt'; + ... + - pattern-inside: | + import { ..., $JWT, ... } from 'express-jwt'; + ... + - pattern-either: + - pattern: | + $JWT({...,secret: "$Y",...},...) + - pattern: | + $OPTS = "$Y"; + ... + $JWT({...,secret: $OPTS},...); + - focus-metavariable: $Y +- id: javascript.express.security.express-phantom-injection.express-phantom-injection + message: If unverified user data can reach the `phantom` methods it can result in + Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://phantomjs.org/page-automation.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection + shortlink: https://sg.run/W8BL + semgrep.dev: + rule: + r_id: 9253 + rv_id: 1263167 + rule_id: 2ZUbx3 + version_id: 2KTv26p + url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('phantom'); + ... + - pattern-inside: | + import 'phantom'; + ... + - pattern-either: + - pattern: $PAGE.open($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.openUrl($SINK,...) + - pattern: $PAGE.evaluateJavaScript($SINK,...) + - pattern: $PAGE.property("content",$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + message: If unverified user data can reach the `puppeteer` methods it can result + in Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://pptr.dev/api/puppeteer.page + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + shortlink: https://sg.run/0QJB + semgrep.dev: + rule: + r_id: 9254 + rv_id: 1263168 + rule_id: X5U8Nz + version_id: X0TzyJY + url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('puppeteer'); + ... + - pattern-inside: | + import 'puppeteer'; + ... + - pattern-either: + - pattern: $PAGE.goto($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.evaluate($SINK,...) + - pattern: $PAGE.evaluate($CODE,$SINK,...) + - pattern: $PAGE.evaluateHandle($SINK,...) + - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + message: Make sure that unverified user data can not reach `sandbox`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + shortlink: https://sg.run/KlwL + semgrep.dev: + rule: + r_id: 9255 + rv_id: 1263169 + rule_id: j2UvXB + version_id: jQTn59D + url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $SANDBOX = require('sandbox'); + ... + - pattern-either: + - patterns: + - pattern-inside: | + $S = new $SANDBOX(...); + ... + - pattern: | + $S.run(...) + - pattern: | + new $SANDBOX($OPTS).run(...) + - pattern: new $SANDBOX().run(...) +- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + message: Make sure that unverified user data can not reach the XML Parser, as it + can result in XML External or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + shortlink: https://sg.run/XBD4 + semgrep.dev: + rule: + r_id: 9264 + rv_id: 1263174 + rule_id: x8Uneb + version_id: bZT534J + url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $EXPAT.toJson($SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + message: Possible writing outside of the destination, make sure that the target + path is nested in the intended destination + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + category: security + references: + - https://owasp.org/www-community/attacks/Path_Traversal + technology: + - express + - node.js + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + shortlink: https://sg.run/weRn + semgrep.dev: + rule: + r_id: 9273 + rv_id: 1263141 + rule_id: L1Uyb8 + version_id: ExTExX0 + url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern-inside: | + $PATH = require('path'); + ... + - pattern-inside: | + import $PATH from 'path'; + ... + - pattern-either: + - pattern: $PATH.join(...,$SINK,...) + - pattern: $PATH.resolve(...,$SINK,...) + - patterns: + - focus-metavariable: $SINK + - pattern-inside: | + import 'path'; + ... + - pattern-either: + - pattern: path.join(...,$SINK,...) + - pattern: path.resolve(...,$SINK,...) + pattern-sanitizers: + - pattern: $Y.replace(...) + - pattern: $Y.indexOf(...) + - pattern: | + function ... (...) { + ... + <... $Y.indexOf(...) ...> + ... + } + - patterns: + - pattern: $FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: sanitize +- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + message: Xml Parser is used inside Request Event. Make sure that unverified user + data can not reach the XML Parser, as it can result in XML External or Internal + Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + shortlink: https://sg.run/x1AA + semgrep.dev: + rule: + r_id: 9274 + rv_id: 1263146 + rule_id: 8GUjkk + version_id: QkTGqgo + url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) + - focus-metavariable: $INPUT +- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write + message: Detected directly writing to a Response object from user-defined input. + This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting + (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + vulnerability_class: + - Cross-Site-Scripting (XSS) + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write + shortlink: https://sg.run/vzGl + semgrep.dev: + rule: + r_id: 9277 + rv_id: 1263150 + rule_id: 3qUPA1 + version_id: JdTzxeg + url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.set('$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.set('$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.set('$TYPE') + } + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response) => { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.set('$TYPE') + } + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: function ... (..., $RES,...) {...} + - pattern-either: + - pattern: $RES.write($ARG) + - pattern: $RES.send($ARG) + - pattern-not: $RES. ... .set('...'). ... .send($ARG) + - pattern-not: $RES. ... .type('...'). ... .send($ARG) + - pattern-not-inside: $RES.$METHOD({ ... }) + - focus-metavariable: $ARG + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'express-xss-sanitizer'; + ... + - pattern-inside: | + import * as $S from "express-xss-sanitizer"; + ... + - pattern-inside: | + const { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + var { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + let { ...,$S,... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + $S = require("express-xss-sanitizer") + ... + - pattern: $S(...) + - patterns: + - pattern: $RES. ... .type('$F'). ... .send(...) + - metavariable-regex: + metavariable: $F + regex: (?!.*text/html) + - patterns: + - pattern-inside: | + $X = [...]; + ... + - pattern: | + if(<... !$X.includes($SOURCE)...>) { + ... + return ... + } + ... + - pattern: $SOURCE +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/Ro1g + semgrep.dev: + rule: + r_id: 9293 + rv_id: 1263182 + rule_id: JDUyRl + version_id: d6TyxbX + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JOSE = require("jose"); + ... + - pattern-either: + - pattern-inside: | + var {JWT} = $JOSE; + ... + - pattern-inside: | + var {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + const {JWT} = $JOSE; + ... + - pattern-inside: | + const {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + let {JWT} = $JOSE; + ... + - pattern-inside: | + let {JWK, JWT} = $JOSE; + ... + - pattern-either: + - pattern: | + JWT.verify($P, "...", ...); + - pattern: | + JWT.sign($P, "...", ...); + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: | + $JWT.sign($P, JWK.asKey("..."), ...); + options: + symbolic_propagation: true + interfile: true +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - javascript + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/4xN9 + semgrep.dev: + rule: + r_id: 9300 + rv_id: 1263189 + rule_id: WAUon7 + version_id: gETB75D + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,"...",...); + - pattern-inside: | + $JWT.verify($DATA,"...",...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $JWT = require("jsonwebtoken") + ... + - pattern-inside: | + import $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import * as $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import {...,$JWT,...} from "jsonwebtoken" + ... + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,$VALUE,...); + - pattern-inside: | + $JWT.verify($DATA,$VALUE,...); + - focus-metavariable: $VALUE +- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - nodejs + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + shortlink: https://sg.run/vz70 + semgrep.dev: + rule: + r_id: 9333 + rv_id: 1263225 + rule_id: QrUzq6 + version_id: X0TzyoE + url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + {..., clientSecret: "...", ...} + - pattern: | + {..., secretOrKey: "...", ...} + - pattern: | + {..., consumerSecret: "...", ...} + - patterns: + - pattern-inside: | + $OBJ = {} + ... + - pattern-either: + - pattern: | + $OBJ.clientSecret = "..." + - pattern: | + $OBJ.secretOrKey = "..." + - pattern: | + $OBJ.consumerSecret = "..." + - pattern: $OBJ + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern: | + {..., clientSecret: $SECRET, ...} + - pattern: | + {..., secretOrKey: $SECRET, ...} + - pattern: | + {..., consumerSecret: $SECRET, ...} + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern-inside: | + $VALUE = {..., clientSecret: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., secretOrKey: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., consumerSecret: $SECRET, ...} + ... + - pattern: $VALUE + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $F = require("$I").Strategy + ... + - pattern-inside: | + $F = require("$I") + ... + - pattern-inside: | + import { $STRAT as $F } from '$I' + ... + - pattern-inside: | + import $F from '$I' + ... + - metavariable-regex: + metavariable: $I + regex: (passport-.*) + - pattern-inside: | + new $F($VALUE,...) + - focus-metavariable: $VALUE +- id: python.boto3.security.hardcoded-token.hardcoded-token + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://bento.dev/checks/boto3/hardcoded-access-token/ + - https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/ + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - boto3 + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token + shortlink: https://sg.run/LwQ6 + semgrep.dev: + rule: + r_id: 9439 + rv_id: 1263347 + rule_id: 5rUOwK + version_id: gETB78n + url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token + origin: community + languages: + - python + severity: WARNING + mode: taint + pattern-sources: + - pattern: | + "..." + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $W(...,$TOKEN="$VALUE",...) + - pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...) + - metavariable-regex: + metavariable: $TOKEN + regex: (aws_session_token|aws_access_key_id|aws_secret_access_key) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^AKI + - pattern-regex: ^[A-Za-z0-9/+=]+$ + - metavariable-analysis: + metavariable: $VALUE + analyzer: entropy +- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + shortlink: https://sg.run/9oyr + semgrep.dev: + rule: + r_id: 9467 + rv_id: 1409400 + rule_id: OrU3e6 + version_id: GxTlb9e + url: https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + origin: community + message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`, + `cpickle`, `dill`, `shelve`, or `yaml`, which are known to lead to remote code + execution vulnerabilities. + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: | + def $INSIDE(..., $PARAM, ...): + ... + - pattern-either: + - pattern: request.$REQFUNC(...) + - pattern: request.$REQFUNC.get(...) + - pattern: request.$REQFUNC[...] + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + pickle.$PICKLEFUNC(...) + - pattern: | + _pickle.$PICKLEFUNC(...) + - pattern: | + cPickle.$PICKLEFUNC(...) + - pattern: | + shelve.$PICKLEFUNC(...) + - metavariable-regex: + metavariable: $PICKLEFUNC + regex: dumps|dump|load|loads + - patterns: + - pattern: dill.$DILLFUNC(...) + - metavariable-regex: + metavariable: $DILLFUNC + regex: dump|dump_session|dumps|load|load_session|loads + - patterns: + - pattern: yaml.$YAMLFUNC(...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...) + - metavariable-regex: + metavariable: $YAMLFUNC + regex: dump|dump_all|load|load_all +- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + message: Found user-controlled request data passed into HttpResponse. This could + be vulnerable to XSS, leading to attackers gaining access to user cookies and + protected information. Ensure that the request data is properly escaped or sanitzed. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + shortlink: https://sg.run/BkvA + semgrep.dev: + rule: + r_id: 9495 + rv_id: 1263398 + rule_id: JDUydR + version_id: GxTke5K + url: https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponse(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W[...], ...) + - pattern: return django.http.HttpResponse(..., request.$W[...], ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W, ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: $A = django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $A = django.http.HttpResponse(..., $INTERM, ...) + - pattern: return django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) +- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + message: Found user-controlled request data passed into a HttpResponseBadRequest. + This could be vulnerable to XSS, leading to attackers gaining access to user cookies + and protected information. Ensure that the request data is properly escaped or + sanitzed. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + shortlink: https://sg.run/DoZP + semgrep.dev: + rule: + r_id: 9496 + rv_id: 1263399 + rule_id: 5rUOX1 + version_id: RGT0LY6 + url: https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...), + ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W, + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...) +- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse + message: Found user-controlled request data being passed into a file open, which + is them passed as an argument into the FileResponse. This is dangerous because + an attacker could specify an arbitrary file to read, which could result in leaking + important data. Be sure to validate or sanitize the user-inputted filename in + the request data before using it in FileResponse. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + shortlink: https://sg.run/W862 + semgrep.dev: + rule: + r_id: 9497 + rv_id: 1263400 + rule_id: GdU7QR + version_id: A8Tgd1K + url: https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: return django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: django.http.FileResponse(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W(...), ...) + - pattern: return django.http.FileResponse(..., request.$W(...), ...) + - pattern: django.http.FileResponse(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W[...], ...) + - pattern: return django.http.FileResponse(..., request.$W[...], ...) + - pattern: django.http.FileResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W, ...) + - pattern: return django.http.FileResponse(..., request.$W, ...) +- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system + message: Request data detected in os.system. This could be vulnerable to a command + injection and should be avoided. If this must be done, use the 'subprocess' module + instead and pass the arguments as a list. See https://owasp.org/www-community/attacks/Command_Injection + for more information. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + shortlink: https://sg.run/Gen2 + semgrep.dev: + rule: + r_id: 9504 + rv_id: 1263387 + rule_id: KxUbp2 + version_id: ExTExPo + url: https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: os.system(..., request.$W.get(...), ...) + - pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: os.system(..., $S % request.$W.get(...), ...) + - pattern: os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W.get(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W.get(...), ...) + - pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: return os.system(..., request.$W.get(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return os.system(..., $S % request.$W.get(...), ...) + - pattern: return os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: os.system(..., request.$W(...), ...) + - pattern: os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: os.system(..., $S % request.$W(...), ...) + - pattern: os.system(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W(...), ...) + - pattern: $A = os.system(..., f"...{request.$W(...)}...", ...) + - pattern: return os.system(..., request.$W(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return os.system(..., $S % request.$W(...), ...) + - pattern: return os.system(..., f"...{request.$W(...)}...", ...) + - pattern: os.system(..., request.$W[...], ...) + - pattern: os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: os.system(..., $S % request.$W[...], ...) + - pattern: os.system(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W[...], ...) + - pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = os.system(..., $S % request.$W[...], ...) + - pattern: $A = os.system(..., f"...{request.$W[...]}...", ...) + - pattern: return os.system(..., request.$W[...], ...) + - pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return os.system(..., $S % request.$W[...], ...) + - pattern: return os.system(..., f"...{request.$W[...]}...", ...) + - pattern: os.system(..., request.$W, ...) + - pattern: os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: os.system(..., $S % request.$W, ...) + - pattern: os.system(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W, ...) + - pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = os.system(..., $S % request.$W, ...) + - pattern: $A = os.system(..., f"...{request.$W}...", ...) + - pattern: return os.system(..., request.$W, ...) + - pattern: return os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: return os.system(..., $S % request.$W, ...) + - pattern: return os.system(..., f"...{request.$W}...", ...) +- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + message: Found request data in a call to 'open'. Ensure the request data is validated + or sanitized, otherwise it could result in path traversal attacks and therefore + sensitive data being leaked. To mitigate, consider using os.path.abspath or os.path.realpath + or the pathlib library. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + shortlink: https://sg.run/W8qg + semgrep.dev: + rule: + r_id: 9509 + rv_id: 1263396 + rule_id: oqUe7z + version_id: JdTzxAw + url: https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: open(..., request.$W.get(...), ...) + - pattern: open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: open(..., $S % request.$W.get(...), ...) + - pattern: open(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W.get(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = open(..., $S % request.$W.get(...), ...) + - pattern: $A = open(..., f"...{request.$W.get(...)}...", ...) + - pattern: return open(..., request.$W.get(...), ...) + - pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return open(..., $S % request.$W.get(...), ...) + - pattern: return open(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W(...), ...) + - pattern: open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: open(..., $S % request.$W(...), ...) + - pattern: open(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = open(..., $S % request.$W(...), ...) + - pattern: $A = open(..., f"...{request.$W(...)}...", ...) + - pattern: return open(..., request.$W(...), ...) + - pattern: return open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return open(..., $S % request.$W(...), ...) + - pattern: return open(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W[...], ...) + - pattern: open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: open(..., $S % request.$W[...], ...) + - pattern: open(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W[...], ...) + - pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = open(..., $S % request.$W[...], ...) + - pattern: $A = open(..., f"...{request.$W[...]}...", ...) + - pattern: return open(..., request.$W[...], ...) + - pattern: return open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return open(..., $S % request.$W[...], ...) + - pattern: return open(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W, ...) + - pattern: open(..., $S.format(..., request.$W, ...), ...) + - pattern: open(..., $S % request.$W, ...) + - pattern: open(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W, ...) + - pattern: $A = open(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = open(..., $S % request.$W, ...) + - pattern: $A = open(..., f"...{request.$W}...", ...) + - pattern: return open(..., request.$W, ...) + - pattern: return open(..., $S.format(..., request.$W, ...), ...) + - pattern: return open(..., $S % request.$W, ...) + - pattern: return open(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + with open(..., $DATA, ...) as $FD: + ... +- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + message: User-controlled data from a request is passed to 'extra()'. This could + lead to a SQL injection and therefore protected information could be leaked. Instead, + use parameterized queries or escape the user-controlled data by using `params` + and not using quote placeholders in the SQL string. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + shortlink: https://sg.run/0Ql5 + semgrep.dev: + rule: + r_id: 9510 + rv_id: 1263402 + rule_id: zdUkx1 + version_id: DkTRb4l + url: https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...), + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...", + ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], + ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...), + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...], + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...), + ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) +- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + message: User-controlled data from request is passed to 'RawSQL()'. This could lead + to a SQL injection and therefore protected information could be leaked. Instead, + use parameterized queries or escape the user-controlled data by using `params` + and not using quote placeholders in the SQL string. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + shortlink: https://sg.run/Kl4X + semgrep.dev: + rule: + r_id: 9511 + rv_id: 1263403 + rule_id: pKUOBp + version_id: WrTqK2L + url: https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...), + ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...), + ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...), + ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W, + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) +- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + message: User-controlled data from a request is passed to 'execute()'. This could + lead to a SQL injection and therefore protected information could be leaked. Instead, + use django's QuerySets, which are built with query parameterization and therefore + not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + shortlink: https://sg.run/qx7y + semgrep.dev: + rule: + r_id: 9512 + rv_id: 1263404 + rule_id: 2ZUbDL + version_id: 0bTKzRj + url: https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: return $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W(...), ...) + - pattern: return $CURSOR.execute(..., request.$W(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W[...], ...) + - pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...) + - pattern: $CURSOR.execute(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W[...], ...) + - pattern: return $CURSOR.execute(..., request.$W[...], ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W, ...) + - pattern: $CURSOR.execute(..., f"...{request.$W}...", ...) + - pattern: $CURSOR.execute(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W, ...) + - pattern: return $CURSOR.execute(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: |- + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) +- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + message: Data that is possible user-controlled from a python request is passed to + `raw()`. This could lead to SQL injection and attackers gaining access to protected + information. Instead, use django's QuerySets, which are built with query parameterization + and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + shortlink: https://sg.run/l2v9 + semgrep.dev: + rule: + r_id: 9513 + rv_id: 1263405 + rule_id: X5U8v5 + version_id: K3TKkBW + url: https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: return $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W, ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W, ...) + - pattern: return $MODEL.objects.raw(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) +- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. See https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + to learn more about SSRF vulnerabilities. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + shortlink: https://sg.run/YvY4 + semgrep.dev: + rule: + r_id: 9514 + rv_id: 1263406 + rule_id: j2UvEw + version_id: qkTR7zn + url: https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W.get(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W.get(...), ...) + - pattern: return requests.$METHOD(..., request.$W.get(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W(...), ...) + - pattern: return requests.$METHOD(..., request.$W(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W[...], ...) + - pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...) + - pattern: requests.$METHOD(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W[...], ...) + - pattern: return requests.$METHOD(..., request.$W[...], ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W, ...) + - pattern: requests.$METHOD(..., f"...{request.$W}...", ...) + - pattern: requests.$METHOD(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W, ...) + - pattern: return requests.$METHOD(..., request.$W, ...) +- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF), which could result in attackers + gaining access to private organization data. To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + shortlink: https://sg.run/6n2B + semgrep.dev: + rule: + r_id: 9515 + rv_id: 1263407 + rule_id: 10UKDo + version_id: l4TJRwD + url: https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...), + ...) + - pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W[...], ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...) + - pattern: urllib.request.urlopen(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W[...], ...) + - pattern: return urllib.request.urlopen(..., request.$W[...], ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W, ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...) + - pattern: urllib.request.urlopen(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W, ...) + - pattern: return urllib.request.urlopen(..., request.$W, ...) +- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + message: Detected Flask route directly returning a formatted string. This is subject + to cross-site scripting if user input can reach the string. Consider using the + template engine instead and rendering pages with 'render_template()'. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + shortlink: https://sg.run/Zv6o + semgrep.dev: + rule: + r_id: 9535 + rv_id: 1263416 + rule_id: QrUz49 + version_id: WrTqKAz + url: https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + origin: community + languages: + - python + severity: WARNING + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $PARAM, ...): + ... + - pattern: $PARAM + - pattern: | + request.$FUNC.get(...) + - pattern: | + request.$FUNC(...) + - pattern: request.$FUNC[...] + pattern-sinks: + - patterns: + - pattern-not-inside: return "..." + - pattern-either: + - pattern: return "...".format(...) + - pattern: return "..." % ... + - pattern: return "..." + ... + - pattern: return ... + "..." + - pattern: return f"...{...}..." + - patterns: + - pattern: return $X + - pattern-either: + - pattern-inside: | + $X = "...".format(...) + ... + - pattern-inside: | + $X = "..." % ... + ... + - pattern-inside: | + $X = "..." + ... + ... + - pattern-inside: | + $X = ... + "..." + ... + - pattern-inside: | + $X = f"...{...}..." + ... + - pattern-not-inside: | + $X = "..." + ... +- id: python.flask.security.injection.os-system-injection.os-system-injection + languages: + - python + severity: ERROR + message: User data detected in os.system. This could be vulnerable to a command + injection and should be avoided. If this must be done, use the 'subprocess' module + instead and pass the arguments as a list. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection + shortlink: https://sg.run/4xzz + semgrep.dev: + rule: + r_id: 9544 + rv_id: 1263429 + rule_id: BYUN99 + version_id: 1QTypw7 + url: https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection + origin: community + pattern-either: + - patterns: + - pattern: os.system(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + os.system(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + os.system(..., <... $INTERM ...>, ...) + - pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W[...] ...>, ...) + - pattern: os.system(..., <... flask.request.$W(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) +- id: python.flask.security.injection.path-traversal-open.path-traversal-open + languages: + - python + severity: ERROR + message: Found request data in a call to 'open'. Ensure the request data is validated + or sanitized, otherwise it could result in path traversal attacks. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open + shortlink: https://sg.run/PJRW + semgrep.dev: + rule: + r_id: 9545 + rv_id: 1263430 + rule_id: DbUpOQ + version_id: 9lT4b94 + url: https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open + origin: community + pattern-either: + - patterns: + - pattern: open(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + open(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + with open(..., <... $ROUTEVAR ...>, ...) as $FD: + ... + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + open(..., <... $INTERM ...>, ...) + - pattern: open(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: open(..., <... flask.request.$W[...] ...>, ...) + - pattern: open(..., <... flask.request.$W(...) ...>, ...) + - pattern: open(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) +- id: python.flask.security.injection.ssrf-requests.ssrf-requests + languages: + - python + severity: ERROR + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests + shortlink: https://sg.run/J9LW + semgrep.dev: + rule: + r_id: 9546 + rv_id: 1263432 + rule_id: WAUoRx + version_id: rxTAKJn + url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests + origin: community + pattern-either: + - patterns: + - pattern: requests.$FUNC(...) + - pattern-either: + - pattern-inside: | + @$APP.$ROUTE_METHOD($ROUTE, ...) + def $ROUTE_FUNC(..., $ROUTEVAR, ...): + ... + requests.$FUNC(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.$ROUTE_METHOD($ROUTE, ...) + def $ROUTE_FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + requests.$FUNC(..., <... $INTERM ...>, ...) + - metavariable-regex: + metavariable: $ROUTE_METHOD + regex: ^(route|get|post|put|delete|patch)$ + - pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) +- id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + patterns: + - pattern-either: + - patterns: + - pattern: | + jwt.decode(..., options={..., "verify_signature": $BOOL, ...}, ...) + - metavariable-pattern: + metavariable: $BOOL + pattern: | + False + - focus-metavariable: $BOOL + - patterns: + - pattern: | + $OPTS = {..., "verify_signature": $BOOL, ...} + ... + jwt.decode(..., options=$OPTS, ...) + - metavariable-pattern: + metavariable: $BOOL + pattern: | + False + - focus-metavariable: $BOOL + message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity + checks for the token which means the token could be tampered with by malicious + actors. Ensure that the JWT token is verified. + metadata: + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + references: + - https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96 + category: security + technology: + - jwt + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + shortlink: https://sg.run/6nyB + semgrep.dev: + rule: + r_id: 9559 + rv_id: 1263454 + rule_id: 10UKjo + version_id: 5PTo12w + url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + origin: community + fix: | + True + severity: ERROR + languages: + - python +- id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + patterns: + - pattern: subprocess.$FUNC(..., shell=$TRUE, ...) + - metavariable-pattern: + metavariable: $TRUE + pattern: "True \n" + - pattern-not: subprocess.$FUNC("...", shell=True, ...) + - focus-metavariable: $TRUE + message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous + because this call will spawn the command using a shell process. Doing so propagates + current shell settings and variables, which makes it much easier for a malicious + actor to execute commands. Use 'shell=False' instead. + fix: | + False + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - secure default + likelihood: HIGH + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + shortlink: https://sg.run/J92w + semgrep.dev: + rule: + r_id: 9646 + rv_id: 1263518 + rule_id: DbUpz2 + version_id: 0bTKzDK + url: https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation + - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 + category: security + technology: + - pyyaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + shortlink: https://sg.run/we9Y + semgrep.dev: + rule: + r_id: 9673 + rv_id: 1263530 + rule_id: ZqU5jZ + version_id: 1QTyprw + url: https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + origin: community + languages: + - python + message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, + `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe + methods of deserializing YAML. An attacker with control over the YAML input could + create special YAML input that allows the attacker to run arbitrary Python code. + This would allow the attacker to steal files, download and install malware, or + otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. + fix-regex: + regex: unsafe_load + replacement: safe_load + count: 1 + severity: ERROR + patterns: + - pattern-inside: | + import yaml + ... + - pattern-not-inside: | + $YAML = ruamel.yaml.YAML(...) + ... + - pattern-either: + - pattern: yaml.unsafe_load(...) + - pattern: yaml.load(..., Loader=yaml.Loader, ...) + - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load(..., Loader=yaml.CLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) + - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) +- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ + category: security + technology: + - ruamel.yaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + shortlink: https://sg.run/x1rz + semgrep.dev: + rule: + r_id: 9674 + rv_id: 1263531 + rule_id: nJUzqK + version_id: 9lT4bvG + url: https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + origin: community + languages: + - python + message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create + arbitrary Python objects. A malicious actor could exploit this to run arbitrary + code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead. + severity: ERROR + pattern-either: + - pattern: ruamel.yaml.YAML(..., typ='unsafe', ...) + - pattern: ruamel.yaml.YAML(..., typ='base', ...) +- id: python.lang.security.deserialization.pickle.avoid-shelve + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve + shortlink: https://sg.run/dKkZ + semgrep.dev: + rule: + r_id: 9678 + rv_id: 1263535 + rule_id: 8GUje2 + version_id: NdTzyb4 + url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve + origin: community + languages: + - python + message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code + execution vulnerabilities. When unpickling, the serialized data could be manipulated + to run arbitrary code. Instead, consider serializing the relevant data as JSON + or a similar text-based serialization format. + severity: WARNING + pattern: shelve.$FUNC(...) +- id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + patterns: + - pattern-either: + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query.join(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause + sql injections if the developer inputs raw SQL into the before-mentioned clauses. + This pattern captures relevant cases in which the developer inputs raw SQL into + the distinct, having, group_by, order_by or filter clauses and injects user-input + into the raw SQL with any function besides "bindparams". Use bindParams to securely + bind user-input to SQL statements. + fix-regex: + regex: format + replacement: bindparams + languages: + - python + severity: WARNING + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - sqlalchemy + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + shortlink: https://sg.run/J3Xo + semgrep.dev: + rule: + r_id: 9702 + rv_id: 1263579 + rule_id: BYUBWo + version_id: NdTzyL4 + url: https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + origin: community +- id: ruby.lang.security.bad-deserialization.bad-deserialization + mode: taint + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + pattern-sinks: + - pattern-either: + - pattern: | + CSV.load(...) + - pattern: | + Marshal.load(...) + - pattern: | + Marshal.restore(...) + - pattern: | + Oj.object_load(...) + - pattern: | + Oj.load($X) + message: Checks for unsafe deserialization. Objects in Ruby can be serialized into + strings, then later loaded from strings. However, uses of load and object_load + can cause remote code execution. Loading user input with MARSHAL or CSV can potentially + be dangerous. Use JSON in a secure fashion instead. + metadata: + references: + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + technology: + - ruby + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization + shortlink: https://sg.run/DJj2 + semgrep.dev: + rule: + r_id: 9708 + rv_id: 1263595 + rule_id: lBUdQg + version_id: 3ZT4Xqp + url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization + origin: community + languages: + - ruby + severity: ERROR +- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + patterns: + - pattern-inside: | + class $CONTROLLER < ApplicationController + ... + http_basic_authenticate_with ..., :password => "$SECRET", ... + end + - focus-metavariable: $SECRET + message: Detected hardcoded password used in basic authentication in a controller + class. Including this password in version control could expose this credential. + Consider refactoring to use environment variables or configuration files. + severity: WARNING + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown + category: security + technology: + - ruby + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + shortlink: https://sg.run/6r0w + semgrep.dev: + rule: + r_id: 9715 + rv_id: 1263606 + rule_id: X5UZWK + version_id: 0bTKzNK + url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + origin: community + languages: + - ruby +- id: ruby.lang.security.no-eval.ruby-eval + message: Use of eval with user-controllable input detected. This can lead to attackers + running arbitrary code. Ensure external data does not reach here, otherwise this + is a security vulnerability. Consider other ways to do this without eval. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe2022-top25: true + cwe2021-top25: true + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb + subcategory: + - vuln + technology: + - ruby + - rails + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval + shortlink: https://sg.run/bDwZ + semgrep.dev: + rule: + r_id: 9726 + rv_id: 1263615 + rule_id: OrUGNk + version_id: A8TgdDv + url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval + origin: community + languages: + - ruby + mode: taint + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + - patterns: + - pattern: | + RubyVM::InstructionSequence.compile(...) + - pattern-not: | + RubyVM::InstructionSequence.compile("...") + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.eval + - pattern: $X.class_eval + - pattern: $X.instance_eval + - pattern: $X.module_eval + - pattern: $X.eval(...) + - pattern: $X.class_eval(...) + - pattern: $X.instance_eval(...) + - pattern: $X.module_eval(...) + - pattern: eval(...) + - pattern: class_eval(...) + - pattern: module_eval(...) + - pattern: instance_eval(...) + - pattern-not: $M("...",...) +- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting + (XSS) vulnerability if this comes from user-provided input. If you have to use + `$TRUST`, ensure it does not come from user-input or use the appropriate prevention + mechanism e.g. input validation or sanitization depending on the context. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://angular.io/api/platform-browser/DomSanitizer + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + confidence: MEDIUM + category: security + technology: + - angular + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + shortlink: https://sg.run/KWxP + semgrep.dev: + rule: + r_id: 9755 + rv_id: 1263902 + rule_id: oqUzgA + version_id: 5PTo1zk + url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + origin: community + languages: + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X: string, ...}) { ... } + - pattern-inside: | + function ...(..., $X: string, ...) { ... } + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.$TRUST($Y) + - focus-metavariable: $Y + - pattern-not: | + $X.$TRUST(`...`) + - pattern-not: | + $X.$TRUST("...") + - metavariable-regex: + metavariable: $TRUST + regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern: sanitizer.sanitize(...) + - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); +- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + message: Detection of dangerouslySetInnerHTML from non-constant definition. This + can inadvertently expose users to cross-site scripting (XSS) attacks if this comes + from user-provided input. If you have to use dangerouslySetInnerHTML, consider + using a sanitization library such as DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + shortlink: https://sg.run/rAx6 + semgrep.dev: + rule: + r_id: 9769 + rv_id: 1263912 + rule_id: x8UWvK + version_id: l4TJR0v + url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-not-inside: | + $F. ... .$SANITIZEUNC(...) + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern-either: + - pattern: | + {...,dangerouslySetInnerHTML: {__html: $X},...} + - pattern: | + <$Y ... dangerouslySetInnerHTML={{__html: $X}} /> + - pattern-not: | + <$Y ... dangerouslySetInnerHTML={{__html: "..."}} /> + - pattern-not: | + {...,dangerouslySetInnerHTML:{__html: "..."},...} + - metavariable-pattern: + patterns: + - pattern-not: | + {...} + metavariable: $X + - pattern-not: | + <... {__html: "..."} ...> + - pattern-not: | + <... {__html: `...`} ...> + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + message: Detection of $HTML from non-constant definition. This can inadvertently + expose users to cross-site scripting (XSS) attacks if this comes from user-provided + input. If you have to use $HTML, consider using a sanitization library such as + DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln + - https://developer.mozilla.org/en-US/docs/Web/API/Document/write + - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + shortlink: https://sg.run/E5x8 + semgrep.dev: + rule: + r_id: 9781 + rv_id: 1263916 + rule_id: QrU68w + version_id: GxTkeRl + url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" + - pattern: "window.document. ... .$HTML('...',$SINK) \n" + - pattern: "document.$HTML($SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (writeln|write) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: "$PROP. ... .$HTML('...',$SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (insertAdjacentHTML) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + message: Detection of $HTML from non-constant definition. This can inadvertently + expose users to cross-site scripting (XSS) attacks if this comes from user-provided + input. If you have to use $HTML, consider using a sanitization library such as + DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + shortlink: https://sg.run/70Zv + semgrep.dev: + rule: + r_id: 9782 + rv_id: 1263917 + rule_id: 3qUBl4 + version_id: RGT0Lln + url: https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $BODY = $REACT.useRef(...) + ... + - pattern-inside: | + $BODY = useRef(...) + ... + - pattern-inside: | + $BODY = findDOMNode(...) + ... + - pattern-inside: | + $BODY = createRef(...) + ... + - pattern-inside: | + $BODY = $REACT.findDOMNode(...) + ... + - pattern-inside: | + $BODY = $REACT.createRef(...) + ... + - pattern-either: + - pattern: "$BODY. ... .$HTML = $SINK \n" + - pattern: "$BODY.$HTML = $SINK \n" + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: ReactDOM.findDOMNode(...).$HTML = $SINK + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: ruby.lang.security.dangerous-exec.dangerous-exec + mode: taint + pattern-sources: + - patterns: + - pattern: | + def $F(...,$ARG,...) + ... + end + - focus-metavariable: $ARG + - pattern: params + - pattern: cookies + pattern-sinks: + - patterns: + - pattern: | + $EXEC(...) + - pattern-not: | + $EXEC("...","...","...",...) + - pattern-not: | + $EXEC(["...","...","...",...],...) + - pattern-not: | + $EXEC({...},"...","...","...",...) + - pattern-not: | + $EXEC({...},["...","...","...",...],...) + - metavariable-regex: + metavariable: $EXEC + regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ + message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If + unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + - rails + references: + - https://guides.rubyonrails.org/security.html#command-line-injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec + shortlink: https://sg.run/R8GY + semgrep.dev: + rule: + r_id: 9805 + rv_id: 1409405 + rule_id: WAUZOw + version_id: WrT7erb + url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec + origin: community + severity: WARNING + languages: + - ruby +- id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + message: Detected non-literal calls to Deno.run(). This could lead to a command + injection vulnerability. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - deno + references: + - https://deno.land/manual/examples/subprocess#simple-example + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + shortlink: https://sg.run/Nrrn + semgrep.dev: + rule: + r_id: 9927 + rv_id: 1409397 + rule_id: x8UWWg + version_id: PkTe7AP + url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: function ... (..., $ARG,...) {...} + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + Deno.run({cmd: [$INPUT,...]},...) + - pattern: | + Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...) + - patterns: + - pattern: | + Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" + ... + - focus-metavariable: $INPUT +- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + mode: taint + pattern-propagators: + - pattern: $X << $Y + from: $Y + to: $X + pattern-sources: + - pattern-either: + - pattern: | + params + - pattern: | + cookies + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $CON = PG.connect(...) + ... + - pattern-inside: | + $CON = PG::Connection.open(...) + ... + - pattern-inside: | + $CON = PG::Connection.new(...) + ... + - pattern-either: + - pattern: | + $CON.$METHOD($X,...) + - pattern: | + $CON.$METHOD $X, ... + - focus-metavariable: $X + - metavariable-regex: + metavariable: $METHOD + regex: ^(exec|exec_params)$ + languages: + - ruby + message: 'Detected string concatenation with a non-literal variable in a pg Ruby + SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use parameterized queries like + so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And + you can use prepared statements with `exec_prepared`.' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + shortlink: https://sg.run/kL0o + semgrep.dev: + rule: + r_id: 10328 + rv_id: 1263628 + rule_id: NbUAz7 + version_id: 2KTv2y2 + url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + origin: community + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + category: security + technology: + - .net + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + shortlink: https://sg.run/ZeXW + semgrep.dev: + rule: + r_id: 11135 + rv_id: 1262635 + rule_id: bwUOjK + version_id: nWT2LGp + url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + origin: community + message: The BinaryFormatter type is dangerous and is not recommended for data processing. + Applications should stop using BinaryFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. BinaryFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Binary; + ... + - pattern: | + new BinaryFormatter(); +- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + shortlink: https://sg.run/E5e5 + semgrep.dev: + rule: + r_id: 11137 + rv_id: 1262638 + rule_id: kxURnR + version_id: LjTkgPk + url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + origin: community + message: The FsPickler is dangerous and is not recommended for data processing. + Default configuration tend to insecure deserialization vulnerability. + patterns: + - pattern-inside: | + using MBrace.FsPickler.Json; + ... + - pattern: | + FsPickler.CreateJsonSerializer(); +- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + shortlink: https://sg.run/70pG + semgrep.dev: + rule: + r_id: 11138 + rv_id: 1262641 + rule_id: wdU87G + version_id: QkTGqnA + url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + origin: community + message: The LosFormatter type is dangerous and is not recommended for data processing. + Applications should stop using LosFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. LosFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Web.UI; + ... + - pattern: | + new LosFormatter(); +- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + shortlink: https://sg.run/L0AX + semgrep.dev: + rule: + r_id: 11139 + rv_id: 1262642 + rule_id: x8UW7x + version_id: 3ZT4X6b + url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + origin: community + message: The NetDataContractSerializer type is dangerous and is not recommended + for data processing. Applications should stop using NetDataContractSerializer + as soon as possible, even if they believe the data they're processing to be trustworthy. + NetDataContractSerializer is insecure and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization; + ... + - pattern: | + new NetDataContractSerializer(); +- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + shortlink: https://sg.run/gJnR + semgrep.dev: + rule: + r_id: 11141 + rv_id: 1262644 + rule_id: eqUvND + version_id: PkTR30n + url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + origin: community + message: The SoapFormatter type is dangerous and is not recommended for data processing. + Applications should stop using SoapFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. SoapFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Soap; + ... + - pattern: | + new SoapFormatter(); +- id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + languages: + - hcl + message: AWS EC2 Instance allowing use of the IMDSv1 + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + references: + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options + category: security + technology: + - terraform + - aws + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + shortlink: https://sg.run/J3BQ + semgrep.dev: + rule: + r_id: 11302 + rv_id: 1263884 + rule_id: GdU0eA + version_id: w8TRooE + url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + origin: community + pattern-either: + - patterns: + - pattern: http_tokens = "optional" + - pattern-inside: | + metadata_options { ... } + - patterns: + - pattern: | + resource "aws_instance" "$NAME" { + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_tokens = "required" + ... + } + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_tokens = "optional" + ... + } + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_endpoint = "disabled" + ... + } + ... + } + severity: ERROR +- id: javascript.express.security.express-vm-injection.express-vm-injection + message: Make sure that unverified user data can not reach `$VM`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection + shortlink: https://sg.run/jkqJ + semgrep.dev: + rule: + r_id: 12821 + rv_id: 1263170 + rule_id: DbUKPX + version_id: 1QTypXQ + url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $VM = require('vm'); + ... + - pattern-either: + - pattern: | + $VM.runInContext(...) + - pattern: | + $VM.runInNewContext(...) + - pattern: | + $VM.compileFunction(...) + - pattern: | + $VM.runInThisContext(...) + - pattern: new $VM.Script(...) +- id: javascript.express.security.express-vm2-injection.express-vm2-injection + message: Make sure that unverified user data can not reach `vm2`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection + shortlink: https://sg.run/1GWv + semgrep.dev: + rule: + r_id: 12822 + rv_id: 1263171 + rule_id: WAUPXJ + version_id: 9lT4bnX + url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + require('vm2') + ... + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $VM = new VM(...) + ... + - pattern-inside: | + $VM = new NodeVM(...) + ... + - pattern: | + $VM.run(...) + - pattern: | + new VM(...).run(...) + - pattern: | + new NodeVM(...).run(...) + - pattern: | + new VMScript(...) + - pattern: | + new VM(...) + - pattern: new NodeVM(...) +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `run:` step could allow an attacker to inject their own code into the runner. + This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate + environment variable with `env:` to store the data and use the environment variable + in the `run:` script. Be sure to use double-quotes the environment variable, like + this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + shortlink: https://sg.run/pkzk + semgrep.dev: + rule: + r_id: 13162 + rv_id: 1423395 + rule_id: v8UjQj + version_id: GxTl1DQ + url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + metadata: + shortDescription: Allowing an attacker to manipulate the session may lead to unintended + behavior. + tags: + - security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + references: + - https://brakemanscanner.org/docs/warning_types/session_manipulation/ + category: security + technology: + - rails + help: | + ## Remediation + Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior. + + ## References + [Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/) + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + shortlink: https://sg.run/86q7 + semgrep.dev: + rule: + r_id: 13584 + rv_id: 1263621 + rule_id: BYUdW6 + version_id: qkTR76G + url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + origin: community + message: This gets data from session using user inputs. A malicious user may be + able to retrieve information from your session that you didn't intend them to. + Do not use user input as a session key. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern: session[...] +- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + shortlink: https://sg.run/gYln + semgrep.dev: + rule: + r_id: 13585 + rv_id: 1263622 + rule_id: DbU1dr + version_id: l4TJRkk + url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - pattern: Dir.$X(...) + - pattern: File.$X(...) + - pattern: IO.$X(...) + - pattern: Kernel.$X(...) + - pattern: PStore.$X(...) + - pattern: Pathname.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + shortlink: https://sg.run/Q9gP + semgrep.dev: + rule: + r_id: 13586 + rv_id: 1263623 + rule_id: WAUyzp + version_id: YDTZeWL + url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - pattern: Net::FTP.$X(...) + - patterns: + - pattern-inside: | + $FTP = Net::FTP.$OPEN(...) + ... + $FTP.$METHOD(...) + - pattern: $FTP.$METHOD(...) +- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + shortlink: https://sg.run/3rLb + semgrep.dev: + rule: + r_id: 13587 + rv_id: 1263624 + rule_id: 0oU2x3 + version_id: 6xT29nN + url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - patterns: + - pattern: Net::HTTP::$METHOD.new(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: Copy + - pattern: Delete + - pattern: Get + - pattern: Head + - pattern: Lock + - pattern: Mkcol + - pattern: Move + - pattern: Options + - pattern: Patch + - pattern: Post + - pattern: Propfind + - pattern: Proppatch + - pattern: Put + - pattern: Trace + - pattern: Unlock + - patterns: + - pattern: Net::HTTP.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: get + - pattern: get2 + - pattern: head + - pattern: head2 + - pattern: options + - pattern: patch + - pattern: post + - pattern: post2 + - pattern: post_form + - pattern: put + - pattern: request + - pattern: request_get + - pattern: request_head + - pattern: request_post + - pattern: send_request + - pattern: trace + - pattern: get_print + - pattern: get_response + - pattern: start +- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + shortlink: https://sg.run/4e8E + semgrep.dev: + rule: + r_id: 13588 + rv_id: 1263625 + rule_id: KxU72k + version_id: o5TbDq8 + url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - pattern: params[...] + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: Kernel.$X(...) + - patterns: + - pattern-either: + - pattern: Shell.$X(...) + - patterns: + - pattern-inside: | + $SHELL = Shell.$ANY(...) + ... + $SHELL.$X(...) + - pattern: $SHELL.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: cat + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: exec + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: system + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://brakemanscanner.org/docs/warning_types/link_to/ + - https://brakemanscanner.org/docs/warning_types/link_to_href/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + shortlink: https://sg.run/JxXQ + semgrep.dev: + rule: + r_id: 13590 + rv_id: 1263632 + rule_id: lBU8Qj + version_id: 9lT4brj + url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + origin: community + message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` + is not escaped. This means that user input which reaches the body will be executed + when the HTML is rendered. Even in other versions, values starting with `javascript:` + or `data:` are not escaped. It is better to create and use a safer function which + checks the body argument. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern-either: + - pattern: $MODEL.url(...) + - pattern: $MODEL.uri(...) + - pattern: $MODEL.link(...) + - pattern: $MODEL.page(...) + - pattern: $MODEL.site(...) + pattern-sinks: + - pattern: link_to(...) + pattern-sanitizers: + - patterns: + - pattern: | + "...#{...}..." + - pattern-not: | + "#{...}..." +- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + shortlink: https://sg.run/GO2n + semgrep.dev: + rule: + r_id: 13592 + rv_id: 1263635 + rule_id: 6JU1bL + version_id: bZT53p0 + url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + origin: community + message: Avoid rendering user input. It may be possible for a malicious user to + input a path that lets them access a template they shouldn't. To prevent this, + check dynamic template paths against a predefined allowlist to make sure it's + an allowed template. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-inside: render($X => $INPUT, ...) + - pattern: $INPUT + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: action + - pattern: template + - pattern: partial + - pattern: file +- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + languages: + - python + severity: WARNING + metadata: + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + technology: + - python + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + shortlink: https://sg.run/AXY4 + semgrep.dev: + rule: + r_id: 13594 + rv_id: 1263482 + rule_id: zdUYqR + version_id: O9Tpxqr + url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + origin: community + message: These permissions `$BITS` are widely permissive and grant access to more + people than may be necessary. A good default is `0o644` which gives read and write + access to yourself and read access to everyone else. + patterns: + - pattern-inside: os.$METHOD(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: chmod + - pattern: lchmod + - pattern: fchmod + - pattern-either: + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o650 and $BITS < 0o100000 + - patterns: + - pattern: os.$METHOD($FILE, $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o100650 + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-pattern: + metavariable: $BITS + patterns: + - pattern-either: + - pattern: <... stat.S_IWGRP ...> + - pattern: <... stat.S_IXGRP ...> + - pattern: <... stat.S_IWOTH ...> + - pattern: <... stat.S_IXOTH ...> + - pattern: <... stat.S_IRWXO ...> + - pattern: <... stat.S_IRWXG ...> + - patterns: + - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) + - metavariable-comparison: + metavariable: $MOD + comparison: $MOD == 0o111 +- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + languages: + - php + message: '`$QUERY` Detected string concatenation with a non-literal variable in + a Doctrine QueryBuilder method. This could lead to SQL injection if the variable + is user-controlled and not properly sanitized. In order to prevent SQL injection, + use parameterized queries or prepared statements instead.' + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + technology: + - doctrine + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + shortlink: https://sg.run/jwDJ + semgrep.dev: + rule: + r_id: 13965 + rv_id: 1263271 + rule_id: kxUw23 + version_id: 1QTypnG + url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + origin: community + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $QUERY->add(...,$SINK,...) + - pattern: $QUERY->select(...,$SINK,...) + - pattern: $QUERY->addSelect(...,$SINK,...) + - pattern: $QUERY->delete(...,$SINK,...) + - pattern: $QUERY->update(...,$SINK,...) + - pattern: $QUERY->insert(...,$SINK,...) + - pattern: $QUERY->from(...,$SINK,...) + - pattern: $QUERY->join(...,$SINK,...) + - pattern: $QUERY->innerJoin(...,$SINK,...) + - pattern: $QUERY->leftJoin(...,$SINK,...) + - pattern: $QUERY->rightJoin(...,$SINK,...) + - pattern: $QUERY->where(...,$SINK,...) + - pattern: $QUERY->andWhere(...,$SINK,...) + - pattern: $QUERY->orWhere(...,$SINK,...) + - pattern: $QUERY->groupBy(...,$SINK,...) + - pattern: $QUERY->addGroupBy(...,$SINK,...) + - pattern: $QUERY->having(...,$SINK,...) + - pattern: $QUERY->andHaving(...,$SINK,...) + - pattern: $QUERY->orHaving(...,$SINK,...) + - pattern: $QUERY->orderBy(...,$SINK,...) + - pattern: $QUERY->addOrderBy(...,$SINK,...) + - pattern: $QUERY->set($SINK,...) + - pattern: $QUERY->setValue($SINK,...) + - pattern-either: + - pattern-inside: | + $Q = $X->createQueryBuilder(); + ... + - pattern-inside: | + $Q = new QueryBuilder(...); + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: sprintf(...) + - pattern: | + "...".$SMTH + severity: WARNING +- id: python.django.security.injection.raw-html-format.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which + will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render + - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/oYj1 + semgrep.dev: + rule: + r_id: 14360 + rv_id: 1263397 + rule_id: 2ZUPER + version_id: 5PTo100 + url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: django.utils.html.escape(...) + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: python.flask.security.injection.raw-html-concat.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`flask.render_template`) which will + safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format + shortlink: https://sg.run/Pb7e + semgrep.dev: + rule: + r_id: 14389 + rv_id: 1409401 + rule_id: GdUrJv + version_id: RGTEN1l + url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: jinja2.escape(...) + - pattern: flask.escape(...) + - patterns: + - pattern: flask.render_template($TPL, ...) + - metavariable-regex: + metavariable: $TPL + regex: .*\.html + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can + lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing + sensitive data. It is recommend where possible to not allow user-input to craft + the base request, but to be treated as part of the path or query parameter. When + user-input is necessary to craft the request, it is recommended to follow OWASP + best practices to prevent abuse, including using an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/5DjW + semgrep.dev: + rule: + r_id: 14391 + rv_id: 1262970 + rule_id: AbUQLr + version_id: yeTxpOj + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $CLIENT := &http.Client{...} + ... + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: | + http.NewRequest("$METHOD", $URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + severity: WARNING +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `html/template` package which will + safely render HTML instead, or inspect that the HTML is rendered safely. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/3r1G + semgrep.dev: + rule: + r_id: 14443 + rv_id: 1262968 + rule_id: PeUonQ + version_id: 1QTyp2p + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: ruby.rails.security.injection.raw-html-format.raw-html-format + languages: + - ruby + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `render template` and make template + files which will safely render HTML instead, or inspect that the HTML is absolutely + rendered safely with a function like `sanitize`. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/ + - https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/b2JQ + semgrep.dev: + rule: + r_id: 14470 + rv_id: 1409408 + rule_id: kxUwZX + version_id: qkTvgYY + url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: sanitize(...) + - pattern: strip_tags(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $HTMLSTR + - pattern-regex: <\w+.* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$HTMLSTR", ...) + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR" % $EXPR + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: python.flask.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RXpK + semgrep.dev: + rule: + r_id: 14649 + rv_id: 1409403 + rule_id: ReU3Wb + version_id: BjTy42w + url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: | + $URL = "$URLSTR" + ... + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + severity: WARNING +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) + or a safe library. + options: + interfile: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/PbEq + semgrep.dev: + rule: + r_id: 14689 + rv_id: 1409388 + rule_id: PeUoqy + version_id: nWTQ5qD + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + severity: ERROR + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern-inside: | + var $SB strings.Builder + ... + - pattern-inside: | + $SB.WriteString("$SQLSTR") + ... + $SB.String(...) + - pattern: | + $SB.WriteString(...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) +- id: javascript.express.security.injection.raw-html-format.raw-html-format + message: User data flows into the host portion of this manually-constructed HTML. + This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from + user-provided input. Consider using a sanitization library such as DOMPurify to + sanitize the HTML within. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/5DO3 + semgrep.dev: + rule: + r_id: 14691 + rv_id: 1263175 + rule_id: 5rUL0X + version_id: NdTzyQv + url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - label: EXPRESS + patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - label: EXPRESSTS + patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - label: CLEAN + by-side-effect: true + patterns: + - pattern-either: + - pattern: $A($SOURCE) + - pattern: $SANITIZE. ... .$A($SOURCE) + - pattern: $A. ... .$SANITIZE($SOURCE) + - focus-metavariable: $SOURCE + - metavariable-regex: + metavariable: $A + regex: (?i)(.*valid|.*sanitiz) + pattern-sinks: + - requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" + $EXPR' + - pattern: '"$HTMLSTR".concat(...)' + - pattern: util.format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...` + - pattern-regex: | + .*<\w+.* +- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host + languages: + - ruby + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction + with `SsrfFilter(...)`, or create an allowlist for approved hosts. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://github.com/arkadiyt/ssrf_filter + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RX3g + semgrep.dev: + rule: + r_id: 14705 + rv_id: 1263668 + rule_id: zdUY0W + version_id: 6xT29BN + url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sanitizers: + - pattern: SsrfFilter + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $URLSTR + - pattern-regex: \w+:\/\/#{.*} + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$URLSTR", ...) + - pattern: | + "$URLSTR" + $EXPR + - pattern: | + "$URLSTR" % $EXPR + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// ... +- id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as ActiveRecord which will protect your queries. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/Y85o + semgrep.dev: + rule: + r_id: 14714 + rv_id: 1263667 + rule_id: bwU8gl + version_id: YDTZeLL + url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sanitizers: + - pattern: | + $PARAMS.slice(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $RECORD.where($X,...) + - pattern: | + $RECORD.find(..., :conditions => $X,...) + - focus-metavariable: $X + - patterns: + - pattern: | + "$SQLVERB#{$EXPR}..." + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $SQLVERB + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", $EXPR) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - php + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) + VALUES (?, ?)");`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/lZYG + semgrep.dev: + rule: + r_id: 14757 + rv_id: 1263290 + rule_id: qNUXdL + version_id: gETB7vY + url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: mysqli_real_escape_string(...) + - pattern: real_escape_string(...) + - pattern: $MYSQLI->real_escape_string(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($SQLSTR, ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "...$EXPR..." + - metavariable-regex: + metavariable: $EXPR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "$SQLSTR".$EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* +- id: php.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - php + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/Y8no + semgrep.dev: + rule: + r_id: 14758 + rv_id: 1263291 + rule_id: lBU8K1 + version_id: QkTGqRd + url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($URLSTR, ...) + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME://%s + - patterns: + - pattern: | + "...{$EXPR}..." + - pattern-regex: | + .*://\{.* + - patterns: + - pattern: | + "...$EXPR..." + - pattern-regex: | + .*://\$.* + - patterns: + - pattern: | + "...".$EXPR + - pattern-regex: | + .*://["'].* +- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/9rzz + semgrep.dev: + rule: + r_id: 14767 + rv_id: 1409396 + rule_id: 10UdRR + version_id: 44TbKvr + url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + interfile: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$SQLSTR"; + ... + - pattern: String.format($VAR, ...) + - pattern-not-inside: System.out.println(...) + - pattern-not-inside: $LOG.info(...) + - pattern-not-inside: $LOG.warn(...) + - pattern-not-inside: $LOG.warning(...) + - pattern-not-inside: $LOG.debug(...) + - pattern-not-inside: $LOG.debugging(...) + - pattern-not-inside: $LOG.error(...) + - pattern-not-inside: new Exception(...) + - pattern-not-inside: throw ...; + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: | + (string $X) + - pattern-not: | + "..." + pattern-propagators: + - pattern: (StringBuilder $B).$ANY(...,(string $X),...) + from: $X + to: $B + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + new $PATTERN($CMD,...) + - focus-metavariable: $CMD + - patterns: + - pattern: | + $CMD.$PATTERN = $VALUE; + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $PATTERN + regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ + pattern-sanitizers: + - pattern-either: + - pattern: | + $CMD.Parameters.Add(...) + - pattern: | + $CMD.Parameters.AddRange(...) + - pattern: | + $CMD.Parameters.AddWithValue(...) + - pattern: | + $CMD.Parameters[$IDX].Value = ... + by-side-effect: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand' + and 'SqlParameter'. + metadata: + category: security + technology: + - csharp + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + shortlink: https://sg.run/d2Xd + semgrep.dev: + rule: + r_id: 15078 + rv_id: 1262648 + rule_id: x8UxeP + version_id: RGT0LqW + url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + origin: community + languages: + - csharp + severity: ERROR +- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + message: Enabling authentication ensures that all communications in the application + are authenticated. The `auth_settings` block needs to be filled out with the appropriate + auth backend settings + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-287: Improper Authentication' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + shortlink: https://sg.run/JxYw + semgrep.dev: + rule: + r_id: 15102 + rv_id: 1263755 + rule_id: 0oU23p + version_id: PkTR3P8 + url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + origin: community + languages: + - hcl + severity: ERROR +- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + metadata: + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + shortlink: https://sg.run/rY2n + semgrep.dev: + rule: + r_id: 15125 + rv_id: 1263258 + rule_id: v8U9Q7 + version_id: WrTqKgJ + url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + origin: community + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html + for more information. + severity: WARNING + pattern: | + $ENV.put($CTX.SECURITY_AUTHENTICATION, "none") + ... + $DCTX = InitialDirContext($ENV, ...) + languages: + - kt +- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + message: Using the GrantPublicAccess method on bucket contruct $X will make the + objects in the bucket world accessible. Verify if this is intentional. + metadata: + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + shortlink: https://sg.run/Z4p7 + semgrep.dev: + rule: + r_id: 15279 + rv_id: 1263906 + rule_id: wdUjZK + version_id: BjTkZA7 + url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new Bucket(...) + ... + $X.grantPublicAccess(...) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new $Y.Bucket(...) + ... + $X.grantPublicAccess(...) +- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + message: CodeBuild Project $X is set to have a public URL. This will make the build + results, logs, artifacts publically accessible, including builds prior to the + project being public. Ensure this is acceptable for the project. + metadata: + category: security + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + shortlink: https://sg.run/nK7G + semgrep.dev: + rule: + r_id: 15280 + rv_id: 1263907 + rule_id: x8UxXZ + version_id: DkTRbj1 + url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Project} from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new Project(..., {..., badge: true, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new $Y.Project(..., {..., badge: true, ...}) +- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + mode: taint + pattern-sinks: + - pattern: | + sqlalchemy.text(...) + pattern-sources: + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $Y + type: string + - patterns: + - pattern: | + f"..." + - patterns: + - pattern: | + $X.format(...) + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X % $Y + - metavariable-type: + metavariable: $X + type: string + message: sqlalchemy.text passes the constructed SQL statement to the database mostly + unchanged. This means that the usual SQL injection protections are not applied + and this function is vulnerable to SQL injection if user input can reach here. + Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct + SQL. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - sqlalchemy + confidence: MEDIUM + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + shortlink: https://sg.run/yP1O + semgrep.dev: + rule: + r_id: 15824 + rv_id: 1263577 + rule_id: r6U2wE + version_id: rxTAKqq + url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + origin: community + languages: + - python + severity: ERROR +- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - ci + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell + shortlink: https://sg.run/4l9l + semgrep.dev: + rule: + r_id: 16200 + rv_id: 1262664 + rule_id: gxUJrJ + version_id: jQTn5QE + url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell + origin: community + message: Semgrep found a bash reverse shell + severity: ERROR + languages: + - generic + pattern-either: + - pattern: | + sh -i >& /dev/udp/.../... 0>&1 + - pattern: | + <...>/dev/tcp/.../...; sh <&... >&... 2>& + - pattern: | + <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done + - pattern: | + sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& +- id: php.lang.security.injection.tainted-filename.tainted-filename + severity: WARNING + message: File name based on user input risks server-side request forgery. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename + shortlink: https://sg.run/Ayqp + semgrep.dev: + rule: + r_id: 16250 + rv_id: 1263287 + rule_id: 5rUpro + version_id: 7ZTE3J1 + url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: basename($PATH, ...) + - pattern-inside: linkinfo($PATH, ...) + - pattern-inside: readlink($PATH, ...) + - pattern-inside: realpath($PATH, ...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: opcache_compile_file($FILENAME, ...) + - pattern-inside: opcache_invalidate($FILENAME, ...) + - pattern-inside: opcache_is_script_cached($FILENAME, ...) + - pattern-inside: runkit7_import($FILENAME, ...) + - pattern-inside: readline_read_history($FILENAME, ...) + - pattern-inside: readline_write_history($FILENAME, ...) + - pattern-inside: rar_open($FILENAME, ...) + - pattern-inside: zip_open($FILENAME, ...) + - pattern-inside: gzfile($FILENAME, ...) + - pattern-inside: gzopen($FILENAME, ...) + - pattern-inside: readgzfile($FILENAME, ...) + - pattern-inside: hash_file($ALGO, $FILENAME, ...) + - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) + - pattern-inside: pg_trace($FILENAME, ...) + - pattern-inside: dio_open($FILENAME, ...) + - pattern-inside: finfo_file($FINFO, $FILENAME, ...) + - pattern-inside: mime_content_type($FILENAME, ...) + - pattern-inside: chgrp($FILENAME, ...) + - pattern-inside: chmod($FILENAME, ...) + - pattern-inside: chown($FILENAME, ...) + - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) + - pattern-inside: file_exists($FILENAME, ...) + - pattern-inside: file_get_contents($FILENAME, ...) + - pattern-inside: file_put_contents($FILENAME, ...) + - pattern-inside: file($FILENAME, ...) + - pattern-inside: fileatime($FILENAME, ...) + - pattern-inside: filectime($FILENAME, ...) + - pattern-inside: filegroup($FILENAME, ...) + - pattern-inside: fileinode($FILENAME, ...) + - pattern-inside: filemtime($FILENAME, ...) + - pattern-inside: fileowner($FILENAME, ...) + - pattern-inside: fileperms($FILENAME, ...) + - pattern-inside: filesize($FILENAME, ...) + - pattern-inside: filetype($FILENAME, ...) + - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) + - pattern-inside: fopen($FILENAME, ...) + - pattern-inside: is_dir($FILENAME, ...) + - pattern-inside: is_executable($FILENAME, ...) + - pattern-inside: is_file($FILENAME, ...) + - pattern-inside: is_link($FILENAME, ...) + - pattern-inside: is_readable($FILENAME, ...) + - pattern-inside: is_uploaded_file($FILENAME, ...) + - pattern-inside: is_writable($FILENAME, ...) + - pattern-inside: lchgrp($FILENAME, ...) + - pattern-inside: lchown($FILENAME, ...) + - pattern-inside: lstat($FILENAME, ...) + - pattern-inside: parse_ini_file($FILENAME, ...) + - pattern-inside: readfile($FILENAME, ...) + - pattern-inside: stat($FILENAME, ...) + - pattern-inside: touch($FILENAME, ...) + - pattern-inside: unlink($FILENAME, ...) + - pattern-inside: xattr_get($FILENAME, ...) + - pattern-inside: xattr_list($FILENAME, ...) + - pattern-inside: xattr_remove($FILENAME, ...) + - pattern-inside: xattr_set($FILENAME, ...) + - pattern-inside: xattr_supported($FILENAME, ...) + - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) + - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_new_personal($FILENAME, ...) + - pattern-inside: exif_imagetype($FILENAME, ...) + - pattern-inside: getimagesize($FILENAME, ...) + - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) + - pattern-inside: imagecreatefromavif($FILENAME, ...) + - pattern-inside: imagecreatefrombmp($FILENAME, ...) + - pattern-inside: imagecreatefromgd2($FILENAME, ...) + - pattern-inside: imagecreatefromgd2part($FILENAME, ...) + - pattern-inside: imagecreatefromgd($FILENAME, ...) + - pattern-inside: imagecreatefromgif($FILENAME, ...) + - pattern-inside: imagecreatefromjpeg($FILENAME, ...) + - pattern-inside: imagecreatefrompng($FILENAME, ...) + - pattern-inside: imagecreatefromtga($FILENAME, ...) + - pattern-inside: imagecreatefromwbmp($FILENAME, ...) + - pattern-inside: imagecreatefromwebp($FILENAME, ...) + - pattern-inside: imagecreatefromxbm($FILENAME, ...) + - pattern-inside: imagecreatefromxpm($FILENAME, ...) + - pattern-inside: imageloadfont($FILENAME, ...) + - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) + - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, + ...) + - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) + - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) + - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) + - pattern-inside: fdf_open($FILENAME, ...) + - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) + - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) + - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) + - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) + - pattern-inside: posix_access($FILENAME, ...) + - pattern-inside: posix_mkfifo($FILENAME, ...) + - pattern-inside: posix_mknod($FILENAME, ...) + - pattern-inside: ftok($FILENAME, ...) + - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) + - pattern-inside: fann_read_train_from_file($FILENAME, ...) + - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) + - pattern-inside: highlight_file($FILENAME, ...) + - pattern-inside: php_strip_whitespace($FILENAME, ...) + - pattern-inside: stream_resolve_include_path($FILENAME, ...) + - pattern-inside: swoole_async_read($FILENAME, ...) + - pattern-inside: swoole_async_readfile($FILENAME, ...) + - pattern-inside: swoole_async_write($FILENAME, ...) + - pattern-inside: swoole_async_writefile($FILENAME, ...) + - pattern-inside: swoole_load_module($FILENAME, ...) + - pattern-inside: tidy_parse_file($FILENAME, ...) + - pattern-inside: tidy_repair_file($FILENAME, ...) + - pattern-inside: get_meta_tags($FILENAME, ...) + - pattern-inside: yaml_emit_file($FILENAME, ...) + - pattern-inside: yaml_parse_file($FILENAME, ...) + - pattern-inside: curl_file_create($FILENAME, ...) + - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) + - pattern-inside: ftp_delete($FTP, $FILENAME, ...) + - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) + - pattern-inside: ftp_size($FTP, $FILENAME, ...) + - pattern-inside: rrd_create($FILENAME, ...) + - pattern-inside: rrd_fetch($FILENAME, ...) + - pattern-inside: rrd_graph($FILENAME, ...) + - pattern-inside: rrd_info($FILENAME, ...) + - pattern-inside: rrd_last($FILENAME, ...) + - pattern-inside: rrd_lastupdate($FILENAME, ...) + - pattern-inside: rrd_tune($FILENAME, ...) + - pattern-inside: rrd_update($FILENAME, ...) + - pattern-inside: snmp_read_mib($FILENAME, ...) + - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) + - pattern-inside: apache_lookup_uri($FILENAME, ...) + - pattern-inside: md5_file($FILENAME, ...) + - pattern-inside: sha1_file($FILENAME, ...) + - pattern-inside: simplexml_load_file($FILENAME, ...) + - pattern: $FILENAME +- id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + patterns: + - pattern-inside: | + provider "aws" { + ... + secret_key = "$SECRET" + } + - focus-metavariable: $SECRET + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + languages: + - hcl + severity: WARNING + metadata: + technology: + - secrets + - aws + - terraform + category: security + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + shortlink: https://sg.run/L3kn + semgrep.dev: + rule: + r_id: 16439 + rv_id: 1263735 + rule_id: d8U4n0 + version_id: rxTAK76 + url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + origin: community +- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - laravel + references: + - https://laravel.com/docs/8.x/queries + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection + shortlink: https://sg.run/x40p + semgrep.dev: + rule: + r_id: 16830 + rv_id: 1263313 + rule_id: j2UQdp + version_id: BjTkZ45 + url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection + origin: community + severity: WARNING + message: Detected a SQL query based on user input. This could lead to SQL injection, + which could potentially result in sensitive data being exfiltrated by attackers. + Instead, use parameterized queries and prepared statements. + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $SQL + - pattern-either: + - pattern-inside: DB::table(...)->whereRaw($SQL, ...) + - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) + - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) + - pattern-inside: DB::table(...)->havingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) + - patterns: + - pattern: $EXPRESSION + - pattern-either: + - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) + - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) + - patterns: + - pattern: $COLUMNS + - pattern-either: + - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereNull($COLUMN) + - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->find($ID, $COLUMNS) + - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) + - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) + - pattern-inside: DB::table(...)->select($COLUMNS) + - pattern-inside: DB::table(...)->get($COLUMNS) + - pattern-inside: DB::table(...)->count($COLUMNS) + - patterns: + - pattern: $COLUMN + - pattern-either: + - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) + - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->having($COLUMN, ...) + - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) + - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) + - pattern-inside: DB::table(...)->orderByDesc($COLUMN) + - pattern-inside: DB::table(...)->latest($COLUMN) + - pattern-inside: DB::table(...)->oldest($COLUMN) + - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->value($COLUMN) + - pattern-inside: DB::table(...)->pluck($COLUMN, ...) + - pattern-inside: DB::table(...)->implode($COLUMN, ...) + - pattern-inside: DB::table(...)->min($COLUMN) + - pattern-inside: DB::table(...)->max($COLUMN) + - pattern-inside: DB::table(...)->sum($COLUMN) + - pattern-inside: DB::table(...)->avg($COLUMN) + - pattern-inside: DB::table(...)->average($COLUMN) + - pattern-inside: DB::table(...)->increment($COLUMN, ...) + - pattern-inside: DB::table(...)->decrement($COLUMN, ...) + - pattern-inside: DB::table(...)->where($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) + - pattern-inside: DB::table(...)->addSelect($COLUMN) + - patterns: + - pattern: $QUERY + - pattern-inside: DB::unprepared($QUERY) +- id: csharp.dotnet.security.razor-template-injection.razor-template-injection + message: User-controllable string passed to Razor.Parse. This leads directly to + code execution in the context of the process. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + cwe2022-top25: true + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/ + subcategory: + - vuln + technology: + - .net + - razor + - asp + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection + shortlink: https://sg.run/oyj0 + semgrep.dev: + rule: + r_id: 18216 + rv_id: 1262621 + rule_id: EwUr68 + version_id: 1QTypdj + url: https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public ActionResult $METHOD(..., string $ARG,...){...} + pattern-sinks: + - pattern: | + Razor.Parse(...) + pattern-sanitizers: + - not_conflicting: true + pattern: $F(...) +- id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + mode: taint + pattern-sources: + - patterns: + - pattern: $A + - pattern-inside: | + Path.Combine(...,$A,...) + - pattern-inside: | + public $TYPE $M(...,$A,...){...} + - pattern-not-inside: | + <... Path.GetFileName($A) != $A ...> + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern: | + File.$METHOD($X,...) + - metavariable-regex: + metavariable: $METHOD + regex: (?i)^(read|write) + pattern-sanitizers: + - pattern: | + Path.GetFileName(...) + - patterns: + - pattern-inside: | + $X = Path.GetFileName(...); + ... + - pattern: $X + - patterns: + - pattern: $X + - pattern-inside: | + if(<... Path.GetFileName($X) != $X ...>){ + ... + throw new $EXCEPTION(...); + } + ... + message: String argument $A is used to read or write data from a file via Path.Combine + without direct sanitization via Path.GetFileName. If the path is user-supplied + data this can lead to path traversal. + languages: + - csharp + severity: WARNING + metadata: + category: security + confidence: MEDIUM + references: + - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ + - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks + technology: + - .net + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + shortlink: https://sg.run/1RvG + semgrep.dev: + rule: + r_id: 18222 + rv_id: 1262632 + rule_id: 3qU3bE + version_id: vdT0644 + url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + origin: community +- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $XMLDOCUMENT.$METHOD(...) + - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver + = new XmlUrlResolver(...);\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + shortlink: https://sg.run/k98P + semgrep.dev: + rule: + r_id: 18228 + rv_id: 1262654 + rule_id: ReUK9k + version_id: K3TKk5E + url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + XmlReader $READER = XmlReader.Create(...,$RS,...); + - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing + = DtdProcessing.Parse;\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + shortlink: https://sg.run/wXjA + semgrep.dev: + rule: + r_id: 18229 + rv_id: 1262655 + rule_id: AbU3pX + version_id: qkTR7WD + url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $READER.$METHOD(...) + - pattern-not-inside: | + $READER.DtdProcessing = DtdProcessing.Prohibit; + ... + - pattern-inside: | + XmlTextReader $READER = new XmlTextReader(...); + ... + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + shortlink: https://sg.run/xXjL + semgrep.dev: + rule: + r_id: 18230 + rv_id: 1262656 + rule_id: BYUevk + version_id: l4TJRWG + url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + origin: community +- id: go.aws-lambda.security.database-sqli.database-sqli + languages: + - go + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' + calls. + mode: taint + metadata: + references: + - https://pkg.go.dev/database/sql#DB.Query + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - database + - sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli + shortlink: https://sg.run/e5e8 + semgrep.dev: + rule: + r_id: 18232 + rv_id: 1262909 + rule_id: WAUdJ7 + version_id: BjTkZkQ + url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.Exec($QUERY,...) + - pattern: $DB.ExecContent($QUERY,...) + - pattern: $DB.Query($QUERY,...) + - pattern: $DB.QueryContext($QUERY,...) + - pattern: $DB.QueryRow($QUERY,...) + - pattern: $DB.QueryRowContext($QUERY,...) + - pattern-inside: | + import "database/sql" + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + severity: WARNING +- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - go + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/vX3Y + semgrep.dev: + rule: + r_id: 18233 + rv_id: 1262910 + rule_id: 0oUwqg + version_id: DkTRbRL + url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "$SQLSTR" + ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + - pattern-not-inside: | + log.$PRINT(...) + pattern-sanitizers: + - pattern: strconv.Atoi(...) +- id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + message: '`Clean` is not intended to sanitize against path traversal attacks. This + function is for finding the shortest path name equivalent to the given input. + Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix + this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package + `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + severity: ERROR + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sanitizers: + - pattern-either: + - pattern: | + "/" + ... + fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + options: + interfile: true + metadata: + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - go + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + shortlink: https://sg.run/ZKzw + semgrep.dev: + rule: + r_id: 18235 + rv_id: 1262967 + rule_id: qNUQJe + version_id: jQTn5Bj + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + origin: community +- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + options: + interfile: true + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EBYN + semgrep.dev: + rule: + r_id: 18237 + rv_id: 1262977 + rule_id: YGUl4z + version_id: O9TpxQN + url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - pattern-not-inside: | + System.out.$PRINTLN(...) +- id: java.aws-lambda.security.tainted-sqli.tainted-sqli + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if variables in the SQL statement are not properly sanitized. + Use parameterized SQL queries or properly sanitize user input instead. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) + options: + interfile: true + metadata: + category: security + technology: + - sql + - java + - aws-lambda + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli + shortlink: https://sg.run/7942 + semgrep.dev: + rule: + r_id: 18238 + rv_id: 1262978 + rule_id: 6JUDWk + version_id: e1Tyj4g + url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli + origin: community +- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + message: Detected input from a HTTPServletRequest going into a SQL sink or statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use parameterized SQL queries or properly sanitize user input instead. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://owasp.org/www-community/attacks/SQL_Injection + subcategory: + - vuln + technology: + - sql + - java + - servlets + - spring + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/Lg56 + semgrep.dev: + rule: + r_id: 18239 + rv_id: 1409390 + rule_id: oqUBJG + version_id: 7ZTKJNj + url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + languages: + - java + mode: taint + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + ... + $OUTPUT = $STMT.$FUNC(...); + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - pattern: | + (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) +- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' + or 'exec' command. This could lead to command injection if variables passed into + the exec commands are not properly sanitized. Instead, avoid using these OS commands + with user-supplied input, or, if you must use these commands, use a whitelist + of specific values. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (ProcessBuilder $PB) = ...; + - patterns: + - pattern: | + (Process $P) = ...; + - pattern-not: | + (Process $P) = (java.lang.Runtime $R).exec(...); + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, ...); + - focus-metavariable: $CMD + - patterns: + - pattern-either: + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n...\n$PB.command($ARGLIST);\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process + $P) = ...;\n" + - pattern: | + $ARGLIST.add(...); + metadata: + category: security + technology: + - java + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + shortlink: https://sg.run/8zPN + semgrep.dev: + rule: + r_id: 18240 + rv_id: 1263042 + rule_id: zdUWrg + version_id: LjTkg9J + url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + origin: community +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + shortlink: https://sg.run/4Dv5 + semgrep.dev: + rule: + r_id: 18244 + rv_id: 1263057 + rule_id: j2UrJ8 + version_id: 0bTKzgX + url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + origin: community + message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external + entity declarations, this is vulnerable to XML external entity attacks. Disable + this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + false); + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/PYBz + semgrep.dev: + rule: + r_id: 18245 + rv_id: 1263058 + rule_id: 10UPQB + version_id: K3TKk80 + url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This + is vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, + allow DOCTYPE declarations and only prohibit external entities declarations. This + can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = DocumentBuilderFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newDocumentBuilder(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newDocumentBuilder(); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + shortlink: https://sg.run/JgPy + semgrep.dev: + rule: + r_id: 18246 + rv_id: 1263059 + rule_id: 9AUJ6r + version_id: qkTR7Lk + url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + false); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + shortlink: https://sg.run/5Lv0 + semgrep.dev: + rule: + r_id: 18247 + rv_id: 1263060 + rule_id: yyUNeo + version_id: l4TJRoL + url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + false); + languages: + - java +- id: javascript.aws-lambda.security.detect-child-process.detect-child-process + message: Allowing spawning arbitrary programs or running shell processes with arbitrary + arguments may end up in a command injection vulnerability. Try to avoid non-literal + values for the command string. If it is not possible, then do not let running + arbitrary commands, use a white list for inputs. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process + shortlink: https://sg.run/Ggoq + semgrep.dev: + rule: + r_id: 18248 + rv_id: 1263105 + rule_id: r6UDNQ + version_id: YDTZe4o + url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: exec($CMD,...) + - pattern: execSync($CMD,...) + - pattern: spawn($CMD,...) + - pattern: spawnSync($CMD,...) + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-either: + - pattern-inside: | + require('child_process') + ... + - pattern-inside: | + import 'child_process' + ... +- id: javascript.aws-lambda.security.knex-sqli.knex-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from + table'', [userinput])`' + metadata: + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli + shortlink: https://sg.run/RgWq + semgrep.dev: + rule: + r_id: 18249 + rv_id: 1263106 + rule_id: bwUBlj + version_id: JdTzxKg + url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $KNEX.fromRaw($QUERY, ...) + - pattern: $KNEX.whereRaw($QUERY, ...) + - pattern: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... +- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://www.npmjs.com/package/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/A502 + semgrep.dev: + rule: + r_id: 18250 + rv_id: 1263107 + rule_id: NbUBJ2 + version_id: 5PTo1En + url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $POOL.query($QUERY, ...) + - pattern: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('mysql') + ... + - pattern-inside: | + require('mysql2') + ... + - pattern-inside: | + require('mysql2/promise') + ... + - pattern-inside: | + import 'mysql' + ... + - pattern-inside: | + import 'mysql2' + ... + - pattern-inside: | + import 'mysql2/promise' + ... +- id: javascript.aws-lambda.security.pg-sqli.pg-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://node-postgres.com/features/queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/BGKA + semgrep.dev: + rule: + r_id: 18251 + rv_id: 1263108 + rule_id: kxU25P + version_id: GxTkeJL + url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('pg') + ... + - pattern-inside: | + import 'pg' + ... +- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `sequelize.query(''SELECT + * FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT + });`' + metadata: + references: + - https://sequelize.org/master/manual/raw-queries.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequelize + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + shortlink: https://sg.run/DAlP + semgrep.dev: + rule: + r_id: 18252 + rv_id: 1263109 + rule_id: wdUA5o + version_id: RGT0LrD + url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('sequelize') + ... + - pattern-inside: | + import 'sequelize' + ... +- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/0Gvj + semgrep.dev: + rule: + r_id: 18254 + rv_id: 1263111 + rule_id: OrUJBY + version_id: BjTkZ8D + url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $BODY + - pattern-inside: | + {..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... } +- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + message: The `vm` module enables compiling and running code within V8 Virtual Machine + contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted + code. If code passed to `vm` functions is controlled by user input it could result + in command injection. Do not let user input in `vm` functions. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + shortlink: https://sg.run/q9w7 + semgrep.dev: + rule: + r_id: 18256 + rv_id: 1263114 + rule_id: v8UOdZ + version_id: 0bTKz9J + url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('vm'); + ... + - pattern-inside: | + import 'vm' + ... + - pattern-either: + - pattern: $VM.runInContext($X,...) + - pattern: $VM.runInNewContext($X,...) + - pattern: $VM.runInThisContext($X,...) + - pattern: $VM.compileFunction($X,...) + - pattern: new $VM.Script($X,...) + - pattern: new $VM.SourceTextModule($X,...) + - pattern: runInContext($X,...) + - pattern: runInNewContext($X,...) + - pattern: runInThisContext($X,...) + - pattern: compileFunction($X,...) + - pattern: new Script($X,...) + - pattern: new SourceTextModule($X,...) +- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT + $1 from table'', [userinput])` can help prevent SQLi.' + metadata: + confidence: MEDIUM + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - express + - nodejs + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + shortlink: https://sg.run/l9eE + semgrep.dev: + rule: + r_id: 18257 + rv_id: 1263205 + rule_id: d8UKLD + version_id: l4TJRey + url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $KNEX.fromRaw($QUERY, ...) + - pattern-inside: $KNEX.whereRaw($QUERY, ...) + - pattern-inside: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) +- id: php.lang.security.deserialization.extract-user-data + mode: taint + pattern-sources: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_FILES[...] + - pattern: $_POST[...] + pattern-sinks: + - pattern: extract(...) + pattern-sanitizers: + - pattern: extract($VAR, EXTR_SKIP,...) + message: Do not call 'extract()' on user-controllable data. If you must, then you + must also provide the EXTR_SKIP flag to prevent overwriting existing variables. + languages: + - php + metadata: + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + technology: + - php + references: + - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data + shortlink: https://sg.run/6bv1 + semgrep.dev: + rule: + r_id: 18259 + rv_id: 1263278 + rule_id: nJUykq + version_id: w8TRovw + url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data + origin: community + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected 'create_subprocess_exec' function with argument tainted by `event` + object. If this data can be controlled by a malicious actor, it may be an instance + of command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + shortlink: https://sg.run/oyv0 + semgrep.dev: + rule: + r_id: 18260 + rv_id: 1263331 + rule_id: EwUrX8 + version_id: rxTAKgo + url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted + by `event` object. If this data can be controlled by a malicious actor, it may + be an instance of command injection. Audit the use of this call to ensure it is + not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + shortlink: https://sg.run/z14d + semgrep.dev: + rule: + r_id: 18261 + rv_id: 1263332 + rule_id: 7KUxXg + version_id: bZT53Ww + url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern: asyncio.create_subprocess_shell($CMD, ...) + message: Detected asyncio subprocess function with argument tainted by `event` object. + If this data can be controlled by a malicious actor, it may be an instance of + command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + shortlink: https://sg.run/p9vZ + semgrep.dev: + rule: + r_id: 18262 + rv_id: 1263333 + rule_id: L1UEl7 + version_id: NdTzyWA + url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Ensure no external data reaches here. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/2AjL + semgrep.dev: + rule: + r_id: 18263 + rv_id: 1263334 + rule_id: 8GUGBq + version_id: kbTzGv8 + url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - patterns: + - pattern: os.$METHOD($MODE, $CMD, ...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) +- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + message: Detected subprocess function with argument tainted by an `event` object. If + this data can be controlled by a malicious actor, it may be an instance of command + injection. The default option for `shell` is False, and this is secure by default. + Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` + means you have to split the command string into an array of strings for the command + and its arguments. You may consider using 'shlex.split()' for this purpose. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/XZ7B + semgrep.dev: + rule: + r_id: 18264 + rv_id: 1263335 + rule_id: gxUyn1 + version_id: w8TRogj + url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: subprocess.$FUNC(..., shell=True, ...) + pattern-sanitizers: + - pattern: shlex.split(...) + - pattern: pipes.quote(...) + - pattern: shlex.quote(...) +- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/jDvN + semgrep.dev: + rule: + r_id: 18265 + rv_id: 1263336 + rule_id: QrUkg6 + version_id: xyTjzbG + url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: os.system($CMD,...) + - pattern: os.popen($CMD,...) + - pattern: os.popen2($CMD,...) + - pattern: os.popen3($CMD,...) + - pattern: os.popen4($CMD,...) +- id: python.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/1RjG + semgrep.dev: + rule: + r_id: 18266 + rv_id: 1263337 + rule_id: 3qU3eE + version_id: O9TpxLJ + url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern-either: + - pattern-inside: | + import mysql + ... + - pattern-inside: | + import mysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://www.psycopg.org/docs/cursor.html#cursor.execute + - https://www.psycopg.org/docs/cursor.html#cursor.executemany + - https://www.psycopg.org/docs/cursor.html#cursor.mogrify + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - psycopg + - psycopg2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + shortlink: https://sg.run/9L8r + semgrep.dev: + rule: + r_id: 18267 + rv_id: 1263338 + rule_id: 4bUQG1 + version_id: e1TyjPZ + url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern: $CURSOR.mogrify($QUERY,...) + - pattern-inside: | + import psycopg2 + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://pypi.org/project/pymssql/ + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymssql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + shortlink: https://sg.run/yXvP + semgrep.dev: + rule: + r_id: 18268 + rv_id: 1263339 + rule_id: PeUxO0 + version_id: vdT06bG + url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import pymssql + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://pypi.org/project/PyMySQL/#id4 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + shortlink: https://sg.run/reve + semgrep.dev: + rule: + r_id: 18269 + rv_id: 1263340 + rule_id: JDUlel + version_id: d6TyxNA + url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-either: + - pattern-inside: | + import pymysql + ... + - pattern-inside: | + import pymysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = ?'', ''active'')`' + mode: taint + metadata: + references: + - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sqlalchemy + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + shortlink: https://sg.run/b48W + semgrep.dev: + rule: + r_id: 18270 + rv_id: 1263341 + rule_id: 5rUy3N + version_id: ZRTKARp + url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import sqlalchemy + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.tainted-html-response.tainted-html-response + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: $BODY + - pattern-inside: | + {..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... } + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/k9vP + semgrep.dev: + rule: + r_id: 18272 + rv_id: 1263343 + rule_id: ReUKrk + version_id: ExTEx5o + url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - python + severity: WARNING +- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/wXvA + semgrep.dev: + rule: + r_id: 18273 + rv_id: 1263346 + rule_id: AbU3LX + version_id: 8KT5ron + url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= + - pattern-not-inside: | + print(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: ERROR +- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT + title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`' + mode: taint + metadata: + references: + - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - active-record + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + shortlink: https://sg.run/vXvY + semgrep.dev: + rule: + r_id: 18277 + rv_id: 1263581 + rule_id: 0oUw9g + version_id: w8TRor7 + url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: ActiveRecord::Base.connection.execute($QUERY,...) + - pattern: $MODEL.find_by_sql($QUERY,...) + - pattern: $MODEL.select_all($QUERY,...) + - pattern-inside: | + require 'active_record' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' + mode: taint + metadata: + references: + - https://github.com/brianmario/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + shortlink: https://sg.run/dJLE + semgrep.dev: + rule: + r_id: 18278 + rv_id: 1263582 + rule_id: KxUrQ3 + version_id: xyTjzOe + url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CLIENT.query($QUERY,...) + - pattern: $CLIENT.prepare($QUERY,...) + - pattern-inside: | + require 'mysql2' + ... + pattern-sanitizers: + - pattern: $CLIENT.escape(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.pg-sqli.pg-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `conn.exec_params(''SELECT + $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`' + mode: taint + metadata: + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/ZKww + semgrep.dev: + rule: + r_id: 18279 + rv_id: 1263583 + rule_id: qNUQee + version_id: O9Tpxz7 + url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CONN.exec($QUERY,...) + - pattern: $CONN.exec_params($QUERY,...) + - pattern: $CONN.exec_prepared($QUERY,...) + - pattern: $CONN.async_exec($QUERY,...) + - pattern: $CONN.async_exec_params($QUERY,...) + - pattern: $CONN.async_exec_prepared($QUERY,...) + - pattern-inside: | + require 'pg' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `DB[''select * from items + where name = ?'', name]`' + mode: taint + metadata: + references: + - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + shortlink: https://sg.run/n9vY + semgrep.dev: + rule: + r_id: 18280 + rv_id: 1263584 + rule_id: lBUy2N + version_id: e1Tyj5j + url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: DB[$QUERY,...] + - pattern: DB.run($QUERY,...) + - pattern-inside: | + require 'sequel' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EB7N + semgrep.dev: + rule: + r_id: 18281 + rv_id: 1263586 + rule_id: PeUxOE + version_id: d6Tyx1Z + url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "...#{...}..." + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", ...) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - pattern-not-inside: | + puts(...) +- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + patterns: + - pattern-inside: | + import ("github.com/gorilla/websocket") + ... + - patterns: + - pattern-not-inside: | + $UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...} + ... + - pattern-not-inside: | + $UPGRADER.CheckOrigin = $FN2 + ... + - pattern: | + $UPGRADER.Upgrade(...) + message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee + that the connection accepted by the WebSocket is from a trusted origin domain. + Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" + documentation: "A CheckOrigin function should carefully validate the request origin + to prevent cross-site request forgery."' + languages: + - go + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader + technology: + - gorilla + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + shortlink: https://sg.run/xXpz + semgrep.dev: + rule: + r_id: 18430 + rv_id: 1262914 + rule_id: ReUKdz + version_id: qkTR7RP + url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + origin: community +- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/Lgqr + semgrep.dev: + rule: + r_id: 18483 + rv_id: 1263112 + rule_id: PeUxwW + version_id: DkTRbvp + url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR".concat(...) + - pattern: $UTIL.format($HTMLSTR, ...) + - pattern: format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...${...}...` + - pattern-regex: | + .*<\w+.* + - pattern-not-inside: | + console.$LOG(...) +- id: python.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/8zNy + semgrep.dev: + rule: + r_id: 18484 + rv_id: 1263344 + rule_id: JDUlwy + version_id: 7ZTE36K + url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - pattern-not-inside: | + print(...) +- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf + patterns: + - pattern-either: + - pattern: Source.fromURL($URL,...) + - pattern: Source.fromURI($URL,...) + - pattern-inside: | + import scala.io.$SOURCE + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `fromURL` most likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode + the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource + category: security + technology: + - scala + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + shortlink: https://sg.run/Qbz4 + semgrep.dev: + rule: + r_id: 18486 + rv_id: 1263675 + rule_id: GdUDOZ + version_id: 1QTypG9 + url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: scala.play.security.tainted-html-response.tainted-html-response + mode: taint + metadata: + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - play + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/BG96 + semgrep.dev: + rule: + r_id: 18795 + rv_id: 1263686 + rule_id: 0oUwn2 + version_id: vdT06yj + url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response + origin: community + message: Detected a request with potential user-input going into an `Ok()` response. + This bypasses any view or template environments, including HTML escaping, which + may expose this application to cross-site scripting (XSS) vulnerabilities. Consider + using a view technology such as Twirl which automatically escapes HTML views. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sanitizers: + - pattern-either: + - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) + - pattern: org.owasp.encoder.Encode.forHtml(...) + pattern-sinks: + - pattern-either: + - pattern: Html.apply(...) + - pattern: Ok(...).as(HTML) + - pattern: Ok(...).as(ContentTypes.HTML) + - patterns: + - pattern: Ok(...).as($CTYPE) + - metavariable-regex: + metavariable: $CTYPE + regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' + - patterns: + - pattern: Ok(...).as($CTYPE) + - pattern-not: Ok(...).as("...") + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + severity: WARNING + languages: + - scala +- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + patterns: + - pattern-either: + - pattern: | + $DF = DocumentBuilderFactory.newInstance(...) + ... + $DB = $DF.newDocumentBuilder(...) + - patterns: + - pattern: $DB = DocumentBuilderFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $DB.newDocumentBuilder(...) + - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: Document Builder being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + shortlink: https://sg.run/gRQn + semgrep.dev: + rule: + r_id: 19041 + rv_id: 1263673 + rule_id: 0oUwzP + version_id: X0TzyRq + url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + origin: community +- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + patterns: + - pattern-either: + - pattern: $SR = new SAXReader(...) + - pattern: | + $SF = SAXParserFactory.newInstance(...) + ... + $SR = $SF.newSAXParser(...) + - patterns: + - pattern: $SR = SAXParserFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $SR.newSAXParser(...) + - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) + - pattern: $SR = new SAXBuilder(...) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: XML processor being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Parsers can result in XML Internal Entity Processing vulnerabilities like + the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + shortlink: https://sg.run/QbYP + semgrep.dev: + rule: + r_id: 19042 + rv_id: 1263678 + rule_id: KxUrkq + version_id: rxTAKWY + url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + origin: community +- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + patterns: + - pattern-not-inside: | + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) + - pattern-either: + - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) + - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) + - pattern: $XMLFACTORY = new XMLInputFactory(...) + message: XMLInputFactory being instantiated without calling the setProperty functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + shortlink: https://sg.run/3BEb + semgrep.dev: + rule: + r_id: 19043 + rv_id: 1263683 + rule_id: qNUQ7w + version_id: xyTjzkA + url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + origin: community +- id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + patterns: + - pattern-either: + - pattern: X-Requested-With = "*" + - pattern: Csrf-Token = "..." + - pattern-inside: | + bypassHeaders {... + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."application/x-www-form-urlencoded"..."multipart/form-data"..."text/plain"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."application/x-www-form-urlencoded"..."text/plain"..."multipart/form-data"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."multipart/form-data"..."application/x-www-form-urlencoded"..."text/plain"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."multipart/form-data"..."text/plain"..."application/x-www-form-urlencoded"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."text/plain"..."application/x-www-form-urlencoded"..."multipart/form-data"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."text/plain"..."multipart/form-data"..."application/x-www-form-urlencoded"...] + ... + ...} + message: "Possibly bypassable CSRF configuration found. CSRF is an attack that forces + an end user to execute unwanted actions on a web application in which they\u2019re + currently authenticated. Make sure that Content-Type black list is configured + and CORS filter is turned on." + languages: + - generic + severity: ERROR + paths: + include: + - '*.conf' + metadata: + references: + - https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes + - https://owasp.org/www-community/attacks/csrf + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - scala + - play + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + shortlink: https://sg.run/4DEE + semgrep.dev: + rule: + r_id: 19044 + rv_id: 1263684 + rule_id: lBUyRR + version_id: O9Tpx53 + url: https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + origin: community +- id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + mode: search + paths: + include: + - '*.erb' + patterns: + - pattern: | + params[...] + - pattern-inside: | + render :file => ... + message: Found request parameters in a call to `render` in a dynamic context. This + can allow end users to request arbitrary local files which may result in leaking + sensitive information persisted on disk. + languages: + - generic + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + shortlink: https://sg.run/3QWl + semgrep.dev: + rule: + r_id: 20043 + rv_id: 1263651 + rule_id: JDUokO + version_id: QkTGq9X + url: https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + origin: community +- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + mode: taint + pattern-sources: + - patterns: + - pattern: params[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + render ..., file: $X + - pattern: | + render ..., inline: $X + - pattern: | + render ..., template: $X + - pattern: | + render ..., action: $X + - pattern: | + render $X, ... + - focus-metavariable: $X + pattern-sanitizers: + - patterns: + - pattern: $MAP[...] + - metavariable-pattern: + metavariable: $MAP + patterns: + - pattern-not-regex: params + - pattern: File.basename(...) + message: Found request parameters in a call to `render`. This can allow end users + to request arbitrary local files which may result in leaking sensitive information + persisted on disk. Where possible, avoid letting users specify template paths + for `render`. If you must allow user input, use an allow-list of known templates + or normalize the user-supplied value with `File.basename(...)`. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + vulnerability_class: + - Path Traversal + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + shortlink: https://sg.run/Jw8Z + semgrep.dev: + rule: + r_id: 20046 + rv_id: 1409407 + rule_id: ReU2pZ + version_id: K3TgANN + url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + origin: community +- id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/ALD6 + semgrep.dev: + rule: + r_id: 20050 + rv_id: 1263682 + rule_id: WAUY8B + version_id: w8TRoO6 + url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + origin: community + pattern-sources: + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = $A { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: s"..." + - pattern: f"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) + - pattern-not-inside: throw new $EXCEPTION(...) + pattern-sanitizers: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $LOGGER.$METHOD(...) + - pattern: $LOGGER(...) + - metavariable-regex: + metavariable: $LOGGER + regex: (i?)log.* + - patterns: + - pattern: $LOGGER.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (i?)(trace|info|warn|warning|warnToError|error|debug) +- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/BeW9 + semgrep.dev: + rule: + r_id: 20051 + rv_id: 1263688 + rule_id: 0oUpon + version_id: ZRTKAoG + url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern: s"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) +- id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + patterns: + - pattern: | + $KEY: $VALUE + - pattern-inside: | + data: ... + - pattern-inside: | + kind: Secret + ... + - metavariable-regex: + metavariable: $VALUE + regex: (?i)^[aA-zZ0-9+/]+={0,2}$ + - metavariable-analysis: + analyzer: entropy + metavariable: $VALUE + message: 'Secrets ($VALUE) should not be stored in infrastructure as code files. + Use an alternative such as Bitnami Sealed Secrets or KSOPS to encrypt Kubernetes + Secrets. ' + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - kubernetes + references: + - https://kubernetes.io/docs/concepts/configuration/secret/ + - https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF + - https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html + - https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/ + - https://github.com/bitnami-labs/sealed-secrets + - https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/ + - https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/ + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + shortlink: https://sg.run/KyL6 + semgrep.dev: + rule: + r_id: 20055 + rv_id: 1263942 + rule_id: YGUYEb + version_id: xyTjz5B + url: https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + origin: community + languages: + - yaml + severity: WARNING +- id: ruby.rails.security.brakeman.check-sql.check-sql + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + :$KEY => $X + - pattern-inside: | + ["...",$X,...] + - pattern: | + params[...].to_i + - pattern: | + params[...].to_f + - patterns: + - pattern: | + params[...] ? $A : $B + - metavariable-pattern: + metavariable: $A + patterns: + - pattern-not: | + params[...] + - metavariable-pattern: + metavariable: $B + patterns: + - pattern-not: | + params[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-not-inside: | + $P.where("...",...) + - pattern-not-inside: | + $P.where(:$KEY => $VAL,...) + - pattern-either: + - pattern-inside: | + $P.$M(...) + - pattern-inside: | + $P.$M("...",...) + - pattern-inside: | + class $P < ActiveRecord::Base + ... + end + - metavariable-regex: + metavariable: $M + regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) + message: Found potential SQL injection due to unsafe SQL query construction via + $X. Where possible, prefer parameterized queries. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/SQL_Injection + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql + shortlink: https://sg.run/vpgb + semgrep.dev: + rule: + r_id: 20533 + rv_id: 1263661 + rule_id: OrUv2z + version_id: DkTRbE4 + url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql + origin: community +- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X. ... .to_proc + - patterns: + - pattern-inside: | + $Y.method($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap{ |$ANY| $Z } + - focus-metavariable: $Z + message: Found user-controllable input to a reflection method. This may allow a + user to alter program behavior and potentially execute arbitrary instructions + in the context of the process. Do not provide arbitrary user input to `tap`, `method`, + or `to_proc` + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + shortlink: https://sg.run/dPYd + semgrep.dev: + rule: + r_id: 20534 + rv_id: 1263662 + rule_id: eqUZ2Q + version_id: WrTqKLA + url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + origin: community +- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + message: Found the use of an hardcoded passphrase for RSA. The passphrase can be + easily discovered, and therefore should not be stored in source-code. It is recommended + to remove the passphrase from source-code, and use system environment variables + or a restricted configuration file. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - secrets + category: security + references: + - https://cwe.mitre.org/data/definitions/522.html + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + shortlink: https://sg.run/xPEe + semgrep.dev: + rule: + r_id: 20730 + rv_id: 1263607 + rule_id: bwULyN + version_id: K3TKkEo + url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') + - patterns: + - pattern-inside: | + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + - pattern-either: + - pattern: | + $OPENSSL.export(...,'...') + - pattern: | + $OPENSSL.to_pem(...,'...') + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + end + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + def $METHOD(...) + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + $ASSIGN = '...' + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) +- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X.constantize + - pattern-inside: | + $X. ... .safe_constantize + - pattern-inside: | + const_get(...) + - pattern-inside: | + qualified_const_get(...) + message: Found user-controllable input to Ruby reflection functionality. This allows + a remote user to influence runtime behavior, up to and including arbitrary remote + code execution. Do not provide user-controllable input to reflection functionality. + Do not call symbol conversion on user-controllable input. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + shortlink: https://sg.run/vpEX + semgrep.dev: + rule: + r_id: 20733 + rv_id: 1263663 + rule_id: wdUkYA + version_id: 0bTKzn8 + url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + origin: community +- id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + patterns: + - pattern-inside: | + $CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...) + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + metavariable: $CHECK_ORIGIN + comparison: $CHECK_ORIGIN == False + message: Automatic check of the referrer for cross-site request forgery tokens has + been explicitly disabled globally, which might leave views unprotected when an + unsafe CSRF storage policy is used. Use 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)' + to turn the automatic check for all unsafe methods (per RFC2616). + languages: + - python + severity: ERROR + fix: | + True + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + shortlink: https://sg.run/3GeW + semgrep.dev: + rule: + r_id: 21443 + rv_id: 1263563 + rule_id: eqU9Le + version_id: K3TKkeo + url: https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + origin: community +- id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + message: Origin check for the CSRF token is disabled for this view. This might represent + a security risk if the CSRF storage policy is not known to be secure. + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + asvs: + section: V4 Access Control + control_id: 4.2.2 CSRF + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + version: '4' + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + shortlink: https://sg.run/4RB9 + semgrep.dev: + rule: + r_id: 21444 + rv_id: 1263564 + rule_id: v8UGpL + version_id: qkTR7Gv + url: https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern-inside: | + from pyramid.view import view_config + ... + @view_config(..., check_origin=$CHECK_ORIGIN, ...) + def $VIEW(...): + ... + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + metavariable: $CHECK_ORIGIN + comparison: $CHECK_ORIGIN == False + fix: | + True +- id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + patterns: + - pattern-inside: | + $CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...) + - pattern: $REQUIRE_CSRF + - metavariable-comparison: + metavariable: $REQUIRE_CSRF + comparison: $REQUIRE_CSRF == False + message: Automatic check of cross-site request forgery tokens has been explicitly + disabled globally, which might leave views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)' + to turn the automatic check for all unsafe methods (per RFC2616). + languages: + - python + severity: ERROR + fix: | + True + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + shortlink: https://sg.run/Bx2R + semgrep.dev: + rule: + r_id: 21451 + rv_id: 1263571 + rule_id: 8GUKqP + version_id: 2KTv2en + url: https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + origin: community +- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + message: Detected data rendered directly to the end user via 'Response'. This bypasses + Pyramid's built-in cross-site scripting (XSS) defenses and could result in an + XSS vulnerability. Use Pyramid's template engines to safely render HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + shortlink: https://sg.run/DX8G + semgrep.dev: + rule: + r_id: 21452 + rv_id: 1263572 + rule_id: gxUeA8 + version_id: X0TzyEe + url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + origin: community + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + pyramid.request.Response.text($SINK) + - pattern: | + pyramid.request.Response($SINK) + - pattern: | + $REQ.response.body = $SINK + - pattern: | + $REQ.response.text = $SINK + - pattern: | + $REQ.response.ubody = $SINK + - pattern: | + $REQ.response.unicode_body = $SINK + - pattern: $SINK +- id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause + sql injections if the developer inputs raw SQL into the before-mentioned clauses. + This pattern captures relevant cases in which the developer inputs raw SQL into + the distinct, having, group_by, order_by or filter clauses and injects user-input + into the raw SQL with any function besides "bindparams". Use bindParams to securely + bind user-input to SQL statements. + languages: + - python + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data + technology: + - pyramid + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + shortlink: https://sg.run/W7eE + semgrep.dev: + rule: + r_id: 21453 + rv_id: 1263573 + rule_id: QrUZ7l + version_id: jQTn5WA + url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + from pyramid.view import view_config + ... + @view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-inside: | + $QUERY = $REQ.dbsession.query(...) + ... + - pattern-either: + - pattern: | + $QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: | + $QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: $SINK + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + fix-regex: + regex: format + replacement: bindparams +- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + message: Use of angular.element can lead to XSS if user-input is treated as part + of the HTML element within `$SINK`. It is recommended to contextually output encode + user-input, before inserting into `$SINK`. If the HTML needs to be preserved it + is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + confidence: MEDIUM + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angularjs + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + shortlink: https://sg.run/5AQ0 + semgrep.dev: + rule: + r_id: 21503 + rv_id: 1263091 + rule_id: GdUP71 + version_id: 44TEj8L + url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: window.location.search + - pattern: window.document.location.search + - pattern: document.location.search + - pattern: location.search + - pattern: $location.search(...) + - patterns: + - pattern-either: + - pattern: $DECODE(<... location.hash ...>) + - pattern: $DECODE(<... window.location.hash ...>) + - pattern: $DECODE(<... document.location.hash ...>) + - pattern: $DECODE(<... location.href ...>) + - pattern: $DECODE(<... window.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.URL ...>) + - pattern: $DECODE(<... window.document.URL ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... $location.absUrl() ...>) + - pattern: $DECODE(<... $location.url() ...>) + - pattern: $DECODE(<... $location.hash() ...>) + - metavariable-regex: + metavariable: $DECODE + regex: ^(unescape|decodeURI|decodeURIComponent)$ + - patterns: + - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|delete|head|jsonp|post|put|patch) + - pattern: $RES.data + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + angular.element(...). ... .$SINK($QUERY) + - pattern-inside: | + $ANGULAR = angular.element(...) + ... + $ANGULAR. ... .$SINK($QUERY) + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) +- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: pickle.load($SINK,...) + - pattern: pickle.loads($SINK,...) + - pattern: _pickle.load($SINK,...) + - pattern: _pickle.loads($SINK,...) + - pattern: cPickle.load($SINK,...) + - pattern: cPickle.loads($SINK,...) + - pattern: dill.load($SINK,...) + - pattern: dill.loads($SINK,...) + - pattern: shelve.open($SINK,...) + message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. + When unpickling, the serialized data could be manipulated to run arbitrary code. + Instead, consider serializing the relevant data as JSON or a similar text-based + serialization format. + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + shortlink: https://sg.run/JbjW + semgrep.dev: + rule: + r_id: 21602 + rv_id: 1263345 + rule_id: JDUDQg + version_id: LjTkgd9 + url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + origin: community + languages: + - python + severity: WARNING +- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...}) + pattern-sanitizers: + - patterns: + - pattern: | + DB::raw("...",[...]) + pattern-sinks: + - patterns: + - pattern: | + DB::raw(...) + message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL + injection via string concatenation or unsafe interpolation. + languages: + - php + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md + technology: + - php + - laravel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + shortlink: https://sg.run/x94g + semgrep.dev: + rule: + r_id: 21674 + rv_id: 1263305 + rule_id: zdUln0 + version_id: qkTR7A9 + url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + origin: community +- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + mode: taint + pattern-sources: + - patterns: + - pattern: | + public function $F(...,Request $R,...){...} + - focus-metavariable: $R + - patterns: + - pattern-either: + - pattern: | + $this->$PROPERTY + - pattern: | + $this->$PROPERTY->$GET + - metavariable-pattern: + metavariable: $PROPERTY + patterns: + - pattern-either: + - pattern: query + - pattern: request + - pattern: headers + - pattern: cookies + - pattern: cookie + - pattern: files + - pattern: file + - pattern: allFiles + - pattern: input + - pattern: all + - pattern: post + - pattern: json + - pattern-either: + - pattern-inside: | + class $CL extends Illuminate\Http\Request {...} + - pattern-inside: | + class $CL extends Illuminate\Foundation\Http\FormRequest {...} + pattern-sinks: + - patterns: + - pattern: | + Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...) + - focus-metavariable: $IGNORE + message: Found a request argument passed to an `ignore()` definition in a Rule constraint. + This can lead to SQL injection. + languages: + - php + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - php + - laravel + references: + - https://laravel.com/docs/9.x/validation#rule-unique + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + shortlink: https://sg.run/vkeb + semgrep.dev: + rule: + r_id: 21677 + rv_id: 1263314 + rule_id: X5ULgE + version_id: DkTRbBl + url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + origin: community +- id: java.spring.security.injection.tainted-html-string.tainted-html-string + languages: + - java + severity: ERROR + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. You can use the OWASP ESAPI encoder if you must render user + data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string + shortlink: https://sg.run/ObdR + semgrep.dev: + rule: + r_id: 22075 + rv_id: 1409395 + rule_id: YGUvkL + version_id: 3ZT2598 + url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + - label: CONCAT + by-side-effect: true + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + ... + - pattern: | + "$HTMLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$HTMLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$HTMLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$HTMLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$HTMLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $HTMLSTR + regex: ^<\w+ + pattern-propagators: + - pattern: (StringBuilder $SB).append($...TAINTED) + from: $...TAINTED + to: $SB + - pattern: $VAR += $...TAINTED + from: $...TAINTED + to: $VAR + pattern-sinks: + - requires: CONCAT + patterns: + - pattern-either: + - pattern: new ResponseEntity<>($PAYLOAD, ...) + - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) + - pattern: ResponseEntity. ... .body($PAYLOAD) + - patterns: + - pattern: | + ResponseEntity.$RESPFUNC($PAYLOAD). ... + - metavariable-regex: + metavariable: $RESPFUNC + regex: ^(ok|of)$ + - focus-metavariable: $PAYLOAD + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) +- id: java.spring.security.injection.tainted-system-command.tainted-system-command + languages: + - java + severity: ERROR + mode: taint + pattern-propagators: + - pattern: (StringBuilder $STRB).append($INPUT) + from: $INPUT + to: $STRB + label: CONCAT + requires: INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $SOURCE + - pattern: $SOURCE + $Y + - pattern: String.format("...", ..., $SOURCE, ...) + - pattern: String.join("...", ..., $SOURCE, ...) + - pattern: (String $STR).concat($SOURCE) + - pattern: $SOURCE.concat(...) + - pattern: $X += $SOURCE + - pattern: $SOURCE += $X + label: CONCAT + requires: INPUT + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (Process $P) = new Process(...); + - pattern: | + (ProcessBuilder $PB).command(...); + - patterns: + - pattern-either: + - pattern: | + (Runtime $R).$EXEC(...); + - pattern: | + Runtime.getRuntime(...).$EXEC(...); + - metavariable-regex: + metavariable: $EXEC + regex: (exec|loadLibrary|load) + - patterns: + - pattern: | + (ProcessBuilder $PB).command(...).$ADD(...); + - metavariable-regex: + metavariable: $ADD + regex: (add|addAll) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $BUILDER = new ProcessBuilder(...); + ... + - pattern: $BUILDER.start(...) + - pattern: | + new ProcessBuilder(...). ... .start(...); + requires: CONCAT + message: 'Detected user input entering a method which executes a system command. + This could result in a command injection vulnerability, which allows an attacker + to inject an arbitrary system command onto the server. The attacker could download + malware onto or steal data from the server. Instead, use ProcessBuilder, separating + the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", + targetDirectory)`. Further, make sure you hardcode or allowlist the actual command + so that attackers can''t run arbitrary commands.' + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - java + - spring + confidence: HIGH + references: + - https://www.stackhawk.com/blog/command-injection-java/ + - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html + - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command + shortlink: https://sg.run/epY0 + semgrep.dev: + rule: + r_id: 22076 + rv_id: 1263087 + rule_id: 6JUxGN + version_id: 8KT5rnP + url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command + origin: community +- id: java.spring.security.injection.tainted-url-host.tainted-url-host + languages: + - java + severity: ERROR + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode + the correct host, or ensure that the user data can only affect the path or parameters. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/vkYn + semgrep.dev: + rule: + r_id: 22077 + rv_id: 1263088 + rule_id: oqUZo8 + version_id: gETB708 + url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - pattern-either: + - pattern: new URL($ONEARG) + - patterns: + - pattern-either: + - pattern: | + "$URLSTR" + ... + - pattern: | + "$URLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$URLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$URLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern: String.format("$URLSTR", ...) + - pattern-not: String.format("$URLSTR", "...", ...) + - patterns: + - pattern-inside: | + String $VAR = "$URLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: http(s?)://%(v|s|q).* +- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + mode: taint + languages: + - ruby + message: Deserialization of a string tainted by `event` object found. Objects in + Ruby can be serialized into strings, then later loaded from strings. However, + uses of `load` can cause remote code execution. Loading user input with MARSHAL, + YAML or CSV can potentially be dangerous. If you need to deserialize untrusted + data, you should use JSON as it is only capable of returning 'primitive' types + such as strings, arrays, hashes, numbers and nil. + metadata: + references: + - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + category: security + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + technology: + - ruby + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + shortlink: https://sg.run/dplX + semgrep.dev: + rule: + r_id: 22078 + rv_id: 1263585 + rule_id: zdUlNJ + version_id: vdT06gR + url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + origin: community + pattern-sinks: + - patterns: + - pattern: $SINK + - pattern-either: + - pattern-inside: | + YAML.load($SINK,...) + - pattern-inside: | + CSV.load($SINK,...) + - pattern-inside: | + Marshal.load($SINK,...) + - pattern-inside: | + Marshal.restore($SINK,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + message: The libxml library processes user-input with the `noent` attribute is set + to `true` which can lead to being vulnerable to XML External Entities (XXE) type + attacks. It is recommended to set `noent` to `false` when using this feature to + ensure you are protected. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + shortlink: https://sg.run/Z75x + semgrep.dev: + rule: + r_id: 22079 + rv_id: 1263138 + rule_id: pKUNeD + version_id: d6TyxpX + url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('$IMPORT') + ... + - pattern-inside: | + import $XML from '$IMPORT' + ... + - pattern-inside: | + import * as $XML from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + shortlink: https://sg.run/LYvG + semgrep.dev: + rule: + r_id: 22083 + rv_id: 1263143 + rule_id: 10Uo39 + version_id: LjTkgle + url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern-inside: | + import $SESSION from 'express-session' + ... + - pattern-inside: | + import {..., $SESSION, ...} from 'express-session' + ... + - pattern-inside: | + import * as $SESSION from 'express-session' + ... + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: | + $SECRET = $VALUE + ... + $APP.use($SESSION($SECRET)) + - pattern: | + secret: '$Y' +- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + message: The following function call $SER.$FUNC accepts user controlled data which + can result in Remote Code Execution (RCE) through Object Deserialization. It is + recommended to use secure data processing alternatives such as JSON.parse() and + Buffer.from(). + options: + interfile: true + metadata: + interfile: true + technology: + - express + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + shortlink: https://sg.run/8W5j + semgrep.dev: + rule: + r_id: 22084 + rv_id: 1263145 + rule_id: 9AUyqj + version_id: gETB7nD + url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $SER = require('$IMPORT') + ... + - pattern-inside: | + import $SER from '$IMPORT' + ... + - pattern-inside: | + import * as $SER from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + message: Detected a sequelize statement that is tainted by user-input. This could + lead to SQL injection if the variable is user-controlled and is not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. + options: + interfile: true + metadata: + interfile: true + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + category: security + technology: + - express + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + shortlink: https://sg.run/gjoe + semgrep.dev: + rule: + r_id: 22085 + rv_id: 1263241 + rule_id: yyU0GX + version_id: nWT2Llx + url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) +- id: javascript.express.security.audit.express-ssrf.express-ssrf + message: 'The following request $REQUEST.$METHOD() was found to be crafted from + user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities. + It is recommended where possible to not allow user-input to craft the base request, + but to be treated as part of the path or query parameter. When user-input is necessary + to craft the request, it is recommeneded to follow OWASP best practices to prevent + abuse. ' + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + technology: + - express + category: security + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf + shortlink: https://sg.run/0PNw + semgrep.dev: + rule: + r_id: 22554 + rv_id: 1263144 + rule_id: eqU9l2 + version_id: 8KT5rBr + url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + options: + taint_unify_mvars: true + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, ...) {...} + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,...) => + {...} + - pattern-inside: | + ({ $REQ }: $EXPRESS.Request,...) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) + - pattern: $REQ. ... .$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) + - pattern: $REQ.$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = "$HTTP"+ $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A + ... + - pattern-inside: | + $ASSIGN = `$HTTP${$REQ.$VALUE[...]}...` + ... + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQUEST.$METHOD($ASSIGN,...) + - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) + - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) + - patterns: + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) + - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern: $ASSIGN + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ +- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + message: Detected usage of dangerous method $METHOD which does not escape inputs + (see link in references). If the argument is user-controlled, this can lead to + SQL injection. When using $METHOD function, do not trust user-submitted data and + only allow approved list of input (possibly, use an allowlist approach). + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-inside: | + import ("gorm.io/gorm") + ... + - patterns: + - pattern-inside: | + func $VAL(..., $GORM *gorm.DB,... ) { + ... + } + - pattern-either: + - pattern: | + $GORM. ... .$METHOD($VALUE) + - pattern: | + $DB := $GORM. ... .$ANYTHING(...) + ... + $DB. ... .$METHOD($VALUE) + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) + options: + interfile: true + metadata: + category: security + technology: + - gorm + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://gorm.io/docs/security.html#SQL-injection-Methods + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + shortlink: https://sg.run/R4qg + semgrep.dev: + rule: + r_id: 24693 + rv_id: 1262915 + rule_id: AbU5o3 + version_id: l4TJRJK + url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + origin: community +- id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + message: Anonymous access shouldn't be allowed unless explicit by design. Access + control checks are missing and potentially can be bypassed. This finding violates + the principle of least privilege or deny by default, where access should only + be permitted for a specific set of roles or conforms to a custom policy or users. + severity: INFO + metadata: + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-862: Missing Authorization' + cwe2021-top25: true + cwe2022-top25: true + cwe2023-top25: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://cwe.mitre.org/data/definitions/862.html + - https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0 + subcategory: + - vuln + technology: + - .net + - mvc + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + shortlink: https://sg.run/Z8GA + semgrep.dev: + rule: + r_id: 26335 + rv_id: 1262615 + rule_id: eqU32Y + version_id: o5TbD41 + url: https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + origin: community + languages: + - csharp + patterns: + - pattern: | + public class $CLASS : Controller { + ... + } + - pattern-inside: | + using Microsoft.AspNetCore.Mvc; + ... + - pattern-not: | + [AllowAnonymous] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize(Roles = ...)] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize(Policy = ...)] + public class $CLASS : Controller { + ... + } +- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - pattern-either: + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...) + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...) + - pattern: $LOOP.subprocess_exec(...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", "...", ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c",...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", "...", ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", ...], ...) + message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled + data. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + shortlink: https://sg.run/Apjp + semgrep.dev: + rule: + r_id: 27250 + rv_id: 1263460 + rule_id: 7KUE1E + version_id: WrTqKXz + url: https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern-inside: asyncio.create_subprocess_shell($CMD, ...) + - focus-metavariable: $CMD + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...") + - pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...) + - pattern-not: asyncio.create_subprocess_shell("...", ...) + message: Detected asyncio subprocess function with user controlled data. You may + consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + shortlink: https://sg.run/Dx8Y + semgrep.dev: + rule: + r_id: 27252 + rv_id: 1263462 + rule_id: 8GU5q3 + version_id: K3TKkDn + url: https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + confidence: MEDIUM + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + shortlink: https://sg.run/qL6z + semgrep.dev: + rule: + r_id: 27256 + rv_id: 1263466 + rule_id: 4bUEAY + version_id: 6xT29l6 + url: https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + shortlink: https://sg.run/Y3Ke + semgrep.dev: + rule: + r_id: 27258 + rv_id: 1263468 + rule_id: JDUz34 + version_id: zyTb2wn + url: https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - pattern: shlex.quote(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], + ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), + ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + message: Detected subprocess function '$FUNC' with user controlled data. A malicious + actor could leverage this to perform command injection. You may consider using + 'shlex.quote()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + shortlink: https://sg.run/pLGg + semgrep.dev: + rule: + r_id: 27262 + rv_id: 1263472 + rule_id: AbUgrZ + version_id: jQTn54Y + url: https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: | + $X = __import__("os") + ... + $X.system(...) + - pattern: | + $X = __import__("os") + ... + getattr($X, "system")(...) + - pattern: | + $X = getattr(os, "system") + ... + $X(...) + - pattern: | + $X = __import__("os") + ... + $Y = getattr($X, "system") + ... + $Y(...) + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + message: Found user-controlled data used in a system call. This could allow a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + shortlink: https://sg.run/XR2K + semgrep.dev: + rule: + r_id: 27264 + rv_id: 1263474 + rule_id: DbUR9g + version_id: 9lT4bG4 + url: https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-os-exec.dangerous-os-exec + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + confidence: MEDIUM + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec + shortlink: https://sg.run/yL9x + semgrep.dev: + rule: + r_id: 27268 + rv_id: 1263523 + rule_id: qNUR13 + version_id: 6xT29rz + url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + - patterns: + - pattern-either: + - pattern: os.environ['$ANYTHING'] + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb['$ANYTHING'] + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv[...] + - pattern: sys.orig_argv[...] + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/r8Zn + semgrep.dev: + rule: + r_id: 27269 + rv_id: 1263524 + rule_id: lBUJrn + version_id: o5TbDO5 + url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], + ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), + ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + message: Detected subprocess function '$FUNC' with user controlled data. A malicious + actor could leverage this to perform command injection. You may consider using + 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/NWxp + semgrep.dev: + rule: + r_id: 27271 + rv_id: 1263526 + rule_id: JDUz3R + version_id: pZT038J + url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-system-call.dangerous-system-call + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: getattr(os, "system")(...) + - pattern: __import__("os").system(...) + - pattern: getattr(__import__("os"), "system")(...) + - pattern: | + $X = __import__("os") + ... + $X.system(...) + - pattern: | + $X = __import__("os") + ... + getattr($X, "system")(...) + - pattern: | + $X = getattr(os, "system") + ... + $X(...) + - pattern: | + $X = __import__("os") + ... + $Y = getattr($X, "system") + ... + $Y(...) + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + message: Found user-controlled data used in a system call. This could allow a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/k0W7 + semgrep.dev: + rule: + r_id: 27272 + rv_id: 1263527 + rule_id: 5rUoP1 + version_id: 2KTv2Zn + url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(..., $REQUEST, ...): + ... + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + shortlink: https://sg.run/49BE + semgrep.dev: + rule: + r_id: 31144 + rv_id: 1263388 + rule_id: EwUepx + version_id: 7ZTE3qK + url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + origin: community +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + shortlink: https://sg.run/5gW3 + semgrep.dev: + rule: + r_id: 31147 + rv_id: 1263433 + rule_id: 8GU3qp + version_id: bZT53gQ + url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + origin: community +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `actions/github-script`''s `script:` step could allow an attacker to inject + their own code into the runner. This would allow them to steal secrets and code. + `github` context data can have arbitrary user input and should be treated as untrusted. + Instead, use an intermediate environment variable with `env:` to store the data + and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + technology: + - github-actions + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + shortlink: https://sg.run/g1G0 + semgrep.dev: + rule: + r_id: 31441 + rv_id: 1423394 + rule_id: OrUQvK + version_id: 5PT7Zyw + url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + uses: $ACTION + ... + - pattern-inside: | + with: + ... + script: ... + ... + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: php.lang.security.injection.echoed-request.echoed-request + mode: taint + message: '`Echo`ing user input risks cross-site scripting vulnerability. You should + use `htmlentities()` when showing data to users.' + languages: + - php + severity: ERROR + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + pattern-sinks: + - pattern: echo $...VARS; + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + fix: echo htmlentities($...VARS); + metadata: + technology: + - php + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request + shortlink: https://sg.run/Bqqb + semgrep.dev: + rule: + r_id: 31707 + rv_id: 1263283 + rule_id: BYUyyg + version_id: d6TyxE9 + url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request + origin: community +- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/Gj32 + semgrep.dev: + rule: + r_id: 59048 + rv_id: 1263061 + rule_id: j2Udpk + version_id: YDTZeko + url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` + and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - + The previous links are not meant to be clicked. They are the literal config key + values that are supposed to be used to disable these features. For more information, + see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = SAXParserFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newSAXParser(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newSAXParser(); + languages: + - java +- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + shortlink: https://sg.run/1wyQ + semgrep.dev: + rule: + r_id: 59622 + rv_id: 1263062 + rule_id: v8UeQ1 + version_id: 6xT29GK + url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + origin: community + message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" + and "accessExternalStylesheet" to "". + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = TransformerFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newTransformer(...); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + $FACTORY.newTransformer(...); + languages: + - java +- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + message: Detected input from a HTTPServletRequest going into the environment variables + of an 'exec' command. Instead, call the command with user-supplied arguments + by using the overloaded method with one String array as the argument. `exec({"command", + "arg1", "arg2"})`. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); + - focus-metavariable: $ENV_ARGS + metadata: + category: security + technology: + - java + cwe: + - 'CWE-454: External Initialization of Trusted Variables or Data Stores' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: false + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + shortlink: https://sg.run/EJAB + semgrep.dev: + rule: + r_id: 70981 + rv_id: 1409391 + rule_id: nJULjy + version_id: LjTRL6W + url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + origin: community +- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + languages: + - clojure + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://xerces.apache.org/xerces2-j/features.html + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml + category: security + technology: + - clojure + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + shortlink: https://sg.run/v7An + semgrep.dev: + rule: + r_id: 71533 + rv_id: 1262608 + rule_id: bwU3Gj + version_id: WrTqKyD + url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + origin: community + message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. + Without prohibiting external entity declarations, this is vulnerable to XML external + entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern-inside: | + (ns ... (:require [clojure.xml :as ...])) + ... + - pattern-either: + - pattern-inside: | + (def ... ... ( ... )) + - pattern-inside: | + (defn ... ... ( ... )) + - pattern-either: + - pattern: (clojure.xml/parse $INPUT) + - patterns: + - pattern-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) + - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" + false) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ...) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ...) +- id: generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param + languages: + - generic + severity: ERROR + message: To remediate this issue, ensure that all URL parameters are properly escaped + before including them in scripts. Please update your code to use either the JSENCODE + method to escape URL parameters or the escape="true" attribute on + tags. Passing URL parameters directly into scripts and DOM sinks creates an opportunity + for Cross-Site Scripting attacks. Cross-Site Scripting (XSS) attacks are a type + of injection, in which malicious scripts are injected into otherwise benign and + trusted websites. To remediate this issue, ensure that all URL parameters are + properly escaped before including them in scripts. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/pages_security_tips_xss.htm + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param + shortlink: https://sg.run/9bGk + semgrep.dev: + rule: + r_id: 72423 + rv_id: 1262906 + rule_id: BYUAJ2 + version_id: GxTkekB + url: https://semgrep.dev/playground/r/GxTkekB/generic.visualforce.security.ncino.vf.xssfromunescapedurlparam.xss-from-unescaped-url-param + origin: community + patterns: + - pattern-either: + - pattern: + - pattern: + - pattern: + - pattern-not: + paths: + include: + - '*.component' + - '*.page' +- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + languages: + - generic + severity: INFO + message: Visualforce Pages must have the cspHeader attribute set to true. This attribute + is available in API version 55 or higher. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + shortlink: https://sg.run/yoj8 + semgrep.dev: + rule: + r_id: 72424 + rv_id: 1262907 + rule_id: DbUj7d + version_id: RGT0L0r + url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + origin: community + patterns: + - pattern: ... + - pattern-not: ... + - pattern-not: ...... + - pattern-not: ...... + paths: + include: + - '*.page' +- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + languages: + - generic + severity: WARNING + message: Visualforce Pages must use API version 55 or higher for required use of + the cspHeader attribute set to true. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + shortlink: https://sg.run/rWr6 + semgrep.dev: + rule: + r_id: 72425 + rv_id: 1262908 + rule_id: WAUwJW + version_id: A8Tgdgn + url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + origin: community + patterns: + - pattern-inside: + - pattern-either: + - pattern-regex: '[>][0-9].[0-9][<]' + - pattern-regex: '[>][1-4][0-9].[0-9][<]' + - pattern-regex: '[>][5][0-4].[0-9][<]' + paths: + include: + - '*.page-meta.xml' +- id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + references: + - https://docs.python.org/3/library/xml.html + - https://github.com/tiran/defusedxml + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + shortlink: https://sg.run/n3jG + semgrep.dev: + rule: + r_id: 72436 + rv_id: 1263541 + rule_id: X5Uqnx + version_id: vdT06ER + url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + origin: community + message: The native Python `xml` library is vulnerable to XML External Entity (XXE) + attacks. These attacks can leak confidential data and "XML bombs" can cause denial + of service. Do not use this library to parse untrusted input. Instead the Python + documentation recommends using `defusedxml`. + languages: + - python + severity: ERROR + patterns: + - pattern: xml.etree.ElementTree.parse($...ARGS) + - pattern-not: xml.etree.ElementTree.parse("...") + fix: defusedxml.etree.ElementTree.parse($...ARGS) +- id: php.lang.security.tainted-exec.tainted-exec + mode: taint + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + pattern-sinks: + - pattern: exec(...) + - pattern: system(...) + - pattern: popen(...) + - pattern: passthru(...) + - pattern: shell_exec(...) + - pattern: pcntl_exec(...) + - pattern: proc_open(...) + pattern-sanitizers: + - pattern: escapeshellarg(...) + message: Executing non-constant commands. This can lead to command injection. You + should use `escapeshellarg()` when using command. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + references: + - https://www.stackhawk.com/blog/php-command-injection/ + - https://brightsec.com/blog/code-injection-php/ + - https://www.acunetix.com/websitesecurity/php-security-2/ + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec + shortlink: https://sg.run/JAkP + semgrep.dev: + rule: + r_id: 73146 + rv_id: 1263300 + rule_id: 9AUw06 + version_id: BjTkZ4y + url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec + origin: community + languages: + - php + severity: ERROR +- id: php.lang.security.injection.tainted-session.tainted-session + severity: WARNING + message: Session key based on user input risks session poisoning. The user can determine + the key used for the session, and thus write any session variable. Session variables + are typically trusted to be set only by the application, and manipulating the + session can result in access control issues. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-284: Improper Access Control' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://en.wikipedia.org/wiki/Session_poisoning + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session + shortlink: https://sg.run/bxNp + semgrep.dev: + rule: + r_id: 73470 + rv_id: 1263289 + rule_id: 4bUdoP + version_id: 8KT5rPE + url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $A . $B + - pattern: bin2hex(...) + - pattern: crc32(...) + - pattern: crypt(...) + - pattern: filter_input(...) + - pattern: filter_var(...) + - pattern: hash(...) + - pattern: md5(...) + - pattern: preg_filter(...) + - pattern: preg_grep(...) + - pattern: preg_match_all(...) + - pattern: sha1(...) + - pattern: sprintf(...) + - pattern: str_contains(...) + - pattern: str_ends_with(...) + - pattern: str_starts_with(...) + - pattern: strcasecmp(...) + - pattern: strchr(...) + - pattern: stripos(...) + - pattern: stristr(...) + - pattern: strnatcasecmp(...) + - pattern: strnatcmp(...) + - pattern: strncmp(...) + - pattern: strpbrk(...) + - pattern: strpos(...) + - pattern: strripos(...) + - pattern: strrpos(...) + - pattern: strspn(...) + - pattern: strstr(...) + - pattern: strtok(...) + - pattern: substr_compare(...) + - pattern: substr_count(...) + - pattern: vsprintf(...) + pattern-sinks: + - patterns: + - pattern-inside: $_SESSION[$KEY] = $VAL; + - pattern: $KEY +- id: php.lang.security.injection.printed-request.printed-request + mode: taint + message: '`Printing user input risks cross-site scripting vulnerability. You should + use `htmlentities()` when showing data to users.' + languages: + - php + severity: ERROR + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + pattern-sinks: + - pattern: print($...VARS); + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + fix: print(htmlentities($...VARS)); + metadata: + technology: + - php + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request + shortlink: https://sg.run/QrxEJ + semgrep.dev: + rule: + r_id: 128886 + rv_id: 1263284 + rule_id: KxUvRBw + version_id: ZRTKAk4 + url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request + origin: community +- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + message: A secret is hard-coded in the application. Secrets stored in source code, + such as credentials, identifiers, and other types of sensitive data, can be leaked + and used by internal or external malicious actors. It is recommended to rotate + the secret and retrieve them from a secure secret vault or Hardware Security Module + (HSM), alternatively environment variables can be used if allowed by your company + policy. + severity: WARNING + metadata: + likelihood: LOW + impact: HIGH + confidence: MEDIUM + category: security + subcategory: + - vuln + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2020-top25: true + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + technology: + - secrets + vulnerability_class: + - Hard-coded Secrets + source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + shortlink: https://sg.run/qN29x + semgrep.dev: + rule: + r_id: 137856 + rv_id: 1263257 + rule_id: ReUD6Kg + version_id: DkTRbLX + url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + origin: community + languages: + - kotlin + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: '$PASS = env[...] ?: $VALUE' + - metavariable-regex: + metavariable: $PASS + regex: (password|pass|passwd|loginPassword) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^[A-Za-z0-9/+=]+$ + paths: + include: + - '*build.gradle.kts' +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action + with the name `discussion.yaml`. + paths: + include: + - '**/.github/workflows/discussion.yaml' + metadata: + category: security + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + shortlink: https://sg.run/JdYPZ + semgrep.dev: + rule: + r_id: 238946 + rv_id: 1263927 + rule_id: 7KUDRPj + version_id: 6xT29ol + url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell + interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote + server is compromised or the URL is hijacked, an attacker can execute arbitrary + code in your CI runner. Consider downloading the file first, verifying its checksum + or signature, and then executing it." + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + technology: + - github-actions + - bash + - curl + cwe2021-top25: true + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + shortlink: https://sg.run/GR8K1 + semgrep.dev: + rule: + r_id: 309392 + rv_id: 1443456 + rule_id: x8UAgrE + version_id: 9lT3zYb + url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli + mode: taint + metadata: + references: + - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values + - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - slick + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + shortlink: https://sg.run/k9K2 + semgrep.dev: + rule: + r_id: 18328 + rv_id: 1263687 + rule_id: GdUDWO + version_id: d6TyxJe + url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + origin: community + message: Detected a tainted SQL statement. This could lead to SQL injection if variables + in the SQL statement are not properly sanitized. Avoid using using user input + for generating SQL strings. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.overrideSql(...) + - pattern: sql"..." + - pattern-inside: | + import slick.$DEPS + ... + severity: ERROR + languages: + - scala diff --git a/backend/app/sandbox/rules/default.yaml b/backend/app/sandbox/rules/default.yaml new file mode 100644 index 0000000..eca160a --- /dev/null +++ b/backend/app/sandbox/rules/default.yaml @@ -0,0 +1,70779 @@ +rules: +- id: c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + pattern: gets(...) + message: Avoid 'gets()'. This function does not consider buffer boundaries and can + lead to buffer overflows. Use 'fgets()' or 'gets_s()' instead. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - https://us-cert.cisa.gov/bsi/articles/knowledge/coding-practices/fgets-and-gets_s + category: security + technology: + - c + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + shortlink: https://sg.run/dKqX + semgrep.dev: + rule: + r_id: 8834 + rv_id: 945170 + rule_id: GdU7OE + version_id: YDTvRlQ + url: https://semgrep.dev/playground/r/YDTvRlQ/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + origin: community + languages: + - c + severity: ERROR +- id: c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + pattern: scanf(...) + message: Avoid using 'scanf()'. This function, when used improperly, does not consider + buffer boundaries and can lead to buffer overflows. Use 'fgets()' instead for + reading input. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - http://sekrit.de/webdocs/c/beginners-guide-away-from-scanf.html + category: security + technology: + - c + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + shortlink: https://sg.run/nd1g + semgrep.dev: + rule: + r_id: 8836 + rv_id: 945173 + rule_id: AbUzPd + version_id: zyTlkWW + url: https://semgrep.dev/playground/r/zyTlkWW/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + origin: community + languages: + - c + severity: WARNING +- id: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + pattern: strtok(...) + message: Avoid using 'strtok()'. This function directly modifies the first argument + buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - https://wiki.sei.cmu.edu/confluence/display/c/STR06-C.+Do+not+assume+that+strtok%28%29+leaves+the+parse+string+unchanged + - https://man7.org/linux/man-pages/man3/strtok.3.html#BUGS + - https://stackoverflow.com/a/40335556 + category: security + technology: + - c + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + shortlink: https://sg.run/LwqG + semgrep.dev: + rule: + r_id: 8839 + rv_id: 1028278 + rule_id: WAUo5v + version_id: qkTx1oq + url: https://semgrep.dev/playground/r/qkTx1oq/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + origin: community + languages: + - c + severity: WARNING +- id: c.lang.security.random-fd-exhaustion.random-fd-exhaustion + pattern-either: + - patterns: + - pattern: | + $FD = open("/dev/urandom", ...); + ... + read($FD, ...); + - pattern-not: | + $FD = open("/dev/urandom", ...); + ... + $BYTES_READ = read($FD, ...); + - patterns: + - pattern: | + $FD = open("/dev/random", ...); + ... + read($FD, ...); + - pattern-not: | + $FD = open("/dev/random", ...); + ... + $BYTES_READ = read($FD, ...); + message: Call to 'read()' without error checking is susceptible to file descriptor + exhaustion. Consider using the 'getrandom()' function. + metadata: + cwe: + - 'CWE-774: Allocation of File Descriptors or Handles Without Limits or Throttling' + references: + - https://lwn.net/Articles/606141/ + category: security + technology: + - c + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + shortlink: https://sg.run/8yNj + semgrep.dev: + rule: + r_id: 8840 + rv_id: 945177 + rule_id: 0oU5k4 + version_id: jQTzvry + url: https://semgrep.dev/playground/r/jQTzvry/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + origin: community + languages: + - c + severity: WARNING +- id: generic.nginx.security.alias-path-traversal.alias-path-traversal + patterns: + - pattern: | + location $...LOCATION { + ... + alias .../; + ... + } + - metavariable-pattern: + metavariable: $...LOCATION + pattern-regex: ^.*[^/]$ + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + fix-regex: + regex: location\s+([A-Za-z0-9/-_\.]+) + replacement: location \1/ + languages: + - generic + severity: WARNING + message: The alias in this location block is subject to a path traversal because + the location path does not end in a path separator (e.g., '/'). To fix, add a + path separator to the end of the path. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md + category: security + technology: + - nginx + confidence: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://www.acunetix.com/vulnerabilities/web/path-traversal-via-misconfigured-nginx-alias/ + - https://www.youtube.com/watch?v=CIhHpkybYsY + - https://github.com/orangetw/My-Presentation-Slides/blob/main/data/2018-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out.pdf + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/generic.nginx.security.alias-path-traversal.alias-path-traversal + shortlink: https://sg.run/ZvNL + semgrep.dev: + rule: + r_id: 9035 + rv_id: 1262670 + rule_id: 5rUOjq + version_id: NdTzyBg + url: https://semgrep.dev/playground/r/NdTzyBg/generic.nginx.security.alias-path-traversal.alias-path-traversal + origin: community +- id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: The host for this proxy URL is dynamically determined. This can be dangerous + if the host can be injected by an attacker because it may forcibly alter destination + of the proxy. Consider hardcoding acceptable destinations and retrieving them + with 'map' or something similar. + metadata: + source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + references: + - https://nginx.org/en/docs/http/ngx_http_map_module.html + category: security + technology: + - nginx + confidence: MEDIUM + cwe: + - 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + shortlink: https://sg.run/ndpb + semgrep.dev: + rule: + r_id: 9036 + rv_id: 1262671 + rule_id: GdU7yl + version_id: kbTzG2j + url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + origin: community + pattern-either: + - pattern: proxy_pass $SCHEME://$$HOST ...; + - pattern: proxy_pass $$SCHEME://$$HOST ...; +- id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: The protocol scheme for this proxy is dynamically determined. This can + be dangerous if the scheme can be injected by an attacker because it may forcibly + alter the connection scheme. Consider hardcoding a scheme for this proxy. + metadata: + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + shortlink: https://sg.run/EkAo + semgrep.dev: + rule: + r_id: 9037 + rv_id: 1262672 + rule_id: ReUg7n + version_id: w8TRoAJ + url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + origin: community + pattern: proxy_pass $$SCHEME:// ...; +- id: generic.nginx.security.header-injection.header-injection + pattern: | + location ... <$VARIABLE> ... { + ... + add_header ... $$VARIABLE + ... + } + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: ERROR + message: 'The $$VARIABLE path parameter is added as a header in the response. This + could allow an attacker to inject a newline and add a new header into the response. + This is called HTTP response splitting. To fix, do not allow whitespace in the + path parameter: ''[^\s]+''.' + metadata: + cwe: + - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP + Request/Response Splitting'')' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md + - https://owasp.org/www-community/attacks/HTTP_Response_Splitting + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection + shortlink: https://sg.run/7oj4 + semgrep.dev: + rule: + r_id: 9038 + rv_id: 1262673 + rule_id: AbUz8p + version_id: xyTjzNW + url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection + origin: community +- id: generic.nginx.security.header-redefinition.header-redefinition + patterns: + - pattern-inside: | + server { + ... + add_header ...; + ... + ... + } + - pattern-inside: | + location ... { + ... + ... + } + - pattern: add_header ...; + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: The 'add_header' directive is called in a 'location' block after headers + have been set at the server block. Calling 'add_header' in the location block + will actually overwrite the headers defined in the server block, no matter which + headers are set. To fix this, explicitly set all headers or set all headers in + the server block. + metadata: + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/addheaderredefinition.md + category: security + technology: + - nginx + confidence: LOW + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/generic.nginx.security.header-redefinition.header-redefinition + shortlink: https://sg.run/Lwl7 + semgrep.dev: + rule: + r_id: 9039 + rv_id: 1262674 + rule_id: BYUN58 + version_id: O9TpxJD + url: https://semgrep.dev/playground/r/O9TpxJD/generic.nginx.security.header-redefinition.header-redefinition + origin: community +- id: generic.nginx.security.insecure-redirect.insecure-redirect + patterns: + - pattern-either: + - pattern: rewrite ... redirect + - pattern: rewrite ... permanent + - pattern-not-inside: rewrite ... https ... $host ... redirect + - pattern-not-inside: rewrite ... https ... $host ... permanent + - pattern-not-regex: (?i)https:\/\/ + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + message: Detected an insecure redirect in this nginx configuration. If no scheme + is specified, nginx will forward the request with the incoming scheme. This could + result in unencrypted communications. To fix this, include the 'https' scheme. + languages: + - generic + severity: WARNING + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - nginx + confidence: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/generic.nginx.security.insecure-redirect.insecure-redirect + shortlink: https://sg.run/8y14 + semgrep.dev: + rule: + r_id: 9040 + rv_id: 1262675 + rule_id: DbUpJe + version_id: e1TyjDz + url: https://semgrep.dev/playground/r/e1TyjDz/generic.nginx.security.insecure-redirect.insecure-redirect + origin: community +- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version + patterns: + - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; + - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; + - pattern-not: ssl_protocols TLSv1.2; + - pattern-not: ssl_protocols TLSv1.3; + - pattern: ssl_protocols ...; + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 + and TLS1.3; older versions are known to be broken and are susceptible to attacks. + Prefer use of TLSv1.2 or later. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ + category: security + technology: + - nginx + confidence: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + shortlink: https://sg.run/gLKy + semgrep.dev: + rule: + r_id: 9041 + rv_id: 1262676 + rule_id: WAUo9k + version_id: vdT06O4 + url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + origin: community +- id: generic.nginx.security.missing-internal.missing-internal + options: + generic_ellipsis_max_span: 0 + generic_engine: aliengrep + patterns: + - pattern-inside: | + location ... { + .... + .... + } + - pattern-not-inside: | + location ... { + .... + internal; + .... + } + - pattern: proxy_pass $...URL; + - metavariable-regex: + metavariable: $...URL + regex: (.*\$.*) + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: This location block contains a 'proxy_pass' directive but does not contain + the 'internal' directive. The 'internal' directive restricts access to this location + to internal requests. Without 'internal', an attacker could use your server for + server-side request forgeries (SSRF). Include the 'internal' directive in this + block to limit exposure. + metadata: + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + - https://nginx.org/en/docs/http/ngx_http_core_module.html#internal + category: security + technology: + - nginx + confidence: LOW + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/generic.nginx.security.missing-internal.missing-internal + shortlink: https://sg.run/Q5px + semgrep.dev: + rule: + r_id: 9042 + rv_id: 1262677 + rule_id: 0oU5BZ + version_id: d6TyxKK + url: https://semgrep.dev/playground/r/d6TyxKK/generic.nginx.security.missing-internal.missing-internal + origin: community +- id: generic.nginx.security.missing-ssl-version.missing-ssl-version + patterns: + - pattern: server { ... listen $PORT ssl; ... } + - pattern-not-inside: server { ... ssl_protocols ... } + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: This server configuration is missing the 'ssl_protocols' directive. By + default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions + older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2 + TLSv1.3' to use secure TLS versions. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://nginx.org/en/docs/http/configuring_https_servers.html + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version + shortlink: https://sg.run/3xzl + semgrep.dev: + rule: + r_id: 9043 + rv_id: 1262678 + rule_id: KxUbeA + version_id: ZRTKAle + url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version + origin: community +- id: generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token + pattern-regex: amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12} + languages: + - regex + message: Amazon MWS Auth Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - aws + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token + shortlink: https://sg.run/PJzE + semgrep.dev: + rule: + r_id: 9045 + rv_id: 1262856 + rule_id: lBU9bw + version_id: K3TKkGj + url: https://semgrep.dev/playground/r/K3TKkGj/generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token + origin: community +- id: generic.secrets.security.detected-artifactory-password.detected-artifactory-password + patterns: + - pattern-regex: (?\bAP[\dABCDEF][a-zA-Z0-9]{8,}) + - pattern-regex: .*(?i)arti[-_]?factory.* + - pattern-not-regex: .*(?i)sha(1|2|3|118|256|512).* + - pattern-not-regex: (?i)-----\s*?BEGIN[ A-Z0-9_-]*? KEY( BLOCK)?-----[\s\S]*?-----\s*?END[ + A-Z0-9_-]*?\s*?----- + - metavariable-analysis: + analyzer: entropy + metavariable: $ITEM + - pattern-not-regex: (\w|\.|\*)\1{4} + languages: + - regex + paths: + exclude: + - '*.svg' + - '*go.sum' + - '*package.json' + - '*cargo.lock' + - '*package-lock.json' + - '*bundle.js' + - '*pnpm-lock*' + - '*Podfile.lock' + - '**/*/openssl/*.h' + - '*.xcscmblueprint' + message: Artifactory token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/artifactory.py + category: security + technology: + - secrets + - artifactory + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-artifactory-password.detected-artifactory-password + shortlink: https://sg.run/J9KZ + semgrep.dev: + rule: + r_id: 9046 + rv_id: 1262857 + rule_id: YGUR5K + version_id: qkTR7BB + url: https://semgrep.dev/playground/r/qkTR7BB/generic.secrets.security.detected-artifactory-password.detected-artifactory-password + origin: community +- id: generic.secrets.security.detected-artifactory-token.detected-artifactory-token + patterns: + - pattern-regex: | + \bAKC[a-zA-Z0-9]{10,} + - pattern-not-regex: | + sha(128|256|512).* + - pattern-not-regex: (?s)---BEGIN.*---\Z + languages: + - regex + paths: + exclude: + - '*.svg' + - '*go.sum' + - '*package.json' + - '*package-lock.json' + - '*bundle.js' + - '*pnpm-lock*' + - '*Podfile.lock' + - '**/*/openssl/*.h' + - '*.xcscmblueprint' + - '*cargo.lock' + message: Artifactory token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/artifactory.py + category: security + technology: + - secrets + - artifactory + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-artifactory-token.detected-artifactory-token + shortlink: https://sg.run/5Q2l + semgrep.dev: + rule: + r_id: 9047 + rv_id: 1262858 + rule_id: 6JUj3l + version_id: l4TJR6J + url: https://semgrep.dev/playground/r/l4TJR6J/generic.secrets.security.detected-artifactory-token.detected-artifactory-token + origin: community +- id: generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value + patterns: + - pattern-regex: \b(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}\b + - pattern-not-regex: (?i)example|sample|test|fake + languages: + - regex + message: AWS Access Key ID Value detected. This is a sensitive credential and should + not be hardcoded here. Instead, read this value from an environment variable or + keep it in a separate, private file. + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - aws + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value + shortlink: https://sg.run/GeD1 + semgrep.dev: + rule: + r_id: 9048 + rv_id: 1262859 + rule_id: oqUevO + version_id: YDTZenE + url: https://semgrep.dev/playground/r/YDTZenE/generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value + origin: community +- id: generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key + pattern-regex: da2-[a-z0-9]{26} + languages: + - regex + message: AWS AppSync GraphQL Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - appsync + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key + shortlink: https://sg.run/AvJ6 + semgrep.dev: + rule: + r_id: 9050 + rv_id: 1262861 + rule_id: pKUOoZ + version_id: o5TbD9o + url: https://semgrep.dev/playground/r/o5TbD9o/generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key + origin: community +- id: generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key + patterns: + - pattern-regex: (("|'|`)?((?i)aws)_?\w*((?i)secret)_?\w*("|'|`)?\s{0,50}(:|=>|=)\s{0,50}("|'|`)?[A-Za-z0-9/+=]{40}("|'|`)?) + - pattern-not-regex: (?i)example|sample|test|fake|xxxxxx + languages: + - regex + message: AWS Secret Access Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - aws + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key + shortlink: https://sg.run/Bk39 + semgrep.dev: + rule: + r_id: 9051 + rv_id: 1262862 + rule_id: 2ZUbe8 + version_id: zyTb2Dr + url: https://semgrep.dev/playground/r/zyTb2Dr/generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key + origin: community +- id: generic.secrets.security.detected-aws-session-token.detected-aws-session-token + patterns: + - pattern-regex: ((?i)AWS_SESSION_TOKEN)\s*(:|=>|=)\s*(?P[A-Za-z0-9/+=]{16,}) + - pattern-not-regex: (?i)example|sample|test|fake + - metavariable-analysis: + analyzer: entropy + metavariable: $TOKEN + languages: + - regex + message: AWS Session Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - aws + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-aws-session-token.detected-aws-session-token + shortlink: https://sg.run/DoRW + semgrep.dev: + rule: + r_id: 9052 + rv_id: 1262863 + rule_id: X5U8Er + version_id: pZT03Lx + url: https://semgrep.dev/playground/r/pZT03Lx/generic.secrets.security.detected-aws-session-token.detected-aws-session-token + origin: community +- id: generic.secrets.security.detected-codeclimate.detected-codeclimate + pattern-regex: (?i)codeclima.{0,50}["|'|`]?[0-9a-f]{64}["|'|`]? + languages: + - regex + message: CodeClimate detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - codeclimate + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-codeclimate.detected-codeclimate + shortlink: https://sg.run/W8yz + semgrep.dev: + rule: + r_id: 9053 + rv_id: 1262865 + rule_id: j2UvW7 + version_id: X0Tzy2o + url: https://semgrep.dev/playground/r/X0Tzy2o/generic.secrets.security.detected-codeclimate.detected-codeclimate + origin: community +- id: generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token + pattern-either: + - pattern-regex: EAACEdEose0cBA[0-9A-Za-z]+ + - pattern-regex: EAAAACZAVC6ygB[0-9A-Za-z]+ + - pattern-regex: EAAAAZAw4[0-9A-Za-z]+ + languages: + - regex + message: Facebook Access Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - facebook + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token + shortlink: https://sg.run/0QYJ + semgrep.dev: + rule: + r_id: 9054 + rv_id: 1262867 + rule_id: 10UKBL + version_id: 1QTyp7J + url: https://semgrep.dev/playground/r/1QTyp7J/generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token + origin: community +- id: generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth + pattern-regex: '[fF][aA][cC][eE][bB][oO][oO][kK].*[tT][oO][kK][eE][nN].*[''|"]?[0-9a-f]{32}[''|"]?' + languages: + - regex + message: Facebook OAuth detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - facebook + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth + shortlink: https://sg.run/Klq6 + semgrep.dev: + rule: + r_id: 9055 + rv_id: 1262868 + rule_id: 9AU127 + version_id: 9lT4b5N + url: https://semgrep.dev/playground/r/9lT4b5N/generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth + origin: community +- id: generic.secrets.security.detected-generic-api-key.detected-generic-api-key + patterns: + - pattern-regex: '[aA][pP][iI]_?[kK][eE][yY][=_:\s-]+[''|"]?(?[0-9a-zA-Z]{32,45})[''|"]?' + - metavariable-analysis: + analyzer: entropy + metavariable: $SECRET + languages: + - regex + message: Generic API Key detected + severity: ERROR + metadata: + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + confidence: LOW + references: + - https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-generic-api-key.detected-generic-api-key + shortlink: https://sg.run/qxj8 + semgrep.dev: + rule: + r_id: 9056 + rv_id: 1262869 + rule_id: yyUn8p + version_id: yeTxpZ9 + url: https://semgrep.dev/playground/r/yeTxpZ9/generic.secrets.security.detected-generic-api-key.detected-generic-api-key + origin: community +- id: generic.secrets.security.detected-generic-secret.detected-generic-secret + patterns: + - pattern-regex: '[sS][eE][cC][rR][eE][tT][:= \t]*[''|\"]?(?[0-9a-zA-Z]{32,45})[''|\"]?' + - metavariable-analysis: + analyzer: entropy + metavariable: $SECRET + languages: + - regex + message: Generic Secret detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-generic-secret.detected-generic-secret + shortlink: https://sg.run/l2o5 + semgrep.dev: + rule: + r_id: 9057 + rv_id: 1262870 + rule_id: r6Urqe + version_id: rxTAK4J + url: https://semgrep.dev/playground/r/rxTAK4J/generic.secrets.security.detected-generic-secret.detected-generic-secret + origin: community +- id: generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token + pattern-regex: ya29\.[0-9A-Za-z\-_]+ + languages: + - regex + message: Google OAuth Access Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - google + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token + shortlink: https://sg.run/ox2n + semgrep.dev: + rule: + r_id: 9060 + rv_id: 1262875 + rule_id: kxUkpo + version_id: xyTjzp6 + url: https://semgrep.dev/playground/r/xyTjzp6/generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token + origin: community +- id: generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key + pattern-regex: '[hH][eE][rR][oO][kK][uU].*[0-9A-Fa-f]{8}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{12}' + languages: + - regex + message: Heroku API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - heroku + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key + shortlink: https://sg.run/pxXR + semgrep.dev: + rule: + r_id: 9062 + rv_id: 1262877 + rule_id: x8UnOB + version_id: e1Tyj3N + url: https://semgrep.dev/playground/r/e1Tyj3N/generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key + origin: community +- id: generic.secrets.security.detected-hockeyapp.detected-hockeyapp + pattern-regex: (?i)hockey.{0,50}(\\\"|'|`)?[0-9a-f]{32}(\\\"|'|`)? + languages: + - regex + message: HockeyApp detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - hockeyapp + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-hockeyapp.detected-hockeyapp + shortlink: https://sg.run/2xoY + semgrep.dev: + rule: + r_id: 9063 + rv_id: 1262878 + rule_id: OrU3zo + version_id: vdT068z + url: https://semgrep.dev/playground/r/vdT068z/generic.secrets.security.detected-hockeyapp.detected-hockeyapp + origin: community +- id: generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key + pattern-regex: '[0-9a-f]{32}-us[0-9]{1,2}' + languages: + - regex + message: MailChimp API Key detected + severity: ERROR + metadata: + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + technology: + - secrets + - mailchimp + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key + shortlink: https://sg.run/XBde + semgrep.dev: + rule: + r_id: 9064 + rv_id: 1262881 + rule_id: eqU8QR + version_id: nWT2LoR + url: https://semgrep.dev/playground/r/nWT2LoR/generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key + origin: community +- id: generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key + pattern-regex: key-[0-9a-zA-Z]{32} + languages: + - regex + message: Mailgun API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - mailgun + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key + shortlink: https://sg.run/jRL2 + semgrep.dev: + rule: + r_id: 9065 + rv_id: 1262882 + rule_id: v8UneY + version_id: ExTExAG + url: https://semgrep.dev/playground/r/ExTExAG/generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key + origin: community +- id: generic.secrets.security.detected-outlook-team.detected-outlook-team + pattern-regex: https://outlook\.office\.com/webhook/[0-9a-f-]{36} + languages: + - regex + message: Outlook Team detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - outlook + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-outlook-team.detected-outlook-team + shortlink: https://sg.run/1ZwQ + semgrep.dev: + rule: + r_id: 9066 + rv_id: 1262884 + rule_id: d8UjXq + version_id: LjTkgA1 + url: https://semgrep.dev/playground/r/LjTkgA1/generic.secrets.security.detected-outlook-team.detected-outlook-team + origin: community +- id: generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token + pattern-regex: access_token\$production\$[0-9a-z]{16}\$[0-9a-z]{32} + languages: + - regex + message: PayPal Braintree Access Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - paypal + - braintree + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token + shortlink: https://sg.run/9oBR + semgrep.dev: + rule: + r_id: 9067 + rv_id: 1262885 + rule_id: ZqU507 + version_id: 8KT5ryb + url: https://semgrep.dev/playground/r/8KT5ryb/generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token + origin: community +- id: generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block + pattern-regex: '-----BEGIN PGP PRIVATE KEY BLOCK-----' + languages: + - regex + message: Something that looks like a PGP private key block is detected. This is + a potential hardcoded secret that could be leaked if this code is committed. Instead, + remove this code block from the commit. + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block + shortlink: https://sg.run/ydKd + semgrep.dev: + rule: + r_id: 9068 + rv_id: 1262886 + rule_id: nJUzXz + version_id: gETB7O4 + url: https://semgrep.dev/playground/r/gETB7O4/generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block + origin: community +- id: generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key + pattern-regex: sk_live_[0-9a-z]{32} + languages: + - regex + message: Picatic API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - picatic + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key + shortlink: https://sg.run/rdGA + semgrep.dev: + rule: + r_id: 9069 + rv_id: 1262887 + rule_id: EwU274 + version_id: QkTGqwK + url: https://semgrep.dev/playground/r/QkTGqwK/generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key + origin: community +- id: generic.secrets.security.detected-private-key.detected-private-key + patterns: + - pattern-either: + - patterns: + - pattern: '-----BEGIN $TYPE PRIVATE KEY----- $KEY' + - metavariable-regex: + metavariable: $TYPE + regex: (?i)([dr]sa|ec|openssh|encrypted)? + - patterns: + - pattern: | + -----BEGIN PRIVATE KEY----- + $KEY + - metavariable-analysis: + metavariable: $KEY + analyzer: entropy + languages: + - generic + message: Private Key detected. This is a sensitive credential and should not be + hardcoded here. Instead, store this in a separate, private file. + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key + shortlink: https://sg.run/b7dr + semgrep.dev: + rule: + r_id: 9070 + rv_id: 1262888 + rule_id: 7KUQ0p + version_id: 3ZT4X4Y + url: https://semgrep.dev/playground/r/3ZT4X4Y/generic.secrets.security.detected-private-key.detected-private-key + origin: community +- id: generic.secrets.security.detected-sauce-token.detected-sauce-token + pattern-regex: (?i)sauce.{0,50}(\\\"|'|`)?[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[0-9a-f]{4}-[0-9a-f]{12}(\\\"|'|`)? + languages: + - regex + message: Sauce Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - sauce + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-sauce-token.detected-sauce-token + shortlink: https://sg.run/N4k1 + semgrep.dev: + rule: + r_id: 9071 + rv_id: 1262889 + rule_id: L1UyZ5 + version_id: 44TEjER + url: https://semgrep.dev/playground/r/44TEjER/generic.secrets.security.detected-sauce-token.detected-sauce-token + origin: community +- id: generic.secrets.security.detected-slack-token.detected-slack-token + pattern-either: + - pattern-regex: (xox[pboa]-[0-9]{12}-[0-9]{12}-[0-9]{12}-[a-z0-9]{32}) + - pattern-regex: xox.-[0-9]{12}-[0-9]{12}-[0-9a-zA-Z]{24} + languages: + - regex + message: Slack Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + references: + - https://github.com/davidburkitt/python-secret-scanner/blob/335a1f6dab8de59cf39063e57aea39a58951e939/patterns.txt#L58 + category: security + technology: + - secrets + - slack + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-slack-token.detected-slack-token + shortlink: https://sg.run/kXdz + semgrep.dev: + rule: + r_id: 9072 + rv_id: 1262891 + rule_id: 8GUjRA + version_id: JdTzxz3 + url: https://semgrep.dev/playground/r/JdTzxz3/generic.secrets.security.detected-slack-token.detected-slack-token + origin: community +- id: generic.secrets.security.detected-slack-webhook.detected-slack-webhook + patterns: + - pattern-regex: https://hooks\.slack\.com/services/T[a-zA-Z0-9_]{8,10}/B[a-zA-Z0-9_]{8,10}/[a-zA-Z0-9_]{24} + - pattern-not: https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX + languages: + - regex + message: Slack Webhook detected + severity: ERROR + metadata: + references: + - https://api.slack.com/messaging/webhooks + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - slack + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-slack-webhook.detected-slack-webhook + shortlink: https://sg.run/weWX + semgrep.dev: + rule: + r_id: 9073 + rv_id: 1262892 + rule_id: gxU1dy + version_id: 5PTo1oO + url: https://semgrep.dev/playground/r/5PTo1oO/generic.secrets.security.detected-slack-webhook.detected-slack-webhook + origin: community +- id: generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key + pattern-regex: (?i)sonar.{0,50}(\\\"|'|`)?[0-9a-f]{40}(\\\"|'|`)? + languages: + - regex + message: SonarQube Docs API Key detected + severity: ERROR + paths: + exclude: + - '*.svg' + - '*go.sum' + - '*cargo.lock' + - '*package.json' + - '*yarn.lock' + - '*package-lock.json' + - '*bundle.js' + - '*pnpm-lock*' + - '*Podfile.lock' + - '**/*/openssl/*.h' + - '*.xcscmblueprint' + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - sonarqube + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key + shortlink: https://sg.run/x10P + semgrep.dev: + rule: + r_id: 9074 + rv_id: 1262895 + rule_id: QrUzP1 + version_id: A8TgdgQ + url: https://semgrep.dev/playground/r/A8TgdgQ/generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key + origin: community +- id: generic.secrets.security.detected-square-access-token.detected-square-access-token + pattern-regex: sq0atp-[0-9A-Za-z\-_]{22} + languages: + - regex + message: Square Access Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - square + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-square-access-token.detected-square-access-token + shortlink: https://sg.run/OP3b + semgrep.dev: + rule: + r_id: 9075 + rv_id: 1262896 + rule_id: 3qUPqO + version_id: BjTkZkz + url: https://semgrep.dev/playground/r/BjTkZkz/generic.secrets.security.detected-square-access-token.detected-square-access-token + origin: community +- id: generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret + pattern-regex: sq0csp-[0-9A-Za-z\\\-_]{43} + languages: + - regex + message: Square OAuth Secret detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + references: + - https://github.com/Yelp/detect-secrets/blob/master/tests/plugins/square_oauth_test.py + category: security + technology: + - secrets + - square + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret + shortlink: https://sg.run/eL7E + semgrep.dev: + rule: + r_id: 9076 + rv_id: 1262897 + rule_id: 4bUk4l + version_id: DkTRbRG + url: https://semgrep.dev/playground/r/DkTRbRG/generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret + origin: community +- id: generic.secrets.security.detected-ssh-password.detected-ssh-password + pattern-regex: sshpass -p\s*['|\\\"][^%] + languages: + - regex + message: SSH Password detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + - ssh + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-ssh-password.detected-ssh-password + shortlink: https://sg.run/vzDR + semgrep.dev: + rule: + r_id: 9077 + rv_id: 1262898 + rule_id: PeUZ4d + version_id: WrTqKqY + url: https://semgrep.dev/playground/r/WrTqKqY/generic.secrets.security.detected-ssh-password.detected-ssh-password + origin: community +- id: generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key + pattern-regex: sk_live_[0-9a-zA-Z]{24} + languages: + - regex + message: Stripe API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - stripe + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key + shortlink: https://sg.run/dKd5 + semgrep.dev: + rule: + r_id: 9078 + rv_id: 1262899 + rule_id: JDUy0z + version_id: 0bTKzK1 + url: https://semgrep.dev/playground/r/0bTKzK1/generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key + origin: community +- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + pattern-regex: rk_live_[0-9a-zA-Z]{24} + languages: + - regex + message: Stripe Restricted API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - stripe + confidence: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + shortlink: https://sg.run/ZvdL + semgrep.dev: + rule: + r_id: 9079 + rv_id: 1262900 + rule_id: 5rUOWq + version_id: K3TKkKj + url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + origin: community +- id: generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key + patterns: + - pattern-regex: '[0-9]+:AA[0-9A-Za-z\-_]{33}' + - pattern-not-regex: go\.mod.* + - pattern-not-regex: v[\d]+\.[\d]+\.[\d]+.* + languages: + - regex + message: Telegram Bot API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - telegram + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key + shortlink: https://sg.run/nd4b + semgrep.dev: + rule: + r_id: 9080 + rv_id: 1262901 + rule_id: GdU7Nl + version_id: qkTR7RB + url: https://semgrep.dev/playground/r/qkTR7RB/generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key + origin: community +- id: generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key + pattern-regex: SK[0-9a-fA-F]{32} + languages: + - regex + message: Twilio API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - twilio + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key + shortlink: https://sg.run/Ek2o + semgrep.dev: + rule: + r_id: 9081 + rv_id: 1262902 + rule_id: ReUgJn + version_id: l4TJRJJ + url: https://semgrep.dev/playground/r/l4TJRJJ/generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key + origin: community +- id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + patterns: + - pattern-not-inside: | + &sessions.Options{ + ..., + HttpOnly: true, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: A session cookie was detected without setting the 'HttpOnly' flag. The + 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts + from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by + setting 'HttpOnly' to 'true' in the Options struct. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + shortlink: https://sg.run/4xJZ + semgrep.dev: + rule: + r_id: 9088 + rv_id: 1262911 + rule_id: qNUj6g + version_id: WrTqKqe + url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + origin: community + fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + patterns: + - pattern-not-inside: | + &sessions.Options{ + ..., + Secure: true, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' + flag for cookies prevents the client from transmitting the cookie over insecure + channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in + the Options struct. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + shortlink: https://sg.run/PJdE + semgrep.dev: + rule: + r_id: 9089 + rv_id: 1262912 + rule_id: lBU9kw + version_id: 0bTKzKk + url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + origin: community + fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + shortlink: https://sg.run/J9yZ + semgrep.dev: + rule: + r_id: 9090 + rv_id: 1262916 + rule_id: PeUZ4X + version_id: YDTZeZB + url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + origin: community + message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This + creates a connection without encryption to a gRPC server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Instead, + establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' + function. You can create a create credentials using a ''tls.Config{}'' struct + with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' + languages: + - go + severity: ERROR + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + shortlink: https://sg.run/5Q5l + semgrep.dev: + rule: + r_id: 9091 + rv_id: 1262917 + rule_id: JDUy0B + version_id: 6xT2923 + url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + origin: community + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. + This allows for a connection without encryption to this server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Include + credentials derived from an SSL certificate in order to create a secure gRPC connection. + You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", + "cert.key")'. + languages: + - go + severity: ERROR + mode: taint + pattern-sinks: + - requires: OPTIONS and not CREDS + pattern: grpc.NewServer($OPT, ...) + - requires: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() +- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + shortlink: https://sg.run/Gej1 + semgrep.dev: + rule: + r_id: 9092 + rv_id: 1262919 + rule_id: 5rUOWQ + version_id: zyTb2bz + url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + origin: community + languages: + - go + severity: ERROR + patterns: + - pattern-either: + - pattern-inside: | + import "github.com/golang-jwt/jwt" + ... + - pattern-inside: | + import "github.com/dgrijalva/jwt-go" + ... + - pattern-either: + - pattern: | + jwt.SigningMethodNone + - pattern: jwt.UnsafeAllowNoneSignatureType +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - jwt + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + shortlink: https://sg.run/Rod2 + semgrep.dev: + rule: + r_id: 9093 + rv_id: 1262920 + rule_id: GdU7Ny + version_id: pZT0305 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + origin: community + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + []byte("$F") + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $TOKEN.SignedString($F) + - focus-metavariable: $F +- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` + unless you know what you're doing This method parses the token but doesn't validate + the signature. It's only ever useful in cases where you know the signature is + valid (because it has been checked previously in the stack) and you want to extract + values from it. + metadata: + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: MEDIUM + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + shortlink: https://sg.run/Av66 + semgrep.dev: + rule: + r_id: 9094 + rv_id: 1262918 + rule_id: ReUgJJ + version_id: o5TbDbq + url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-inside: | + import "github.com/dgrijalva/jwt-go" + ... + - pattern: | + $JWT.ParseUnverified(...) +- id: go.lang.security.bad_tmp.bad-tmp-file-creation + message: File creation in shared tmp directory without using `io.CreateTemp`. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-377: Insecure Temporary File' + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://pkg.go.dev/io/ioutil#TempFile + - https://pkg.go.dev/os#CreateTemp + - https://github.com/securego/gosec/blob/5fd2a370447223541cddb35da8d1bc707b7bb153/rules/tempfiles.go#L67 + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.lang.security.bad_tmp.bad-tmp-file-creation + shortlink: https://sg.run/Gejn + semgrep.dev: + rule: + r_id: 9104 + rv_id: 1262965 + rule_id: 6JUjnL + version_id: 2KTv2pJ + url: https://semgrep.dev/playground/r/2KTv2pJ/go.lang.security.bad_tmp.bad-tmp-file-creation + origin: community + pattern-either: + - pattern: ioutil.WriteFile("=~//tmp/.*$/", ...) + - pattern: os.Create("=~//tmp/.*$/", ...) + - pattern: os.WriteFile("=~//tmp/.*$/", ...) +- id: go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + message: 'Detected a possible denial-of-service via a zip bomb attack. By limiting + the max bytes read, you can mitigate this attack. `io.CopyN()` can specify a size. ' + severity: WARNING + languages: + - go + patterns: + - pattern-either: + - pattern: io.Copy(...) + - pattern: io.CopyBuffer(...) + - pattern-either: + - pattern-inside: | + gzip.NewReader(...) + ... + - pattern-inside: | + zlib.NewReader(...) + ... + - pattern-inside: | + zlib.NewReaderDict(...) + ... + - pattern-inside: | + bzip2.NewReader(...) + ... + - pattern-inside: | + flate.NewReader(...) + ... + - pattern-inside: | + flate.NewReaderDict(...) + ... + - pattern-inside: | + lzw.NewReader(...) + ... + - pattern-inside: | + tar.NewReader(...) + ... + - pattern-inside: | + zip.NewReader(...) + ... + - pattern-inside: | + zip.OpenReader(...) + ... + fix-regex: + regex: (.*)(Copy|CopyBuffer)\((.*?),(.*?)(\)|,.*\)) + replacement: \1CopyN(\3, \4, 1024*1024*256) + metadata: + cwe: + - 'CWE-400: Uncontrolled Resource Consumption' + source-rule-url: https://github.com/securego/gosec + references: + - https://golang.org/pkg/io/#CopyN + - https://github.com/securego/gosec/blob/master/rules/decompression-bomb.go + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + shortlink: https://sg.run/RodK + semgrep.dev: + rule: + r_id: 9105 + rv_id: 945606 + rule_id: oqUeqn + version_id: JdTDye5 + url: https://semgrep.dev/playground/r/JdTDye5/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + origin: community +- id: go.lang.security.zip.path-traversal-inside-zip-extraction + message: File traversal when extracting zip archive + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source_rule_url: https://github.com/securego/gosec/issues/205 + category: security + technology: + - go + confidence: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/go.lang.security.zip.path-traversal-inside-zip-extraction + shortlink: https://sg.run/Av64 + semgrep.dev: + rule: + r_id: 9106 + rv_id: 1262971 + rule_id: zdUkoR + version_id: rxTAK1Z + url: https://semgrep.dev/playground/r/rxTAK1Z/go.lang.security.zip.path-traversal-inside-zip-extraction + origin: community + languages: + - go + severity: WARNING + pattern: | + reader, $ERR := zip.OpenReader($ARCHIVE) + ... + for _, $FILE := range reader.File { + ... + path := filepath.Join($TARGET, $FILE.Name) + ... + } +- id: go.lang.security.audit.dangerous-command-write.dangerous-command-write + patterns: + - pattern: | + $CW.Write($BYTE) + - pattern-inside: | + $CW,$ERR := $CMD.StdinPipe() + ... + - pattern-not: | + $CW.Write("...") + - pattern-not: | + $CW.Write([]byte("...")) + - pattern-not: | + $CW.Write([]byte("..."+"...")) + - pattern-not-inside: | + $BYTE = []byte("..."); + ... + - pattern-not-inside: | + $BYTE = []byte("..."+"..."); + ... + - pattern-inside: | + import "os/exec" + ... + message: Detected non-static command inside Write. Audit the input to '$CW.Write'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + severity: ERROR + languages: + - go + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + category: security + technology: + - go + confidence: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-command-write.dangerous-command-write + shortlink: https://sg.run/Bko5 + semgrep.dev: + rule: + r_id: 9107 + rv_id: 1262933 + rule_id: pKUOZ9 + version_id: O9Tpx8N + url: https://semgrep.dev/playground/r/O9Tpx8N/go.lang.security.audit.dangerous-command-write.dangerous-command-write + origin: community +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + patterns: + - pattern-either: + - patterns: + - pattern: | + exec.Cmd {...,Path: $CMD,...} + - pattern-not: | + exec.Cmd {...,Path: "...",...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: $ARGS,...} + - pattern-not: | + exec.Cmd {...,Args: []string{...},...} + - pattern-not-inside: | + $ARGS = []string{"...",...}; + ... + - pattern-not-inside: | + $CMD = "..."; + ... + $ARGS = []string{$CMD,...}; + ... + - pattern-not-inside: | + $CMD = exec.LookPath("..."); + ... + $ARGS = []string{$CMD,...}; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,...},...} + - pattern-not: | + exec.Cmd {...,Args: []string{"...",...},...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern-either: + - pattern: | + exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...} + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...} + - pattern-inside: | + $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); + ... + - pattern-not: | + exec.Cmd {...,Args: []string{"...","...","...",...},...} + - pattern-not-inside: | + $EXE = "..."; + ... + - pattern-inside: | + import "os/exec" + ... + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + shortlink: https://sg.run/Dorj + semgrep.dev: + rule: + r_id: 9108 + rv_id: 1262934 + rule_id: 2ZUb8l + version_id: e1Tyjeg + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + origin: community + severity: ERROR + languages: + - go +- id: go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + exec.Command($CMD,...) + - pattern: | + exec.CommandContext($CTX,$CMD,...) + - pattern-not: | + exec.Command("...",...) + - pattern-not: | + exec.CommandContext($CTX,"...",...) + - patterns: + - pattern-either: + - pattern: | + exec.Command("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) + - pattern: | + exec.CommandContext($CTX,"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) + - pattern-not: | + exec.Command("...","...","...",...) + - pattern-not: | + exec.CommandContext($CTX,"...","...","...",...) + - pattern-either: + - pattern: | + exec.Command("=~/\/bin\/env/","=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) + - pattern: | + exec.CommandContext($CTX,"=~/\/bin\/env/","=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) + - pattern-inside: | + import "os/exec" + ... + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + message: Detected non-static command inside Command. Audit the input to 'exec.Command'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + shortlink: https://sg.run/W8lA + semgrep.dev: + rule: + r_id: 9109 + rv_id: 1262935 + rule_id: X5U8RQ + version_id: vdT06Xp + url: https://semgrep.dev/playground/r/vdT06Xp/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + origin: community + severity: ERROR + languages: + - go +- id: go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + patterns: + - pattern-either: + - patterns: + - pattern: | + syscall.$METHOD($BIN,...) + - pattern-not: | + syscall.$METHOD("...",...) + - pattern-not-inside: | + $BIN,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $BIN = "..."; + ... + - patterns: + - pattern: | + syscall.$METHOD($BIN,$ARGS,...) + - pattern-not: | + syscall.$METHOD($BIN,[]string{"...",...},...) + - pattern-not-inside: | + $ARGS := []string{"...",...}; + ... + - pattern-not-inside: | + $CMD = "..."; + ... + $ARGS = []string{$CMD,...}; + ... + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + $ARGS = []string{$CMD,...}; + ... + - patterns: + - pattern: | + syscall.$METHOD($BIN,[]string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...) + - pattern-not: | + syscall.$METHOD($BIN,[]string{"...","...","...",...},...) + - patterns: + - pattern: | + syscall.$METHOD($BIN,$ARGS,...) + - pattern-either: + - pattern-inside: | + $ARGS := []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...}; + ... + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; + ... + $ARGS = []string{$CMD,"-c",$EXE,...}; + ... + - pattern-inside: | + $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); + ... + $ARGS = []string{$CMD,"-c",$EXE,...}; + ... + - pattern-not-inside: | + $ARGS := []string{"...","...","...",...}; + ... + - pattern-not-inside: | + $CMD = "..."; + ... + $ARGS = []string{$CMD,"...","...",...}; + ... + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + $ARGS = []string{$CMD,"...","...",...}; + ... + - pattern-inside: | + import "syscall" + ... + - metavariable-regex: + metavariable: $METHOD + regex: (Exec|ForkExec) + message: Detected non-static command inside Exec. Audit the input to 'syscall.Exec'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + shortlink: https://sg.run/0QRb + semgrep.dev: + rule: + r_id: 9110 + rv_id: 1262936 + rule_id: j2UvPl + version_id: d6Tyx3j + url: https://semgrep.dev/playground/r/d6Tyx3j/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + origin: community + severity: ERROR + languages: + - go +- id: go.lang.security.audit.reflect-makefunc.reflect-makefunc + message: '''reflect.MakeFunc'' detected. This will sidestep protections that are + normally afforded by Go''s type system. Audit this call and be sure that user + input cannot be used to affect the code generated by MakeFunc; otherwise, you + will have a serious security vulnerability.' + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.reflect-makefunc.reflect-makefunc + shortlink: https://sg.run/KlPd + semgrep.dev: + rule: + r_id: 9111 + rv_id: 1262950 + rule_id: 10UKGb + version_id: GxTkeqB + url: https://semgrep.dev/playground/r/GxTkeqB/go.lang.security.audit.reflect-makefunc.reflect-makefunc + origin: community + severity: ERROR + pattern: reflect.MakeFunc(...) + languages: + - go +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + message: The package `net/http/cgi` is on the import blocklist. The package is + vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http` + or a web framework to build a web application instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec + references: + - https://godoc.org/golang.org/x/crypto/sha3 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + shortlink: https://sg.run/l2gj + semgrep.dev: + rule: + r_id: 9113 + rv_id: 1262921 + rule_id: yyUnov + version_id: 2KTv2vJ + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + origin: community + languages: + - go + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import "net/http/cgi" + ... + - pattern: | + cgi.$FUNC(...) +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + message: Disabled host key verification detected. This allows man-in-the-middle + attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. + See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to + learn more about the problem and how to fix it. + metadata: + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + shortlink: https://sg.run/Yv6X + semgrep.dev: + rule: + r_id: 9114 + rv_id: 1262922 + rule_id: r6UrW9 + version_id: X0TzyzN + url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + origin: community + languages: + - go + severity: WARNING + pattern: ssh.InsecureIgnoreHostKey() +- id: go.lang.security.audit.crypto.math_random.math-random-used + metadata: + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + shortlink: https://sg.run/6nK6 + semgrep.dev: + rule: + r_id: 9115 + rv_id: 1262923 + rule_id: bwUwy8 + version_id: jQTn5nj + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + origin: community + message: Do not use `math/rand`. Use `crypto/rand` instead. + languages: + - go + severity: WARNING + patterns: + - pattern-either: + - pattern: | + import $RAND "$MATH" + - pattern: | + import "$MATH" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: | + ... + rand.$FUNC(...) + - pattern-inside: | + ... + $RAND.$FUNC(...) + - focus-metavariable: + - $MATH + fix: | + crypto/rand +- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + message: '`MinVersion` is missing from this TLS configuration. By default, as of + Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications + should default to TLS 1.3 with all other protocols disabled. Only where it is + known that a web server must support legacy clients with unsupported an insecure + browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 + to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration + to bump the minimum version to TLS 1.3.' + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + shortlink: https://sg.run/oxEN + semgrep.dev: + rule: + r_id: 9116 + rv_id: 1262924 + rule_id: NbUk4X + version_id: 1QTypyp + url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern: | + tls.Config{ $...CONF } + - pattern-not: | + tls.Config{..., MinVersion: ..., ...} + fix: | + tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 } +- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, + SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + shortlink: https://sg.run/zvE1 + semgrep.dev: + rule: + r_id: 9117 + rv_id: 1262926 + rule_id: kxUkJ2 + version_id: yeTxpxj + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + origin: community + languages: + - go + severity: WARNING + fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered + weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. + See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other + cipher suites to use. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: HIGH + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + shortlink: https://sg.run/px8N + semgrep.dev: + rule: + r_id: 9118 + rv_id: 1262927 + rule_id: wdUJYk + version_id: rxTAKAZ + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + shortlink: https://sg.run/2xB5 + semgrep.dev: + rule: + r_id: 9119 + rv_id: 1262928 + rule_id: x8Un6q + version_id: bZT535Y + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + origin: community + patterns: + - pattern-inside: | + import "crypto/md5" + ... + - pattern-either: + - pattern: | + md5.New() + - pattern: | + md5.Sum(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + shortlink: https://sg.run/XBYA + semgrep.dev: + rule: + r_id: 9120 + rv_id: 1262929 + rule_id: OrU31O + version_id: NdTzyz1 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + origin: community + patterns: + - pattern-inside: | + import "crypto/sha1" + ... + - pattern-either: + - pattern: | + sha1.New() + - pattern: | + sha1.Sum(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + message: Detected DES cipher algorithm which is insecure. The algorithm is considered + weak and has been deprecated. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + shortlink: https://sg.run/jREA + semgrep.dev: + rule: + r_id: 9121 + rv_id: 1262930 + rule_id: eqU8B3 + version_id: kbTzGzA + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + origin: community + patterns: + - pattern-inside: | + import "crypto/des" + ... + - pattern-either: + - pattern: | + des.NewTripleDESCipher(...) + - pattern: | + des.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many + known vulnerabilities. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + shortlink: https://sg.run/1ZAD + semgrep.dev: + rule: + r_id: 9122 + rv_id: 1262931 + rule_id: v8Unl0 + version_id: w8TRoRQ + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + origin: community + patterns: + - pattern-inside: | + import "crypto/rc4" + ... + - pattern: rc4.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + shortlink: https://sg.run/9oY4 + semgrep.dev: + rule: + r_id: 9123 + rv_id: 1262932 + rule_id: d8UjY3 + version_id: xyTjz8L + url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + rsa.GenerateKey(..., $BITS) + - pattern: | + rsa.GenerateMultiPrimeKey(..., $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 + - focus-metavariable: + - $BITS + fix: | + 2048 +- id: go.lang.security.audit.database.string-formatted-query.string-formatted-query + languages: + - go + message: String-formatted SQL query detected. This could lead to SQL injection if + the string is not sanitized properly. Audit this call to ensure the SQL is not + manipulable by external data. + severity: WARNING + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.database.string-formatted-query.string-formatted-query + shortlink: https://sg.run/ydEr + semgrep.dev: + rule: + r_id: 9124 + rv_id: 1262937 + rule_id: ZqU5bD + version_id: ZRTKA2q + url: https://semgrep.dev/playground/r/ZRTKA2q/go.lang.security.audit.database.string-formatted-query.string-formatted-query + origin: community + patterns: + - metavariable-regex: + metavariable: $OBJ + regex: (?i).*(db|database) + - pattern-not-inside: | + $VAR = "..." + "..." + ... + $OBJ.$SINK(..., $VAR, ...) + - pattern-not: $OBJ.Exec("...") + - pattern-not: $OBJ.ExecContext($CTX, "...") + - pattern-not: $OBJ.Query("...") + - pattern-not: $OBJ.QueryContext($CTX, "...") + - pattern-not: $OBJ.QueryRow("...") + - pattern-not: $OBJ.QueryRow($CTX, "...") + - pattern-not: $OBJ.QueryRowContext($CTX, "...") + - pattern-either: + - pattern: $OBJ.Exec($X + ...) + - pattern: $OBJ.ExecContext($CTX, $X + ...) + - pattern: $OBJ.Query($X + ...) + - pattern: $OBJ.QueryContext($CTX, $X + ...) + - pattern: $OBJ.QueryRow($X + ...) + - pattern: $OBJ.QueryRow($CTX, $X + ...) + - pattern: $OBJ.QueryRowContext($CTX, $X + ...) + - pattern: $OBJ.Exec(fmt.$P("...", ...)) + - pattern: $OBJ.ExecContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.Query(fmt.$P("...", ...)) + - pattern: $OBJ.QueryContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow(fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow($CTX, fmt.$U("...", ...)) + - pattern: $OBJ.QueryRowContext($CTX, fmt.$P("...", ...)) + - patterns: + - pattern-either: + - pattern: $QUERY = fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: $QUERY = fmt.Sprintf("$SQLSTR", ...) + - pattern: $QUERY = fmt.Printf("$SQLSTR", ...) + - pattern: $QUERY = $X + ... + - pattern-either: + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.Query($QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.ExecContext($CTX, $QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.Exec($QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRow($CTX, $QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRow($QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryContext($CTX, $QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRowContext($CTX, $QUERY, ...) + ... + } +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + message: Detected a network listener listening on 0.0.0.0 or an empty string. This + could unexpectedly expose the server publicly as it binds to all available interfaces. + Instead, specify another IP address that is not 0.0.0.0 nor the empty string. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: HIGH + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdE0 + semgrep.dev: + rule: + r_id: 9125 + rv_id: 1262939 + rule_id: nJUz3J + version_id: ExTExoK + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + origin: community + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) +- id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + patterns: + - pattern-not-inside: | + http.Cookie{ + ..., + HttpOnly: true, + ..., + } + - pattern: | + http.Cookie{ + ..., + } + message: A session cookie was detected without setting the 'HttpOnly' flag. The + 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts + from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by + setting 'HttpOnly' to 'true' in the Cookie. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + shortlink: https://sg.run/b73e + semgrep.dev: + rule: + r_id: 9126 + rv_id: 1262940 + rule_id: EwU2Z6 + version_id: 7ZTE3BW + url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + origin: community + fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + patterns: + - pattern-not-inside: | + http.Cookie{ + ..., + Secure: true, + ..., + } + - pattern: | + http.Cookie{ + ..., + } + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' + flag for cookies prevents the client from transmitting the cookie over insecure + channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in + the Options struct. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + shortlink: https://sg.run/N4G7 + semgrep.dev: + rule: + r_id: 9127 + rv_id: 1262941 + rule_id: 7KUQ8X + version_id: LjTkgGE + url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + origin: community + fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep + could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous + because they deserialize function code to run when certain Request events occur, + which could lead to code being run without your knowledge. Ensure that your ClientTrace + is statically defined. + metadata: + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + shortlink: https://sg.run/kXEK + semgrep.dev: + rule: + r_id: 9128 + rv_id: 1262942 + rule_id: L1Uyjp + version_id: 8KT5rNv + url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + origin: community + patterns: + - pattern-not-inside: | + package $PACKAGE + ... + &httptrace.ClientTrace { ... } + ... + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. If user data can reach this template, you may have a XSS vulnerability. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + category: security + technology: + - go + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + shortlink: https://sg.run/weE0 + semgrep.dev: + rule: + r_id: 9129 + rv_id: 1262943 + rule_id: 8GUjDW + version_id: gETB7Pe + url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTML($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTML($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTML($OTHER, ...) +- id: go.lang.security.audit.net.pprof.pprof-debug-exposure + metadata: + cwe: + - 'CWE-489: Active Debug Code' + owasp: A06:2017 - Security Misconfiguration + source-rule-url: https://github.com/securego/gosec#available-rules + references: + - https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ + category: security + technology: + - go + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/go.lang.security.audit.net.pprof.pprof-debug-exposure + shortlink: https://sg.run/x1Ep + semgrep.dev: + rule: + r_id: 9130 + rv_id: 945583 + rule_id: gxU1Kp + version_id: 9lTy168 + url: https://semgrep.dev/playground/r/9lTy168/go.lang.security.audit.net.pprof.pprof-debug-exposure + origin: community + message: The profiling 'pprof' endpoint is automatically exposed on /debug/pprof. + This could leak information about the server. Instead, use `import "net/http/pprof"`. + See https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ + for more information and mitigation. + languages: + - go + severity: WARNING + patterns: + - pattern-inside: | + import _ "net/http/pprof" + ... + - pattern-inside: | + func $ANY(...) { + ... + } + - pattern-not-inside: | + $MUX = http.NewServeMux(...) + ... + http.ListenAndServe($ADDR, $MUX) + - pattern-not: http.ListenAndServe("=~/^localhost.*/", ...) + - pattern-not: http.ListenAndServe("=~/^127[.]0[.]0[.]1.*/", ...) + - pattern: http.ListenAndServe(...) +- id: go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + message: Found a formatted template string passed to 'template. HTMLAttr()'. 'template.HTMLAttr()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template or validate and sanitize the data before passing it into the + template. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTMLAttr + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + shortlink: https://sg.run/OPRp + semgrep.dev: + rule: + r_id: 9131 + rv_id: 1262945 + rule_id: QrUz9R + version_id: 3ZT4XRr + url: https://semgrep.dev/playground/r/3ZT4XRr/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.HTMLAttr($T + $X, ...) + - pattern: template.HTMLAttr(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTMLAttr($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTMLAttr($OTHER, ...) +- id: go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + message: Found a formatted template string passed to 'template.JS()'. 'template.JS()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#JS + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + shortlink: https://sg.run/eLNl + semgrep.dev: + rule: + r_id: 9132 + rv_id: 1262946 + rule_id: 3qUP8K + version_id: 44TEj9E + url: https://semgrep.dev/playground/r/44TEj9E/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.JS($T + $X, ...) + - pattern: template.JS(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.JS($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.JS($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.JS($T, ...) + - pattern: | + $T = $X + $Y + ... + template.JS($T, ...) + - pattern: | + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.JS($OTHER, ...) +- id: go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + message: Found a formatted template string passed to 'template.URL()'. 'template.URL()' + does not escape contents, and this could result in XSS (cross-site scripting) + and therefore confidential data being stolen. Sanitize data coming into this function + or make sure that no user-controlled input is coming into the function. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#URL + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + shortlink: https://sg.run/vzE4 + semgrep.dev: + rule: + r_id: 9133 + rv_id: 1262947 + rule_id: 4bUkDW + version_id: PkTR3zz + url: https://semgrep.dev/playground/r/PkTR3zz/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.URL($T + $X, ...) + - pattern: template.URL(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.URL($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.URL($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.URL($T, ...) + - pattern: | + $T = $X + $Y + ... + template.URL($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.URL($OTHER, ...) +- id: go.lang.security.audit.net.use-tls.use-tls + pattern: http.ListenAndServe($ADDR, $HANDLER) + fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + shortlink: https://sg.run/dKbY + semgrep.dev: + rule: + r_id: 9134 + rv_id: 1262948 + rule_id: PeUZ8X + version_id: JdTzxkn + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + origin: community + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. + See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + languages: + - go + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + patterns: + - pattern-inside: | + func $FUNC(..., $W http.ResponseWriter, ...) { + ... + var $TEMPLATE = "..." + ... + $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) + ... + } + - pattern-either: + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) + message: Found data going from url query parameters into formatted data written + to ResponseWriter. This could be XSS and should not be done. If you must do this, + ensure your data is sanitized or escaped. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + shortlink: https://sg.run/Zvon + semgrep.dev: + rule: + r_id: 9135 + rv_id: 1262949 + rule_id: JDUyXB + version_id: 5PTo1qr + url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + origin: community + severity: WARNING + languages: + - go +- id: go.lang.security.audit.xss.import-text-template.import-text-template + message: When working with web applications that involve rendering user-generated content, + it's important to properly escape any HTML content to prevent Cross-Site Scripting + (XSS) attacks. In Go, the `text/template` package does not automatically escape + HTML content, which can leave your application vulnerable to these types of attacks. + To mitigate this risk, it's recommended to use the `html/template` package instead, + which provides built-in functionality for HTML escaping. By using `html/template` + to render your HTML content, you can help to ensure that your web application + is more secure and less susceptible to XSS vulnerabilities. + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://www.veracode.com/blog/secure-development/use-golang-these-mistakes-could-compromise-your-apps-security + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.import-text-template.import-text-template + shortlink: https://sg.run/ndEO + semgrep.dev: + rule: + r_id: 9136 + rv_id: 1262956 + rule_id: 5rUOZQ + version_id: 0bTKzok + url: https://semgrep.dev/playground/r/0bTKzok/go.lang.security.audit.xss.import-text-template.import-text-template + origin: community + severity: WARNING + patterns: + - pattern: | + import "$IMPORT" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(text/template)$ + - focus-metavariable: $IMPORT + fix: | + html/template + languages: + - go +- id: go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + languages: + - go + message: Detected directly writing or similar in 'http.ResponseWriter.write()'. + This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. + Instead, use the 'html/template' package and render data using 'template.Execute()'. + metadata: + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + shortlink: https://sg.run/EkbA + semgrep.dev: + rule: + r_id: 9137 + rv_id: 1262957 + rule_id: GdU71y + version_id: K3TKkoB + url: https://semgrep.dev/playground/r/K3TKkoB/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + origin: community + patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-inside: | + func $HANDLER(..., $WRITER *http.ResponseWriter, ...) { + ... + } + - pattern-inside: | + func(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-either: + - pattern: $WRITER.Write(...) + - pattern: (*$WRITER).Write(...) + - pattern-not: $WRITER.Write([]byte("...")) + severity: WARNING +- id: go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + message: Detected 'Fprintf' or similar writing to 'http.ResponseWriter'. This bypasses + HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use + the 'html/template' package to render data to users. + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + shortlink: https://sg.run/7oqR + semgrep.dev: + rule: + r_id: 9138 + rv_id: 1262958 + rule_id: ReUgyJ + version_id: qkTR7OP + url: https://semgrep.dev/playground/r/qkTR7OP/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-inside: | + func(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-not: fmt.$PRINTF($WRITER, "...") + - pattern: fmt.$PRINTF($WRITER, ...) + languages: + - go +- id: go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + message: Detected template variable interpolation in an HTML tag. This is potentially + vulnerable to cross-site scripting (XSS) attacks because a malicious actor has + control over HTML but without the need to use escaped characters. Use explicit + tags instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/golang/go/issues/19669 + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + category: security + technology: + - generic + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + shortlink: https://sg.run/LwJJ + semgrep.dev: + rule: + r_id: 9139 + rv_id: 1262959 + rule_id: AbUzBB + version_id: l4TJRZK + url: https://semgrep.dev/playground/r/l4TJRZK/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + origin: community + languages: + - generic + severity: WARNING + paths: + include: + - '*.html' + - '*.thtml' + - '*.gohtml' + - '*.tmpl' + - '*.tpl' + pattern: <{{ ... }} ... > +- id: go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + message: Detected template variable interpolation in a JavaScript template string. + This is potentially vulnerable to cross-site scripting (XSS) attacks because a + malicious actor has control over JavaScript but without the need to use escaped + characters. Instead, obtain this variable outside of the template string and ensure + your template is properly escaped. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/golang/go/issues/9200#issuecomment-66100328 + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + category: security + technology: + - generic + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + shortlink: https://sg.run/8yl7 + semgrep.dev: + rule: + r_id: 9140 + rv_id: 1262960 + rule_id: BYUNR6 + version_id: YDTZeEB + url: https://semgrep.dev/playground/r/YDTZeEB/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + origin: community + languages: + - generic + severity: WARNING + paths: + include: + - '*.html' + - '*.thtml' + - '*.gohtml' + - '*.tmpl' + - '*.tpl' + patterns: + - pattern-inside: + - pattern: '` ... {{ ... }} ...`' +- id: go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + message: Detected 'io.WriteString()' writing directly to 'http.ResponseWriter'. + This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. + Instead, use the 'html/template' package to render data to users. + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + - https://golang.org/pkg/io/#WriteString + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + shortlink: https://sg.run/gLwn + semgrep.dev: + rule: + r_id: 9141 + rv_id: 1262961 + rule_id: DbUpEr + version_id: 6xT2983 + url: https://semgrep.dev/playground/r/6xT2983/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-inside: | + func(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-not: io.WriteString($WRITER, "...") + - pattern: io.WriteString($WRITER, $STRING) + languages: + - go +- id: go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + message: Detected 'printf' or similar in 'http.ResponseWriter.write()'. This bypasses + HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use + the 'html/template' package to render data to users. + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + shortlink: https://sg.run/Q5BP + semgrep.dev: + rule: + r_id: 9142 + rv_id: 1262962 + rule_id: WAUoLp + version_id: o5TbDdq + url: https://semgrep.dev/playground/r/o5TbDdq/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern-inside: | + func(..., $WRITER http.ResponseWriter, ...) { + ... + } + - pattern: | + $WRITER.Write(<... fmt.$PRINTF(...) ...>, ...) + languages: + - go +- id: go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + message: Semgrep could not determine that the argument to 'template.HTML()' is a + constant. 'template.HTML()' and similar does not escape contents. Be absolutely + sure there is no user-controlled data in this template. If user data can reach + this template, you may have a XSS vulnerability. Instead, do not use this function + and use 'template.Execute()'. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/vulnerability/xss/xss.go#L33 + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + shortlink: https://sg.run/3xDb + semgrep.dev: + rule: + r_id: 9143 + rv_id: 1262963 + rule_id: 0oU5n3 + version_id: zyTb2Lz + url: https://semgrep.dev/playground/r/zyTb2Lz/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-not: template.$ANY("..." + "...") + - pattern-not: template.$ANY("...") + - pattern-either: + - pattern: template.HTML(...) + - pattern: template.CSS(...) + - pattern: template.HTMLAttr(...) + - pattern: template.JS(...) + - pattern: template.JSStr(...) + - pattern: template.Srcset(...) + - pattern: template.URL(...) +- id: go.otto.security.audit.dangerous-execution.dangerous-execution + message: Detected non-static script inside otto VM. Audit the input to 'VM.Run'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - otto + - vm + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.otto.security.audit.dangerous-execution.dangerous-execution + shortlink: https://sg.run/4xWE + semgrep.dev: + rule: + r_id: 9144 + rv_id: 1262972 + rule_id: KxUbxk + version_id: bZT53ZY + url: https://semgrep.dev/playground/r/bZT53ZY/go.otto.security.audit.dangerous-execution.dangerous-execution + origin: community + severity: ERROR + patterns: + - pattern-inside: | + $VM = otto.New(...) + ... + - pattern-not: $VM.Run("...", ...) + - pattern: $VM.Run(...) + languages: + - go +- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + technology: + - java + - secrets + - jwt + category: security + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + shortlink: https://sg.run/RoDK + semgrep.dev: + rule: + r_id: 9149 + rv_id: 1262980 + rule_id: oqUeAn + version_id: d6Tyx8j + url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - pattern: | + (Algorithm $ALG) = $ALGO.$HMAC("$Y"); + - pattern: | + $SECRET = "$Y"; + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + - pattern: | + class $CLASS { + ... + $TYPE $SECRET = "$Y"; + ... + $RETURNTYPE $FUNC (...) { + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + ... + } + ... + } + - focus-metavariable: $Y + - metavariable-regex: + metavariable: $HMAC + regex: (HMAC384|HMAC256|HMAC512) +- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + shortlink: https://sg.run/Av14 + semgrep.dev: + rule: + r_id: 9150 + rv_id: 1262981 + rule_id: zdUkzR + version_id: ZRTKADq + url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + origin: community + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $JWT.sign(com.auth0.jwt.algorithms.Algorithm.none()); + - pattern: | + $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $JWT.sign($NONE); + - pattern: |- + class $CLASS { + ... + $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $RETURNTYPE $FUNC (...) { + ... + $JWT.sign($NONE); + ... + } + ... + } +- id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + message: Detected the decoding of a JWT token without a verify step. JWT tokens + must be verified before use, otherwise the token's integrity is unknown. This + means a malicious actor could forge a JWT token with any claims. Call '.verify()' + before using the token. + metadata: + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: MEDIUM + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + shortlink: https://sg.run/Bk95 + semgrep.dev: + rule: + r_id: 9151 + rv_id: 1262979 + rule_id: pKUOE9 + version_id: vdT06Lp + url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern: | + com.auth0.jwt.JWT.decode(...); + - pattern-not-inside: |- + class $CLASS { + ... + $RETURNTYPE $FUNC (...) { + ... + $VERIFIER.verify(...); + ... + } + } +- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - jax-rs + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + shortlink: https://sg.run/DoWj + semgrep.dev: + rule: + r_id: 9152 + rv_id: 1262984 + rule_id: 2ZUb9l + version_id: 7ZTE3KW + url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } + - pattern: |- + $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } +- id: java.jboss.security.session_sqli.find-sql-string-concatenation + message: In $METHOD, $X is used to construct a SQL query via string concatenation. + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + Session $SESSION = ...; + ... + String $QUERY = ... + $X + ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + String $QUERY = ... + $X + ...; + ... + Session $SESSION = ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + metadata: + category: security + technology: + - jboss + confidence: MEDIUM + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation + shortlink: https://sg.run/W8kA + semgrep.dev: + rule: + r_id: 9153 + rv_id: 1262986 + rule_id: X5U8rQ + version_id: 8KT5r3v + url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation + origin: community +- id: java.jjwt.security.jwt-none-alg.jjwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + confidence: LOW + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.jjwt.security.jwt-none-alg.jjwt-none-alg + shortlink: https://sg.run/0Q7b + semgrep.dev: + rule: + r_id: 9154 + rv_id: 1262987 + rule_id: j2Uvol + version_id: gETB7re + url: https://semgrep.dev/playground/r/gETB7re/java.jjwt.security.jwt-none-alg.jjwt-none-alg + origin: community + languages: + - java + severity: ERROR + patterns: + - pattern: | + io.jsonwebtoken.Jwts.builder(); + - pattern-not-inside: |- + $RETURNTYPE $FUNC(...) { + ... + $JWTS.signWith(...); + ... + } +- id: java.lang.security.do-privileged-use.do-privileged-use + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + references: + - https://docs.oracle.com/javase/8/docs/technotes/guides/security/doprivileged.html + - https://wiki.sei.cmu.edu/confluence/display/java/Privilege+Escalation + - http://phrack.org/papers/escaping_the_java_sandbox.html + category: security + technology: + - java + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/java.lang.security.do-privileged-use.do-privileged-use + shortlink: https://sg.run/6n76 + semgrep.dev: + rule: + r_id: 9159 + rv_id: 1263063 + rule_id: bwUw28 + version_id: o5TbDoY + url: https://semgrep.dev/playground/r/o5TbDoY/java.lang.security.do-privileged-use.do-privileged-use + origin: community + message: Marking code as privileged enables a piece of trusted code to temporarily + enable access to more resources than are available directly to the code that called + it. Be very careful in your use of the privileged construct, and always remember + to make the privileged code section as small as possible. + patterns: + - pattern-inside: | + import java.security.*; + ... + - pattern-either: + - pattern: AccessController.doPrivileged(...); + - pattern: class $ACTION implements PrivilegedAction { ... } +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + shortlink: https://sg.run/oxXN + semgrep.dev: + rule: + r_id: 9160 + rv_id: 1263064 + rule_id: NbUk7X + version_id: zyTb2rq + url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (java.io.File $FILE) = ... + - pattern: | + (java.io.FileOutputStream $FOS) = ... + - pattern: | + new java.io.FileInputStream(...) + severity: ERROR + languages: + - java +- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.3 Insecue Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + shortlink: https://sg.run/zvO1 + semgrep.dev: + rule: + r_id: 9161 + rv_id: 1263065 + rule_id: kxUk12 + version_id: pZT03A1 + url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + origin: community + message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling + of the message payload when ObjectMessage.getObject() is called. Deserialization + of untrusted data can lead to security flaws; a remote attacker could via a crafted + JMS ObjectMessage to execute arbitrary code with the permissions of the application + listening/consuming JMS Messages. In this case, the JMS MessageListener consume + an ObjectMessage type received inside the onMessage method, which may lead to + arbitrary code execution when calling the $Y.getObject method. + patterns: + - pattern-inside: | + public class $JMS_LISTENER implements MessageListener { + ... + public void onMessage(Message $JMS_MSG) { + ... + } + } + - pattern-either: + - pattern-inside: $X = $Y.getObject(...); + - pattern-inside: $X = ($Z) $Y.getObject(...); +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + message: 'Cross-site scripting detected in HttpServletResponse writer with variable + ''$VAR''. User input was detected going directly from the HttpServletRequest into + output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + ''Encode.forHtml($VAR)''.' + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + shortlink: https://sg.run/pxjN + semgrep.dev: + rule: + r_id: 9162 + rv_id: 1263066 + rule_id: wdUJOk + version_id: 2KTv2EG + url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + origin: community + severity: ERROR + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: | + $WRITER = $RESP.getWriter(...); + ... + $WRITER.write(..., $VAR, ...); + languages: + - java +- id: java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + shortlink: https://sg.run/2x75 + semgrep.dev: + rule: + r_id: 9163 + rv_id: 1263068 + rule_id: x8Unkq + version_id: jQTn5Jv + url: https://semgrep.dev/playground/r/jQTn5Jv/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + origin: community + message: XML external entities are enabled for this XMLInputFactory. This is vulnerable + to XML external entity attacks. Disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" + to false. + patterns: + - pattern-either: + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", + Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + Boolean.TRUE); + languages: + - java +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + shortlink: https://sg.run/XBwA + semgrep.dev: + rule: + r_id: 9164 + rv_id: 1263069 + rule_id: OrU35O + version_id: 1QTypQZ + url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + origin: community + message: XML external entities are not explicitly disabled for this XMLInputFactory. + This could be vulnerable to XML external entity vulnerabilities. Explicitly disable + external entities by setting "javax.xml.stream.isSupportingExternalEntities" to + false. + patterns: + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); + ... + } + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + languages: + - java +- id: java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + metadata: + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + shortlink: https://sg.run/jR6A + semgrep.dev: + rule: + r_id: 9165 + rv_id: 1262988 + rule_id: eqU8J3 + version_id: QkTGqE0 + url: https://semgrep.dev/playground/r/QkTGqE0/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + origin: community + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html + for more information. + severity: WARNING + pattern: | + $ENV.put($CTX.SECURITY_AUTHENTICATION, "none"); + ... + $DCTX = new InitialDirContext($ENV, ...); + languages: + - java +- id: java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + metadata: + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + owasp: A03:2017 - Sensitive Data Exposure + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BAD_HEXA_CONVERSION + category: security + technology: + - java + references: + - https://cwe.mitre.org/data/definitions/704.html + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + shortlink: https://sg.run/1Z7D + semgrep.dev: + rule: + r_id: 9166 + rv_id: 945646 + rule_id: v8Uny0 + version_id: QkTZzgy + url: https://semgrep.dev/playground/r/QkTZzgy/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + origin: community + message: '''Integer.toHexString()'' strips leading zeroes from each byte if read + byte-by-byte. This mistake weakens the hash value computed since it introduces + more collisions. Use ''String.format("%02X", ...)'' instead.' + severity: WARNING + languages: + - java + pattern: |- + $X $METHOD(...) { + ... + MessageDigest $MD = ...; + ... + $MD.digest(...); + ... + Integer.toHexString(...); + } +- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + shortlink: https://sg.run/9o74 + semgrep.dev: + rule: + r_id: 9167 + rv_id: 1262989 + rule_id: d8UjJ3 + version_id: 3ZT4X2r + url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + origin: community + message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits + or more, or switch to use AES instead. + severity: WARNING + languages: + - java + patterns: + - pattern: | + $KEYGEN = KeyGenerator.getInstance("Blowfish"); + ... + $KEYGEN.init($SIZE); + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 128 +- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A + malicious actor could discern the difference between plaintext with valid or invalid + padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' + instead. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE + references: + - https://capec.mitre.org/data/definitions/463.html + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY + category: security + technology: + - java + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + shortlink: https://sg.run/ydxr + semgrep.dev: + rule: + r_id: 9168 + rv_id: 1262990 + rule_id: ZqU5oD + version_id: 44TEjbE + url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + origin: community + severity: WARNING + fix: | + "AES/GCM/NoPadding" + languages: + - java + patterns: + - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") + - pattern: | + "=~/.*\/CBC\/PKCS5Padding/" +- id: java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + patterns: + - metavariable-pattern: + metavariable: $RUNTIME + patterns: + - pattern-either: + - pattern: (java.lang.Runtime $R) + - pattern: java.lang.Runtime.getRuntime(...) + - pattern-either: + - pattern: $RUNTIME.exec($X + $Y); + - pattern: $RUNTIME.exec(String.format(...)); + - pattern: $RUNTIME.loadLibrary($X + $Y); + - pattern: $RUNTIME.loadLibrary(String.format(...)); + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...},...) + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec($CMD,"-c",$ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList($CMD,"-c",$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{$CMD,"-c",$ARG,...},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; + ... + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec($CMD, $EXECUTE, $ARG, ...) + - pattern-inside: | + $CMD = new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/", ...}; + ... + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", $BASH, $ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...},...) + - pattern-inside: | + $BASH = new String[]{"=~/(-c)/", ...}; + ... + - pattern-not-inside: | + $ARG = "..."; + ... + - pattern-not: | + $RUNTIME.exec("...","...","...",...) + - pattern-not: | + $RUNTIME.exec(new String[]{"...","...","...",...},...) + - pattern-not: | + $RUNTIME.exec(Arrays.asList("...","...","...",...),...) + message: A formatted or concatenated string was detected as input to a java.lang.Runtime + call. This is dangerous if a variable is controlled by user input and could result + in a command injection. Ensure your variables are not controlled by users or sufficiently + sanitized. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#COMMAND_INJECTION. + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + shortlink: https://sg.run/rd90 + semgrep.dev: + rule: + r_id: 9169 + rv_id: 1262991 + rule_id: nJUzvJ + version_id: PkTR3ez + url: https://semgrep.dev/playground/r/PkTR3ez/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + origin: community + severity: ERROR + languages: + - java +- id: java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTPONLY_COOKIE + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.4.2 Missing Cookie Attribute + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + shortlink: https://sg.run/b7Be + semgrep.dev: + rule: + r_id: 9170 + rv_id: 1262993 + rule_id: EwU2z6 + version_id: 5PTo17r + url: https://semgrep.dev/playground/r/5PTo17r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + origin: community + message: A cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' + flag for cookies instructs the browser to forbid client-side scripts from reading + the cookie. Set the 'HttpOnly' flag by calling 'cookie.setHttpOnly(true);' + severity: WARNING + languages: + - java + patterns: + - pattern-not-inside: $COOKIE.setValue(""); ... + - pattern-either: + - pattern: $COOKIE.setHttpOnly(false); + - patterns: + - pattern-not-inside: $COOKIE.setHttpOnly(...); ... + - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... + - pattern: $RESPONSE.addCookie($COOKIE); +- id: java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_COOKIE + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.4.1 Missing Cookie Attribute + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + shortlink: https://sg.run/kXoK + semgrep.dev: + rule: + r_id: 9172 + rv_id: 1262994 + rule_id: L1Uyvp + version_id: GxTkelB + url: https://semgrep.dev/playground/r/GxTkelB/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + origin: community + message: A cookie was detected without setting the 'secure' flag. The 'secure' flag + for cookies prevents the client from transmitting the cookie over insecure channels + such as HTTP. Set the 'secure' flag by calling '$COOKIE.setSecure(true);' + severity: WARNING + languages: + - java + patterns: + - pattern-not-inside: $COOKIE.setValue(""); ... + - pattern-either: + - pattern: $COOKIE.setSecure(false); + - patterns: + - pattern-not-inside: $COOKIE.setSecure(...); ... + - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... + - pattern: $RESPONSE.addCookie($COOKIE); +- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + message: When data from an untrusted source is put into a logger and not neutralized + correctly, an attacker could forge log entries or include malicious content. + metadata: + cwe: + - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + shortlink: https://sg.run/wek0 + semgrep.dev: + rule: + r_id: 9173 + rv_id: 1262995 + rule_id: 8GUjwW + version_id: RGT0LEr + url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + class $CLASS { + ... + Logger $LOG = ...; + ... + } + - pattern-either: + - pattern-inside: | + $X $METHOD(...,HttpServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...,ServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + ServletRequest $REQ = ...; + ... + } + - pattern-either: + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.$LEVEL(<... $VAL ...>); + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.log($LEVEL,<... $VAL ...>); + - pattern: | + $LOG.$LEVEL(<... $REQ.getParameter(...) ...>); + - pattern: | + $LOG.log($LEVEL,<... $REQ.getParameter(...) ...>); +- id: java.lang.security.audit.el-injection.el-injection + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#EL_INJECTION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.el-injection.el-injection + shortlink: https://sg.run/x1wp + semgrep.dev: + rule: + r_id: 9174 + rv_id: 1263021 + rule_id: gxU1Np + version_id: pZT03e1 + url: https://semgrep.dev/playground/r/pZT03e1/java.lang.security.audit.el-injection.el-injection + origin: community + message: An expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF; + ... + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF = ...; + ... + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + $X $METHOD(...) { + ... + ExpressionFactory $EF = ...; + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ExpressionFactory $EF,...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF; + ... + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF = ...; + ... + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + $X $METHOD(...) { + ... + ExpressionFactory $EF = ...; + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ExpressionFactory $EF,...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(String $INPUT, ...) { + ... + $OBJECT.buildConstraintViolationWithTemplate($INPUT, ...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $EF.createValueExpression($CTX,$S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $EF.createMethodExpression($CTX,$S,...); + ... + } +- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps + - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string + shortlink: https://sg.run/OPXp + semgrep.dev: + rule: + r_id: 9175 + rv_id: 1409389 + rule_id: QrUzxR + version_id: ExTeyBP + url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + $ANNOT $FUNC (..., $INPUT, ...) { + ... + } + - pattern: (String $INPUT) + - focus-metavariable: $INPUT + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $INPUT + - pattern: $X += $INPUT + - pattern: String.format(..., $INPUT, ...) + - pattern: String.join(..., $INPUT, ...) + - pattern: (String $STR).concat($INPUT) + - pattern: $INPUT.concat(...) + - patterns: + - pattern-either: + - pattern: $STRB.append($INPUT) + - pattern: new $STRB(..., $INPUT, ...) + - metavariable-type: + metavariable: $STRB + type: StringBuilder + label: CONCAT + requires: INPUT + pattern-propagators: + - pattern: (StringBuffer $S).append($X) + from: $X + to: $S + - pattern: (StringBuilder $S).append($X) + from: $X + to: $S + pattern-sinks: + - patterns: + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) + - pattern-either: + - pattern: (Statement $S).$SQLFUNC(...) + - pattern: (PreparedStatement $P).$SQLFUNC(...) + - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) + - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) + - pattern: (EntityManager $EM).$SQLFUNC(...) + - metavariable-regex: + metavariable: $SQLFUNC + regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare + requires: CONCAT + pattern-sanitizers: + - patterns: + - pattern: (CriteriaBuilder $CB).$ANY(...) + severity: ERROR + languages: + - java +- id: java.lang.security.audit.http-response-splitting.http-response-splitting + metadata: + cwe: + - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP + Request/Response Splitting'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING + references: + - https://www.owasp.org/index.php/HTTP_Response_Splitting + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting + shortlink: https://sg.run/eL0l + semgrep.dev: + rule: + r_id: 9176 + rv_id: 1263023 + rule_id: 3qUPyK + version_id: X0Tzykw + url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting + origin: community + message: Older Java application servers are vulnerable to HTTP response splitting, + which may occur if an HTTP request can be injected with CRLF characters. This + finding is reported for completeness; it is recommended to ensure your environment + is not affected by testing this yourself. + severity: INFO + languages: + - java + pattern-either: + - pattern: | + $VAR = $REQ.getParameter(...); + ... + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); + - patterns: + - pattern-inside: | + $RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) { + ... + } + - pattern: | + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); +- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + metadata: + cwe: + - 'CWE-297: Improper Validation of Certificate with Host Mismatch' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + shortlink: https://sg.run/vzN4 + semgrep.dev: + rule: + r_id: 9177 + rv_id: 1263024 + rule_id: 4bUkrW + version_id: jQTn5Dv + url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + origin: community + message: Insecure SMTP connection detected. This connection will trust any SSL certificate. + Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'. + severity: WARNING + patterns: + - pattern-not-inside: | + $EMAIL.setSSLCheckServerIdentity(true); + ... + - pattern-inside: | + $EMAIL = new SimpleEmail(...); + ... + - pattern: $EMAIL.send(...); + languages: + - java +- id: java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION_SPRING_JDBC + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - jdbc + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + shortlink: https://sg.run/dKWY + semgrep.dev: + rule: + r_id: 9178 + rv_id: 1263026 + rule_id: PeUZNX + version_id: 9lT4bqk + url: https://semgrep.dev/playground/r/9lT4bqk/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + origin: community + message: 'Possible JDBC injection detected. Use the parameterized query feature + available in queryForObject instead of concatenating or formatting strings: ''jdbc.queryForObject("select + * from table where name = ?", Integer.class, parameterName);''' + patterns: + - pattern-inside: | + $JDBC = new JdbcTemplate(...); + ... + - pattern-either: + - pattern: $JDBC.queryForObject($STR + $VAR, ...); + - pattern: $JDBC.queryForObject(String.format(...), ...); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.queryForObject($Q, ...); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.queryForObject($Q, ...); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.queryForObject($Q, ...); + - pattern: $JDBC.queryForList($STR + $VAR); + - pattern: $JDBC.queryForList(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.queryForList($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.queryForList($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.queryForList($Q, ...); + - pattern: $JDBC.update($STR + $VAR); + - pattern: $JDBC.update(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.update($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.update($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.update($Q, ...); + - pattern: $JDBC.execute($STR + $VAR); + - pattern: $JDBC.execute(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.execute($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.execute($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.execute($Q, ...); + - pattern: $JDBC.insert($STR + $VAR); + - pattern: $JDBC.insert(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.insert($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.insert($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.insert($Q, ...); + severity: WARNING + languages: + - java +- id: java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ENTRY_POISONING + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.7 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + shortlink: https://sg.run/ZvOn + semgrep.dev: + rule: + r_id: 9179 + rv_id: 1263027 + rule_id: JDUy8B + version_id: yeTxpGP + url: https://semgrep.dev/playground/r/yeTxpGP/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + origin: community + message: An object-returning LDAP search will allow attackers to control the LDAP + response. This could lead to Remote Code Execution. + severity: WARNING + pattern-either: + - pattern: | + new SearchControls($S, $CL, $TL, $AT, true, $DEREF) + - pattern: | + SearchControls $VAR = new SearchControls(); + ... + $VAR.setReturningObjFlag(true); + languages: + - java +- id: java.lang.security.audit.ldap-injection.ldap-injection + message: Detected non-constant data passed into an LDAP query. If this data can + be controlled by an external user, this is an LDAP injection. Ensure data passed + to an LDAP query is not controllable; or properly sanitize the data. + metadata: + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.7 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.ldap-injection.ldap-injection + shortlink: https://sg.run/nd2O + semgrep.dev: + rule: + r_id: 9180 + rv_id: 1263028 + rule_id: 5rUObQ + version_id: rxTAKl2 + url: https://semgrep.dev/playground/r/rxTAKl2/java.lang.security.audit.ldap-injection.ldap-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + $X $METHOD(...) { + ... + InitialDirContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + DirContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + InitialLdapContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + LdapContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + LdapCtx $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + EventDirContext $CTX = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $CTX.search($Y,$INPUT,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $CTX.search($Y,"...",...); + ... + } +- id: java.lang.security.audit.object-deserialization.object-deserialization + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OBJECT_DESERIALIZATION + references: + - https://www.owasp.org/index.php/Deserialization_of_untrusted_data + - https://www.oracle.com/java/technologies/javase/seccodeguide.html#8 + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.audit.object-deserialization.object-deserialization + shortlink: https://sg.run/Ek0A + semgrep.dev: + rule: + r_id: 9181 + rv_id: 1263030 + rule_id: GdU7py + version_id: NdTzyGe + url: https://semgrep.dev/playground/r/NdTzyGe/java.lang.security.audit.object-deserialization.object-deserialization + origin: community + message: Found object deserialization using ObjectInputStream. Deserializing entire + Java objects is dangerous because malicious actors can create Java object streams + with unintended consequences. Ensure that the objects being deserialized are not + user-controlled. If this must be done, consider using HMACs to sign the data stream + to make sure it is not tampered with, or consider only transmitting object fields + and populating a new object. + severity: WARNING + languages: + - java + pattern: new ObjectInputStream(...); +- id: java.lang.security.audit.ognl-injection.ognl-injection + message: A expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OGNL_INJECTION + category: security + technology: + - ognl + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.ognl-injection.ognl-injection + shortlink: https://sg.run/7o7R + semgrep.dev: + rule: + r_id: 9182 + rv_id: 1263031 + rule_id: ReUgjJ + version_id: kbTzG3Y + url: https://semgrep.dev/playground/r/kbTzG3Y/java.lang.security.audit.ognl-injection.ognl-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.getGetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.getSetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.getField($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlReflectionProvider $P,...) { + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.getGetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.getSetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.getField($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ReflectionProvider $P,...) { + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,TextParseUtil $P,...) { + ... + $P.translateVariables($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,TextParseUtil $P,...) { + ... + $P.translateVariablesCollection($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,TextParseUtil $P,...) { + ... + $P.shallBeIncluded($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,TextParseUtil $P,...) { + ... + $P.commaDelimitedStringToSet($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,TextParser $P,...) { + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlTextParser $P,...) { + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.callMethod($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlUtil $P,...) { + ... + $P.compile($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,VelocityStrutsUtil $P,...) { + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.isTrue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.findString($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.getText($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.translateVariables($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,StrutsUtil $P,...) { + ... + $P.makeSelectList($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,OgnlTool $P,...) { + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ValueStack $P,...) { + ... + $P.findString($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ValueStack $P,...) { + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ValueStack $P,...) { + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ValueStack $P,...) { + ... + $P.setParameter($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.getGetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.getSetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.getField($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlReflectionProvider $P = ...; + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.getGetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.getSetMethod($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.getField($T, $INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ReflectionProvider $P = ...; + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + TextParseUtil $P = ...; + ... + $P.translateVariables($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + TextParseUtil $P = ...; + ... + $P.translateVariablesCollection($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + TextParseUtil $P = ...; + ... + $P.shallBeIncluded($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + TextParseUtil $P = ...; + ... + $P.commaDelimitedStringToSet($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + TextParser $P = ...; + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlTextParser $P = ...; + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.setProperties($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.setProperty($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.getValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.callMethod($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlUtil $P = ...; + ... + $P.compile($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + VelocityStrutsUtil $P = ...; + ... + $P.evaluate($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.isTrue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.findString($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.getText($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.translateVariables($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + StrutsUtil $P = ...; + ... + $P.makeSelectList($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + OgnlTool $P = ...; + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ValueStack $P = ...; + ... + $P.findString($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ValueStack $P = ...; + ... + $P.findValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ValueStack $P = ...; + ... + $P.setValue($INPUT,...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + ValueStack $P = ...; + ... + $P.setParameter($INPUT,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.getGetMethod($T,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.getSetMethod($T,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.getField($T,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.setProperties("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.setProperty("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.getValue("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.setValue("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.translateVariables("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.translateVariablesCollection("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.shallBeIncluded("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.commaDelimitedStringToSet("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.evaluate("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.callMethod("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.compile("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.isTrue("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.findString("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.findValue("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.getText("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.makeSelectList("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $P.setParameter("...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.getGetMethod($T,$S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.getSetMethod($T,$S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.getField($T,$S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.setProperties($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.setProperty($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.getValue($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.setValue($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.translateVariables($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.translateVariablesCollection($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.shallBeIncluded($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.commaDelimitedStringToSet($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.evaluate($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.callMethod($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.compile($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.isTrue($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.findString($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.findValue($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.getText($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.makeSelectList($S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $P.setParameter($S,...); + ... + } +- id: java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + message: Detected file permissions that are overly permissive (read, write, and + execute). It is generally a bad practices to set overly permissive file permission + such as read+write+exec for all users. If the file affected is a configuration, + a binary, a script or sensitive data, it can lead to privilege escalation or information + leakage. Instead, follow the principle of least privilege and give users only + the permissions they need. + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-276: Incorrect Default Permissions' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OVERLY_PERMISSIVE_FILE_PERMISSION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + shortlink: https://sg.run/LwzJ + semgrep.dev: + rule: + r_id: 9183 + rv_id: 1263032 + rule_id: AbUzwB + version_id: w8TRoNn + url: https://semgrep.dev/playground/r/w8TRoNn/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + origin: community + pattern-either: + - pattern: java.nio.file.Files.setPosixFilePermissions($FILE, java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/")); + - pattern: | + $TYPE $P = java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/"); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: | + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_READ); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: | + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_WRITE); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: |- + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_EXECUTE); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); +- id: java.lang.security.audit.permissive-cors.permissive-cors + message: https://find-sec-bugs.github.io/bugs.htm#PERMISSIVE_CORS Permissive CORS + policy will allow a malicious application to communicate with the victim application + in an inappropriate way, leading to spoofing, data theft, relay and other attacks. + metadata: + cwe: + - 'CWE-183: Permissive List of Allowed Inputs' + asvs: + section: 'V14: Configuration Verification Requirements' + control_id: 14.4.8 Permissive CORS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x22-V14-Config.md#v144-http-security-headers-requirements + version: '4' + category: security + technology: + - java + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.permissive-cors.permissive-cors + shortlink: https://sg.run/8y77 + semgrep.dev: + rule: + r_id: 9184 + rv_id: 1263033 + rule_id: BYUN66 + version_id: xyTjz0p + url: https://semgrep.dev/playground/r/xyTjz0p/java.lang.security.audit.permissive-cors.permissive-cors + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + HttpServletResponse $RES = ...; + ... + $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + HttpServletResponse $RES = ...; + ... + $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + ServerHttpResponse $RES = ...; + ... + $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + HttpHeaders $HEADERS = ...; + ... + $HEADERS.set("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + ServerWebExchange $SWE = ...; + ... + $SWE.getResponse().getHeaders().add("Access-Control-Allow-Origin", "*"); + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,ServerHttpResponse $RES,...) { + ... + $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,ServerWebExchange $SWE,...) { + ... + $SWE.getResponse().getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: ResponseEntity.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") + - pattern: ServerResponse.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") +- id: java.lang.security.audit.script-engine-injection.script-engine-injection + message: Detected potential code injection using ScriptEngine. Ensure user-controlled + data cannot enter '.eval()', otherwise, this is a code injection vulnerability. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SCRIPT_ENGINE_INJECTION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.script-engine-injection.script-engine-injection + shortlink: https://sg.run/gLqn + semgrep.dev: + rule: + r_id: 9185 + rv_id: 1263034 + rule_id: DbUpAr + version_id: O9TpxEp + url: https://semgrep.dev/playground/r/O9TpxEp/java.lang.security.audit.script-engine-injection.script-engine-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS { + ... + ScriptEngine $SE; + ... + } + - pattern-inside: | + class $CLASS { + ... + ScriptEngine $SE = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ScriptEngine $SE = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $SE.eval(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $SE.eval("..."); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $SE.eval($S); + ... + } +- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + message: Application redirects to a destination URL specified by a user-supplied + parameter that is not validated. This could direct users to malicious locations. + Consider using an allowlist to validate URLs. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.1.5 Open Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + impact: LOW + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + shortlink: https://sg.run/Q51P + semgrep.dev: + rule: + r_id: 9186 + rv_id: 1263048 + rule_id: WAUo0p + version_id: PkTR329 + url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } + - pattern: |- + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } +- id: java.lang.security.audit.url-rewriting.url-rewriting + message: URL rewriting has significant security risks. Since session ID appears + in the URL, it may be easily seen by third parties. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#URL_REWRITING + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.url-rewriting.url-rewriting + shortlink: https://sg.run/3x7b + semgrep.dev: + rule: + r_id: 9187 + rv_id: 1263049 + rule_id: 0oU5j3 + version_id: JdTzxGb + url: https://semgrep.dev/playground/r/JdTzxGb/java.lang.security.audit.url-rewriting.url-rewriting + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeURL(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeUrl(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeRedirectURL(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeRedirectUrl(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeURL(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeUrl(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeRedirectURL(...); + ... + } + - pattern: |- + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeRedirectUrl(...); + ... + } +- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context + shortlink: https://sg.run/4x7E + semgrep.dev: + rule: + r_id: 9188 + rv_id: 1263050 + rule_id: KxUb1k + version_id: 5PTo1rW + url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context + origin: community + message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL + versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") + for the best security. + severity: WARNING + languages: + - java + patterns: + - pattern-not: SSLContext.getInstance("TLSv1.3") + - pattern-not: SSLContext.getInstance("TLSv1.2") + - pattern: SSLContext.getInstance("...") + fix-regex: + regex: (.*?)\.getInstance\(.*?\) + replacement: \1.getInstance("TLSv1.2") +- id: java.lang.security.audit.xml-decoder.xml-decoder + message: XMLDecoder should not be used to parse untrusted data. Deserializing user + input can lead to arbitrary code execution. Use an alternative and explicitly + disable external entities. See https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + for alternatives and vulnerability prevention. + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XML_DECODER + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xml-decoder.xml-decoder + shortlink: https://sg.run/PJjq + semgrep.dev: + rule: + r_id: 9189 + rv_id: 1263051 + rule_id: qNUj3y + version_id: GxTkeY1 + url: https://semgrep.dev/playground/r/GxTkeY1/java.lang.security.audit.xml-decoder.xml-decoder + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern: | + $X $METHOD(...) { + ... + new XMLDecoder(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + new XMLDecoder("..."); + ... + } + - pattern-not: |- + $X $METHOD(...) { + ... + String $STR = "..."; + ... + new XMLDecoder($STR); + ... + } +- id: java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_REQUEST_WRAPPER + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + shortlink: https://sg.run/J96Q + semgrep.dev: + rule: + r_id: 9190 + rv_id: 1263056 + rule_id: lBU9Gj + version_id: WrTqKGK + url: https://semgrep.dev/playground/r/WrTqKGK/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + origin: community + message: It looks like you're using an implementation of XSSRequestWrapper from + dzone. (https://www.javacodegeeks.com/2012/07/anti-cross-site-scripting-xss-filter.html) + The XSS filtering in this code is not secure and can be bypassed by malicious + actors. It is recommended to use a stack that automatically escapes in your view + or templates instead of filtering yourself. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + class XSSRequestWrapper extends HttpServletRequestWrapper { + ... + } + - pattern: |- + $P = $X.compile("", $X.CASE_INSENSITIVE); + $V = $P.matcher(...).replaceAll(""); +- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + message: DES is considered deprecated. AES is the recommended cipher. Upgrade to + use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + for more information. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + shortlink: https://sg.run/5Q73 + semgrep.dev: + rule: + r_id: 9191 + rv_id: 1262996 + rule_id: PeUZNg + version_id: A8TgdEn + url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") + - pattern-inside: $CIPHER.getInstance("DES") + - pattern-either: + - pattern: | + "=~/DES/.*/" + - pattern: | + "DES" + fix: | + "AES/GCM/NoPadding" + languages: + - java + - kt +- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended + cipher. Upgrade to use AES. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE + references: + - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + shortlink: https://sg.run/Geqn + semgrep.dev: + rule: + r_id: 9192 + rv_id: 1262997 + rule_id: JDUy8J + version_id: BjTkZyQ + url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $CIPHER.getInstance("=~/DESede.*/") + - pattern: | + $CRYPTO.KeyGenerator.getInstance("DES") + languages: + - java + - kt +- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + shortlink: https://sg.run/Ro9K + semgrep.dev: + rule: + r_id: 9193 + rv_id: 1262998 + rule_id: 5rUOb6 + version_id: DkTRbwL + url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + origin: community + message: Cipher in ECB mode is detected. ECB mode produces the same output for the + same input each time which allows an attacker to intercept and replay the data. + Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + severity: WARNING + languages: + - java + patterns: + - pattern: | + Cipher $VAR = $CIPHER.getInstance($MODE); + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* +- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + patterns: + - pattern-either: + - pattern: new NullCipher(...); + - pattern: new javax.crypto.NullCipher(...); + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + shortlink: https://sg.run/AvA4 + semgrep.dev: + rule: + r_id: 9194 + rv_id: 1263001 + rule_id: GdU7pw + version_id: K3TKkgB + url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + message: Initialization Vectors (IVs) for block ciphers should be randomly generated + each time they are used. Using a static IV means the same plaintext encrypts to + the same ciphertext every time, weakening the strength of the encryption. + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cwe.mitre.org/data/definitions/329.html + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + shortlink: https://sg.run/BkB5 + semgrep.dev: + rule: + r_id: 9195 + rv_id: 1263002 + rule_id: ReUgj1 + version_id: qkTR7vP + url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + byte[] $IV = { + ... + }; + ... + new IvParameterSpec($IV, ...); + - pattern: | + class $CLASS { + byte[] $IV = { + ... + }; + ... + $METHOD(...) { + ... + new IvParameterSpec($IV, ...); + ... + } + } +- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING + references: + - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + - kotlin + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + shortlink: https://sg.run/DoOj + semgrep.dev: + rule: + r_id: 9196 + rv_id: 1263003 + rule_id: AbUzoj + version_id: l4TJRpK + url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + origin: community + message: Using RSA without OAEP mode weakens the encryption. + severity: WARNING + languages: + - java + - kt + pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") +- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + metadata: + functional-categories: + - net::search::crypto-config::java.net + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + shortlink: https://sg.run/W8zA + semgrep.dev: + rule: + r_id: 9197 + rv_id: 1263008 + rule_id: BYUN3X + version_id: RGT0LEj + url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + origin: community + message: Detected use of a Java socket that is not encrypted. As a result, the traffic + could be read by an attacker intercepting the network traffic. Use an SSLSocket + created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. + severity: WARNING + languages: + - java + pattern-either: + - pattern: new ServerSocket(...) + - pattern: new Socket(...) +- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::key-length::java.security + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/4x6x + semgrep.dev: + rule: + r_id: 9200 + rv_id: 1263019 + rule_id: 0oU5P5 + version_id: o5TbDLY + url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern: | + KeyPairGenerator $KEY = $G.getInstance("RSA"); + ... + $KEY.initialize($BITS); + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 +- id: java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CUSTOM_MESSAGE_DIGEST + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#custom-algorithms + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests + shortlink: https://sg.run/PJ0p + semgrep.dev: + rule: + r_id: 9201 + rv_id: 1263004 + rule_id: KxUbW4 + version_id: YDTZewB + url: https://semgrep.dev/playground/r/YDTZewB/java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests + origin: community + message: 'Cryptographic algorithms are notoriously difficult to get right. By implementing + a custom message digest, you risk introducing security issues into your program. + Use one of the many sound message digests already available to you: MessageDigest + sha256Digest = MessageDigest.getInstance("SHA256");' + severity: WARNING + languages: + - java + pattern: |- + class $CLASS extends MessageDigest { + ... + } +- id: java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DEFAULT_HTTP_CLIENT + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.3 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + shortlink: https://sg.run/J9Gj + semgrep.dev: + rule: + r_id: 9202 + rv_id: 1263005 + rule_id: qNUj8b + version_id: JdTzxnb + url: https://semgrep.dev/playground/r/JdTzxnb/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + origin: community + message: DefaultHttpClient is deprecated. Further, it does not support connections + using TLS1.2, which makes using DefaultHttpClient a security hazard. Use HttpClientBuilder + instead. + severity: WARNING + languages: + - java + pattern: new DefaultHttpClient(...); + fix-regex: + regex: DefaultHttpClient + replacement: HttpClientBuilder +- id: java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + message: Insecure HostnameVerifier implementation detected. This will accept any + SSL certificate with any hostname, which creates the possibility for man-in-the-middle + attacks. + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_HOSTNAME_VERIFIER + asvs: + section: V9 Communications Verification Requirements + control_id: 9.2.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + shortlink: https://sg.run/5QoD + semgrep.dev: + rule: + r_id: 9203 + rv_id: 1263006 + rule_id: lBU9n8 + version_id: 5PTo17W + url: https://semgrep.dev/playground/r/5PTo17W/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + class $CLASS implements HostnameVerifier { + ... + public boolean verify(...) { return true; } + } + - pattern: |- + new HostnameVerifier(...){ + public boolean verify(...) { + return true; + } + } + - pattern: import org.apache.http.conn.ssl.NoopHostnameVerifier; +- id: java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_TRUST_MANAGER + asvs: + section: V9 Communications Verification Requirements + control_id: 9.2.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + references: + - https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + shortlink: https://sg.run/GePy + semgrep.dev: + rule: + r_id: 9204 + rv_id: 1263007 + rule_id: YGUR9A + version_id: GxTkel1 + url: https://semgrep.dev/playground/r/GxTkel1/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + origin: community + message: Detected empty trust manager implementations. This is dangerous because + it accepts any certificate, enabling man-in-the-middle attacks. Consider using + a KeyStore and TrustManagerFactory instead. See https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https + for more information. + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS implements X509TrustManager { + ... + } + - pattern-inside: | + new X509TrustManager() { + ... + } + - pattern-inside: | + class $CLASS implements X509ExtendedTrustManager { + ... + } + - pattern-inside: | + new X509ExtendedTrustManager() { + ... + } + - pattern-not: public void checkClientTrusted(...) { $SOMETHING; } + - pattern-not: public void checkServerTrusted(...) { $SOMETHING; } + - pattern-either: + - pattern: public void checkClientTrusted(...) {} + - pattern: public void checkServerTrusted(...) {} + - pattern: public X509Certificate[] getAcceptedIssuers(...) { return null; } +- id: java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli + pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $VAL $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: org.hibernate.criterion.Restrictions.sqlRestriction($SQL,...) + - pattern: org.hibernate.criterion.Restrictions.sqlRestriction(String.format(...),...) + - patterns: + - pattern: org.hibernate.criterion.Restrictions.sqlRestriction($X + $Y,...) + - pattern-not: org.hibernate.criterion.Restrictions.sqlRestriction("..." + "...",...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $TYPE $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $SESSION.$METHOD($SQL,...) + - pattern: | + $SESSION.$METHOD(String.format(...),...); + - pattern: | + $SESSION.$METHOD($X + $Y,...); + - pattern-either: + - pattern-inside: | + org.hibernate.Session $SESSION = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,org.hibernate.Session $SESSION,...) { + ... + } + - pattern-not: | + $SESSION.$METHOD("..." + "...",...); + - metavariable-regex: + metavariable: $METHOD + regex: ^(createQuery|createSQLQuery)$ + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION_HIBERNATE + asvs: + section: V5 Stored Cryptography Verification Requirements + control_id: 5.3.5 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - hibernate + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli + shortlink: https://sg.run/Roqg + semgrep.dev: + rule: + r_id: 9205 + rv_id: 1263035 + rule_id: 6JUjPD + version_id: e1Tyjbe + url: https://semgrep.dev/playground/r/e1Tyjbe/java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli + origin: community + languages: + - java + severity: WARNING +- id: java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $VAL $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $S.$METHOD($SQL,...) + - pattern: | + $S.$METHOD(String.format(...),...); + - pattern: | + $S.$METHOD($X + $Y,...); + - pattern-either: + - pattern-inside: | + java.sql.Statement $S = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,java.sql.Statement $S,...) { + ... + } + - pattern-not: | + $S.$METHOD("..." + "...",...); + - metavariable-regex: + metavariable: $METHOD + regex: ^(executeQuery|execute|executeUpdate|executeLargeUpdate|addBatch|nativeSQL)$ + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - jdbc + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli + shortlink: https://sg.run/AvkL + semgrep.dev: + rule: + r_id: 9206 + rv_id: 1263036 + rule_id: oqUe8K + version_id: vdT06oL + url: https://semgrep.dev/playground/r/vdT06oL/java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli + origin: community +- id: java.lang.security.audit.sqli.jdo-sqli.jdo-sqli + pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $TYPE $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $Q.$METHOD($SQL,...) + - pattern: | + $Q.$METHOD(String.format(...),...); + - pattern: | + $Q.$METHOD($X + $Y,...); + - pattern-either: + - pattern-inside: | + javax.jdo.Query $Q = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,javax.jdo.Query $Q,...) { + ... + } + - pattern-not: | + $Q.$METHOD("..." + "...",...); + - metavariable-regex: + metavariable: $METHOD + regex: ^(setFilter|setGrouping)$ + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $VAL $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $PM.newQuery(...,$SQL,...) + - pattern: | + $PM.newQuery(...,String.format(...),...); + - pattern: | + $PM.newQuery(...,$X + $Y,...); + - pattern-either: + - pattern-inside: | + javax.jdo.PersistenceManager $PM = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,javax.jdo.PersistenceManager $PM,...) { + ... + } + - pattern-not: | + $PM.newQuery(...,"..." + "...",...); + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - java + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.jdo-sqli.jdo-sqli + shortlink: https://sg.run/Bkwx + semgrep.dev: + rule: + r_id: 9207 + rv_id: 1263037 + rule_id: zdUk7l + version_id: d6Tyx77 + url: https://semgrep.dev/playground/r/d6Tyx77/java.lang.security.audit.sqli.jdo-sqli.jdo-sqli + origin: community +- id: java.lang.security.audit.sqli.jpa-sqli.jpa-sqli + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $TYPE $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $EM.$METHOD($SQL,...) + - pattern: | + $EM.$METHOD(String.format(...),...); + - pattern: | + $EM.$METHOD($X + $Y,...); + - pattern-either: + - pattern-inside: | + EntityManager $EM = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,EntityManager $EM,...) { + ... + } + - pattern-not: | + $EM.$METHOD("..." + "...",...); + - metavariable-regex: + metavariable: $METHOD + regex: ^(createQuery|createNativeQuery)$ + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - jpa + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.jpa-sqli.jpa-sqli + shortlink: https://sg.run/DoOd + semgrep.dev: + rule: + r_id: 9208 + rv_id: 1263038 + rule_id: pKUO7y + version_id: ZRTKAxW + url: https://semgrep.dev/playground/r/ZRTKAxW/java.lang.security.audit.sqli.jpa-sqli.jpa-sqli + origin: community +- id: java.lang.security.audit.sqli.turbine-sqli.turbine-sqli + pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $VAL $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $PEER.executeQuery($SQL,...) + - pattern: | + $PEER.executeQuery(String.format(...),...) + - pattern: | + $PEER.executeQuery($X + $Y,...) + - pattern-not: | + $PEER.executeQuery("..." + "...",...) + - metavariable-regex: + metavariable: $PEER + regex: (BasePeer|GroupPeer) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $VAL $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $P.executeQuery($SQL,...) + - pattern: | + $P.executeQuery(String.format(...),...) + - pattern: | + $P.executeQuery($X + $Y,...) + - pattern-either: + - pattern-inside: | + BasePeer $P = ...; + ... + - pattern-inside: | + GroupPeer $P = ...; + ... + - pattern-inside: | + $VAL $FUNC(...,GroupPeer $P,...) { + ... + } + - pattern-inside: | + $VAL $FUNC(...,BasePeer $P,...) { + ... + } + - pattern-not: | + $P.executeQuery("..." + "...",...) + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - turbine + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.turbine-sqli.turbine-sqli + shortlink: https://sg.run/W8zL + semgrep.dev: + rule: + r_id: 9209 + rv_id: 1263040 + rule_id: 2ZUbJ3 + version_id: ExTExvY + url: https://semgrep.dev/playground/r/ExTExvY/java.lang.security.audit.sqli.turbine-sqli.turbine-sqli + origin: community +- id: java.lang.security.audit.sqli.vertx-sqli.vertx-sqli + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + String $SQL = $X + $Y; + ... + - pattern-inside: | + String $SQL = String.format(...); + ... + - pattern-inside: | + $TYPE $FUNC(...,String $SQL,...) { + ... + } + - pattern-not-inside: | + String $SQL = "..." + "..."; + ... + - pattern: $SC.$METHOD($SQL,...) + - pattern: | + $SC.$METHOD(String.format(...),...); + - pattern: | + $SC.$METHOD($X + $Y,...); + - pattern-either: + - pattern-inside: | + SqlClient $SC = ...; + ... + - pattern-inside: | + SqlConnection $SC = ...; + ... + - pattern-inside: | + $TYPE $FUNC(...,SqlClient $SC,...) { + ... + } + - pattern-inside: | + $TYPE $FUNC(...,SqlConnection $SC,...) { + ... + } + - pattern-not: | + $SC.$METHOD("..." + "...",...); + - metavariable-regex: + metavariable: $METHOD + regex: ^(query|preparedQuery|prepare)$ + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - vertx + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.vertx-sqli.vertx-sqli + shortlink: https://sg.run/0QKB + semgrep.dev: + rule: + r_id: 9210 + rv_id: 1263041 + rule_id: X5U86z + version_id: 7ZTE3Z5 + url: https://semgrep.dev/playground/r/7ZTE3Z5/java.lang.security.audit.sqli.vertx-sqli.vertx-sqli + origin: community +- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + message: Detected a request with potential user-input going into a OutputStream + or Writer object. This bypasses any view or template environments, including HTML + escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. + Consider using a view technology such as JavaServer Faces (JSFs) which automatically + escapes HTML views. + severity: WARNING + options: + interfile: true + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html + subcategory: + - vuln + technology: + - java + - servlets + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + shortlink: https://sg.run/KlRL + semgrep.dev: + rule: + r_id: 9211 + rv_id: 1263055 + rule_id: j2Uv7B + version_id: DkTRbXy + url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + origin: community + languages: + - java + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...) + - pattern: | + (HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...) + - pattern: | + (java.io.PrintWriter $WRITER).$WRITE(...) + - pattern: | + (PrintWriter $WRITER).$WRITE(...) + - pattern: | + (javax.servlet.ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (java.io.OutputStream $WRITER).$WRITE(...) + - pattern: | + (OutputStream $WRITER).$WRITE(...) + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) + - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) + - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) + - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) +- id: java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled + message: Detected an element with disabled HTML escaping. If external data can reach + this, this is a cross-site scripting (XSS) vulnerability. Ensure no external data + can reach here, or remove 'escape=false' from this element. + metadata: + owasp: A07:2017 - Cross-Site Scripting (XSS) + cwe: + - 'CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences' + references: + - https://stackoverflow.com/a/7442668 + category: security + technology: + - jsf + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled + shortlink: https://sg.run/qxne + semgrep.dev: + rule: + r_id: 9212 + rv_id: 945709 + rule_id: 10UKqE + version_id: GxTP74Y + url: https://semgrep.dev/playground/r/GxTP74Y/java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled + origin: community + pattern-regex: .*escape.*?=.*?false.* + paths: + include: + - '*.html' + - '*.xhtml' + languages: + - regex + severity: WARNING +- id: java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://mogwailabs.de/blog/2019/03/attacking-java-rmi-services-after-jep-290/ + category: security + technology: + - rmi + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization + shortlink: https://sg.run/oxg6 + semgrep.dev: + rule: + r_id: 9216 + rv_id: 1263071 + rule_id: bwUwj4 + version_id: yeTxpeP + url: https://semgrep.dev/playground/r/yeTxpeP/java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization + origin: community + message: Using a non-primitive class with Java RMI may be an insecure deserialization + vulnerability. Depending on the underlying implementation. This object could be + manipulated by a malicious actor allowing them to execute code on your system. + Instead, use an integer ID to look up your object, or consider alternative serialization + schemes such as JSON. + patterns: + - pattern: | + interface $INTERFACE extends Remote { + $RETURNTYPE $METHOD($CLASS $PARAM) throws RemoteException; + } + - metavariable-regex: + metavariable: $CLASS + regex: (?!int|boolean|short|long|byte|char|float|double) +- id: java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + severity: ERROR + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://frohoff.github.io/appseccali-marshalling-pickles/ + - https://book.hacktricks.xyz/network-services-pentesting/1099-pentesting-java-rmi + - https://youtu.be/t_aw1mDNhzI + - https://github.com/qtc-de/remote-method-guesser + - https://github.com/openjdk/jdk/blob/master/src/java.rmi/share/classes/sun/rmi/server/UnicastRef.java#L303C4-L331 + category: security + technology: + - rmi + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + shortlink: https://sg.run/zvnl + semgrep.dev: + rule: + r_id: 9217 + rv_id: 1263072 + rule_id: NbUkw5 + version_id: rxTAKN2 + url: https://semgrep.dev/playground/r/rxTAKN2/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + origin: community + message: Using an arbitrary object ('$PARAMTYPE $PARAM') with Java RMI is an insecure + deserialization vulnerability. This object can be manipulated by a malicious actor + allowing them to execute code on your system. Instead, use an integer ID to look + up your object, or consider alternative serialization schemes such as JSON. + languages: + - java + patterns: + - pattern: | + interface $INTERFACE extends Remote { + $RETURNTYPE $METHOD($PARAMTYPE $PARAM) throws RemoteException; + } + - metavariable-pattern: + metavariable: $PARAMTYPE + language: generic + patterns: + - pattern-not: String + - pattern-not: java.lang.String + - pattern-not: boolean + - pattern-not: Boolean + - pattern-not: java.lang.Boolean + - pattern-not: byte + - pattern-not: Byte + - pattern-not: java.lang.Byte + - pattern-not: char + - pattern-not: Character + - pattern-not: java.lang.Character + - pattern-not: double + - pattern-not: Double + - pattern-not: java.lang.Double + - pattern-not: float + - pattern-not: Float + - pattern-not: java.lang.Float + - pattern-not: int + - pattern-not: Integer + - pattern-not: java.lang.Integer + - pattern-not: long + - pattern-not: Long + - pattern-not: java.lang.Long + - pattern-not: short + - pattern-not: Short + - pattern-not: java.lang.Short +- id: java.servlets.security.cookie-issecure-false.cookie-issecure-false + patterns: + - pattern: $COOKIE = new Cookie($...ARGS); + - pattern-not-inside: | + $COOKIE = new Cookie(...); + ... + $COOKIE.setSecure(...); + message: 'Default session middleware settings: `setSecure` not set to true. This + ensures that the cookie is sent only over HTTPS to prevent cross-site scripting + attacks.' + fix: | + $COOKIE = new Cookie($...ARGS); + $COOKIE.setSecure(true); + metadata: + vulnerability: Insecure Transport + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://docs.oracle.com/javaee/6/api/javax/servlet/http/Cookie.html#setSecure(boolean) + - https://owasp.org/www-community/controls/SecureCookieAttribute + category: security + technology: + - java + - cookie + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.servlets.security.cookie-issecure-false.cookie-issecure-false + shortlink: https://sg.run/pxn0 + semgrep.dev: + rule: + r_id: 9218 + rv_id: 1263073 + rule_id: kxUkn9 + version_id: bZT53lB + url: https://semgrep.dev/playground/r/bZT53lB/java.servlets.security.cookie-issecure-false.cookie-issecure-false + origin: community + languages: + - java + severity: WARNING +- id: java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + patterns: + - pattern-inside: | + @RequestMapping(...) + $RETURNTYPE $METHOD(...) { ... } + - pattern-not-inside: | + @RequestMapping(..., method = $X, ...) + $RETURNTYPE $METHOD(...) { ... } + - pattern: | + RequestMapping + message: Detected a method annotated with 'RequestMapping' that does not specify + the HTTP method. CSRF protections are not enabled for GET, HEAD, TRACE, or OPTIONS, + and by default all HTTP methods are allowed when the HTTP method is not explicitly + specified. This means that a method that performs state changes could be vulnerable + to CSRF attacks. To mitigate, add the 'method' field and specify the HTTP method + (such as 'RequestMethod.POST'). + severity: WARNING + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + references: + - https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + category: security + technology: + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + shortlink: https://sg.run/2xlq + semgrep.dev: + rule: + r_id: 9219 + rv_id: 1263089 + rule_id: wdUJ7q + version_id: QkTGq2l + url: https://semgrep.dev/playground/r/QkTGq2l/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + origin: community + languages: + - java +- id: java.spring.security.audit.spel-injection.spel-injection + message: A Spring expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPEL_INJECTION + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.spring.security.audit.spel-injection.spel-injection + shortlink: https://sg.run/XBp4 + semgrep.dev: + rule: + r_id: 9220 + rv_id: 1263075 + rule_id: x8Un7b + version_id: kbTzG5Y + url: https://semgrep.dev/playground/r/kbTzG5Y/java.spring.security.audit.spel-injection.spel-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS { + ... + ExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + ExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + class $CLASS { + ... + SpelExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + SpelExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + SpelExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + class $CLASS { + ... + TemplateAwareExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + TemplateAwareExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + TemplateAwareExpressionParser $PARSER = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $PARSER.parseExpression(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $PARSER.parseExpression("..."); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $PARSER.parseExpression($S); + ... + } +- id: java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + message: CSRF protection is disabled for this configuration. This is a security + risk. + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_PROTECTION_DISABLED + asvs: + section: V4 Access Control + control_id: 4.2.2 CSRF + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + version: '4' + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + shortlink: https://sg.run/jRnl + semgrep.dev: + rule: + r_id: 9221 + rv_id: 1263080 + rule_id: OrU3gK + version_id: vdT06dL + url: https://semgrep.dev/playground/r/vdT06dL/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + origin: community + severity: WARNING + languages: + - java + pattern: $OBJ.csrf(...).disable(...) +- id: java.spring.security.audit.spring-sqli.spring-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: $ARG + - pattern-inside: | + public $T $M (..., String $ARG,...){...} + pattern-sanitizers: + - not_conflicting: true + pattern-either: + - patterns: + - focus-metavariable: $A + - pattern-inside: | + new $TYPE(...,$A,...); + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - focus-metavariable: $A + - pattern: | + new PreparedStatementCreatorFactory($A,...); + - patterns: + - focus-metavariable: $A + - pattern: | + (JdbcTemplate $T).$M($A,...) + - patterns: + - pattern: (String $A) + - pattern-inside: | + (JdbcTemplate $T).batchUpdate(...) + - patterns: + - focus-metavariable: $A + - pattern: | + NamedParameterBatchUpdateUtils.$M($A,...) + - patterns: + - focus-metavariable: $A + - pattern: | + BatchUpdateUtils.$M($A,...) + message: Detected a string argument from a public method contract in a raw SQL statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You + can obtain a PreparedStatement using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - spring + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli + shortlink: https://sg.run/1Z3x + semgrep.dev: + rule: + r_id: 9222 + rv_id: 1263082 + rule_id: eqU8N2 + version_id: ZRTKAWW + url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli + origin: community +- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + message: Application redirects a user to a destination URL specified by a user supplied + parameter that is not validated. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + shortlink: https://sg.run/9oXz + semgrep.dev: + rule: + r_id: 9223 + rv_id: 1263083 + rule_id: v8Un7w + version_id: nWT2Lk0 + url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,String $URL,...) { + return "redirect:" + $URL; + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + return $REDIR; + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + new ModelAndView("redirect:" + $URL); + ... + } + - pattern: |- + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + new ModelAndView($REDIR); + ... + } +- id: javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods + message: Use of angular.element can lead to XSS if user-input is treated as part + of the HTML element within `$SINK`. It is recommended to contextually output encode + user-input, before inserting into `$SINK`. If the HTML needs to be preserved it + is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + confidence: LOW + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - angularjs + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods + shortlink: https://sg.run/ydnO + semgrep.dev: + rule: + r_id: 9224 + rv_id: 1263090 + rule_id: d8Ujdo + version_id: 3ZT4Xbz + url: https://semgrep.dev/playground/r/3ZT4Xbz/javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods + origin: community + languages: + - javascript + - typescript + severity: INFO + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + function(..., $SCOPE, ...) { ... } + - focus-metavariable: $SCOPE + - metavariable-regex: + metavariable: $SCOPE + regex: ^\$scope$ + - pattern: $rootScope + - pattern: $injector.get('$rootScope') + - pattern: $injector.get('$scope') + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + angular.element(...). ... .$SINK($QUERY) + - pattern-inside: | + $ANGULAR = angular.element(...) + ... + $ANGULAR. ... .$SINK($QUERY) + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) +- id: javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading + message: $sceDelegateProvider allowlisting can introduce security issues if wildcards + are used. + metadata: + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsJs + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading + shortlink: https://sg.run/b7kd + semgrep.dev: + rule: + r_id: 9226 + rv_id: 1263093 + rule_id: nJUzgX + version_id: JdTzxKb + url: https://semgrep.dev/playground/r/JdTzxKb/javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern-either: + - pattern: | + $sceDelegateProvider.resourceUrlWhitelist([...,'**',...]); + - patterns: + - pattern: | + $sceDelegateProvider.resourceUrlWhitelist([...,$DOM,...]); + - metavariable-regex: + metavariable: $DOM + regex: ^'.*\*\*.+'$ +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) + in an AngularJS application could provide additional attack surface for XSS vulnerabilities. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + shortlink: https://sg.run/N4DG + semgrep.dev: + rule: + r_id: 9227 + rv_id: 1263094 + rule_id: EwU20Z + version_id: 5PTo1EW + url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern: | + $sceProvider.enabled(false); +- id: javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method + message: The use of $sce.trustAsCss can be dangerous if unsanitized user input flows + through this API. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsCss + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method + shortlink: https://sg.run/kXgo + semgrep.dev: + rule: + r_id: 9228 + rv_id: 1263095 + rule_id: 7KUQ4k + version_id: GxTkeB1 + url: https://semgrep.dev/playground/r/GxTkeB1/javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SOURCE = $scope.$INPUT; + $sce.trustAsCss($SOURCE); + - pattern: | + $sce.trustAsCss($scope.$INPUT); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method + message: The use of $sce.trustAsHtml can be dangerous if unsanitized user input + flows through this API. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsHtml + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method + shortlink: https://sg.run/wenn + semgrep.dev: + rule: + r_id: 9229 + rv_id: 1263096 + rule_id: L1Uy88 + version_id: RGT0L9j + url: https://semgrep.dev/playground/r/RGT0L9j/javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SOURCE = $scope.$INPUT; + $sce.trustAsHtml($SOURCE); + - pattern: | + $sce.trustAsHtml($scope.$INPUT); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method + message: The use of $sce.trustAsJs can be dangerous if unsanitized user input flows + through this API. + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsJs + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + category: security + technology: + - angular + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method + shortlink: https://sg.run/x1nA + semgrep.dev: + rule: + r_id: 9230 + rv_id: 1263097 + rule_id: 8GUj8k + version_id: A8Tgdpo + url: https://semgrep.dev/playground/r/A8Tgdpo/javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SOURCE = $scope.$INPUT; + $sce.trustAsJs($SOURCE); + - pattern: | + $sce.trustAsJs($scope.$INPUT); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + message: The use of $sce.trustAs can be dangerous if unsanitized user input flows + through this API. + metadata: + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + shortlink: https://sg.run/OPW2 + semgrep.dev: + rule: + r_id: 9231 + rv_id: 1263098 + rule_id: gxU1QX + version_id: BjTkZv0 + url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + app.controller(..., function($scope,$sce) { + ... + }); + - pattern: $scope.$X + pattern-sinks: + - pattern: $sce.trustAs(...) + - pattern: $sce.trustAsHtml(...) +- id: javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method + message: The use of $sce.trustAsResourceUrl can be dangerous if unsanitized user + input flows through this API. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsResourceUrl + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method + shortlink: https://sg.run/eLOd + semgrep.dev: + rule: + r_id: 9232 + rv_id: 1263099 + rule_id: QrUzeq + version_id: DkTRb7y + url: https://semgrep.dev/playground/r/DkTRb7y/javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SOURCE = $scope.$INPUT; + $sce.trustAsResourceUrl($SOURCE); + - pattern: | + $sce.trustAsResourceUrl($scope.$INPUT); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method + message: The use of $sce.trustAsUrl can be dangerous if unsanitized user input flows + through this API. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsUrl + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method + shortlink: https://sg.run/vznl + semgrep.dev: + rule: + r_id: 9233 + rv_id: 1263100 + rule_id: 3qUP01 + version_id: WrTqKJK + url: https://semgrep.dev/playground/r/WrTqKJK/javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SOURCE = $scope.$INPUT; + $sce.trustAsUrl($SOURCE); + - pattern: | + $sce.trustAsUrl($scope.$INPUT); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method + message: The use of $translateProvider.translations method can be dangerous if user + input is provided to this API. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/service/$sce#trustAsUrl + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + - typescript + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method + shortlink: https://sg.run/ZvXp + semgrep.dev: + rule: + r_id: 9235 + rv_id: 1263101 + rule_id: PeUZPg + version_id: 0bTKzqX + url: https://semgrep.dev/playground/r/0bTKzqX/javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method + origin: community + languages: + - javascript + severity: WARNING + patterns: + - pattern: | + $translateProvider.translations(...,$SOURCE); + - pattern-inside: | + app.controller(..., function($scope,$sce){ + ... + }); +- id: javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution + message: Potential arbitrary code execution, whatever is provided to `toFastProperties` + is sent straight to eval() + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - bluebird + references: + - http://bluebirdjs.com/docs/getting-started.html + cwe2022-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution + shortlink: https://sg.run/ndnZ + semgrep.dev: + rule: + r_id: 9236 + rv_id: 1263115 + rule_id: JDUy9J + version_id: K3TKkQ7 + url: https://semgrep.dev/playground/r/K3TKkQ7/javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: function ... (..., $ARG,...) {...} + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $UTIL.toFastProperties($SINK,...) + - pattern: toFastProperties($SINK,...) + - pattern-either: + - pattern-inside: | + $BB = require('bluebird'); + ... + - pattern-inside: | + import 'bluebird'; + ... + - focus-metavariable: $SINK +- id: javascript.browser.security.eval-detected.eval-detected + message: Detected the use of eval(). eval() can be dangerous if used to evaluate + dynamic content. If this content can be input from outside the program, this may + be a code injection vulnerability. Ensure evaluated content is not definable by + external sources. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.2.4 Dynamic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing + version: '4' + category: security + technology: + - browser + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.browser.security.eval-detected.eval-detected + shortlink: https://sg.run/7ope + semgrep.dev: + rule: + r_id: 9238 + rv_id: 1263117 + rule_id: GdU7dw + version_id: l4TJR2y + url: https://semgrep.dev/playground/r/l4TJR2y/javascript.browser.security.eval-detected.eval-detected + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-not: eval("...") + - pattern: eval(...) +- id: javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation + message: No validation of origin is done by the addEventListener API. It may be + possible to exploit this flaw to perform Cross Origin attacks such as Cross-Site + Scripting(XSS). + metadata: + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + category: security + technology: + - browser + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation + shortlink: https://sg.run/gL9x + semgrep.dev: + rule: + r_id: 9241 + rv_id: 1263120 + rule_id: BYUN0X + version_id: o5TbDRl + url: https://semgrep.dev/playground/r/o5TbDRl/javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern-either: + - patterns: + - pattern: | + window.addEventListener('message', $FUNC, ...) + - metavariable-pattern: + patterns: + - pattern: | + function($OBJ) { ... } + - pattern-not: | + function($OBJ) { ... if (<... $OBJ.origin ...>) { ... } ... } + metavariable: $FUNC + - patterns: + - pattern-either: + - pattern-inside: | + function $FNAME($OBJ) { $CONTEXT } + ... + - pattern-inside: | + $FNAME = (...) => { $CONTEXT } + ... + - pattern: | + window.addEventListener('message', $FNAME,...) + - metavariable-pattern: + patterns: + - pattern-not: | + ... if (<... $OBJ.origin ...>) { ... } ... + metavariable: $CONTEXT +- id: javascript.browser.security.open-redirect.js-open-redirect + message: The application accepts potentially user-controlled input `$PROP` which + can control the location of the current window context. This can lead two types + of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript + URIs. It is recommended to validate user-controllable input before allowing it + to control the redirection. + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.1 Insecue Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + version: '4' + category: security + confidence: HIGH + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + technology: + - browser + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect + shortlink: https://sg.run/3xRe + semgrep.dev: + rule: + r_id: 9243 + rv_id: 1263122 + rule_id: WAUopl + version_id: pZT03x0 + url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + new URLSearchParams($WINDOW. ... .location.search).get('...') + - pattern: | + new URLSearchParams(location.search).get('...') + - pattern: | + new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') + - pattern: | + new URLSearchParams(location.hash.substring(1)).get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.hash.substring(1)) + ... + - pattern: $PROPS.get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URL($WINDOW. ... .location.href) + ... + - pattern-inside: | + $PROPS = new URL(location.href) + ... + - pattern: $PROPS.searchParams.get('...') + - patterns: + - pattern-either: + - pattern: | + new URL($WINDOW. ... .location.href).searchParams.get('...') + - pattern: | + new URL(location.href).searchParams.get('...') + pattern-sinks: + - patterns: + - pattern-either: + - pattern: location.href = $SINK + - pattern: $THIS. ... .location.href = $SINK + - pattern: location.replace($SINK) + - pattern: $THIS. ... .location.replace($SINK) + - pattern: location = $SINK + - pattern: $WINDOW. ... .location = $SINK + - focus-metavariable: $SINK + - metavariable-pattern: + patterns: + - pattern-not: | + "..." + $VALUE + - pattern-not: | + `...${$VALUE}` + metavariable: $SINK +- id: javascript.browser.security.raw-html-concat.raw-html-concat + message: User controlled data in a HTML string may result in XSS + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/xss/ + category: security + technology: + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat + shortlink: https://sg.run/4xAx + semgrep.dev: + rule: + r_id: 9244 + rv_id: 1263123 + rule_id: 0oU5b5 + version_id: 2KTv2wp + url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $STRING + $EXPR + - pattern-not: $STRING + "..." + - metavariable-pattern: + patterns: + - pattern: <$TAG ... + - pattern-not: <$TAG ...>...... + metavariable: $STRING + language: generic + - patterns: + - pattern: $EXPR + $STRING + - pattern-not: '"..." + $STRING' + - metavariable-pattern: + patterns: + - pattern: '... + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('node-expat') + ... + - pattern-inside: | + import $XML from 'node-expat' + ... + - pattern-inside: | + import * as $XML from 'node-expat' + ... + - pattern-either: + - pattern-inside: | + $PARSER = new $XML.Parser(...); + ... + - pattern-either: + - pattern: $PARSER.parse($QUERY) + - pattern: $PARSER.write($QUERY) + - focus-metavariable: $QUERY +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + shortlink: https://sg.run/Do1d + semgrep.dev: + rule: + r_id: 9252 + rv_id: 1263166 + rule_id: pKUOjy + version_id: pZT03Q0 + url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern-inside: | + import $JWT from 'express-jwt'; + ... + - pattern-inside: | + import * as $JWT from 'express-jwt'; + ... + - pattern-inside: | + import { ..., $JWT, ... } from 'express-jwt'; + ... + - pattern-either: + - pattern: | + $JWT({...,secret: "$Y",...},...) + - pattern: | + $OPTS = "$Y"; + ... + $JWT({...,secret: $OPTS},...); + - focus-metavariable: $Y +- id: javascript.express.security.express-phantom-injection.express-phantom-injection + message: If unverified user data can reach the `phantom` methods it can result in + Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://phantomjs.org/page-automation.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection + shortlink: https://sg.run/W8BL + semgrep.dev: + rule: + r_id: 9253 + rv_id: 1263167 + rule_id: 2ZUbx3 + version_id: 2KTv26p + url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('phantom'); + ... + - pattern-inside: | + import 'phantom'; + ... + - pattern-either: + - pattern: $PAGE.open($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.openUrl($SINK,...) + - pattern: $PAGE.evaluateJavaScript($SINK,...) + - pattern: $PAGE.property("content",$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + message: If unverified user data can reach the `puppeteer` methods it can result + in Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://pptr.dev/api/puppeteer.page + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + shortlink: https://sg.run/0QJB + semgrep.dev: + rule: + r_id: 9254 + rv_id: 1263168 + rule_id: X5U8Nz + version_id: X0TzyJY + url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('puppeteer'); + ... + - pattern-inside: | + import 'puppeteer'; + ... + - pattern-either: + - pattern: $PAGE.goto($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.evaluate($SINK,...) + - pattern: $PAGE.evaluate($CODE,$SINK,...) + - pattern: $PAGE.evaluateHandle($SINK,...) + - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + message: Make sure that unverified user data can not reach `sandbox`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + shortlink: https://sg.run/KlwL + semgrep.dev: + rule: + r_id: 9255 + rv_id: 1263169 + rule_id: j2UvXB + version_id: jQTn59D + url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $SANDBOX = require('sandbox'); + ... + - pattern-either: + - patterns: + - pattern-inside: | + $S = new $SANDBOX(...); + ... + - pattern: | + $S.run(...) + - pattern: | + new $SANDBOX($OPTS).run(...) + - pattern: new $SANDBOX().run(...) +- id: javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection + message: If unverified user data can reach the `phantom` methods it can result in + Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/wkhtmltopdf + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection + shortlink: https://sg.run/pxe0 + semgrep.dev: + rule: + r_id: 9262 + rv_id: 1263172 + rule_id: kxUkl9 + version_id: yeTxpdd + url: https://semgrep.dev/playground/r/yeTxpdd/javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection + origin: community + severity: ERROR + languages: + - javascript + - typescript + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern: $WK.generate($SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection + message: If unverified user data can reach the `wkhtmltopdf` methods it can result + in Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/wkhtmltopdf + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection + shortlink: https://sg.run/2xGq + semgrep.dev: + rule: + r_id: 9263 + rv_id: 1263173 + rule_id: wdUJxq + version_id: rxTAK8b + url: https://semgrep.dev/playground/r/rxTAK8b/javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $WK = require('wkhtmltopdf'); + ... + - pattern: $WK($SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + message: Make sure that unverified user data can not reach the XML Parser, as it + can result in XML External or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + shortlink: https://sg.run/XBD4 + semgrep.dev: + rule: + r_id: 9264 + rv_id: 1263174 + rule_id: x8Uneb + version_id: bZT534J + url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $EXPAT.toJson($SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.require-request.require-request + message: If an attacker controls the x in require(x) then they can cause code to + load that was not intended to run on the server. + options: + interfile: true + metadata: + interfile: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html + category: security + technology: + - express + references: + - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/javascript.express.security.require-request.require-request + shortlink: https://sg.run/jRbl + semgrep.dev: + rule: + r_id: 9265 + rv_id: 1263177 + rule_id: OrU3WK + version_id: w8TRo0d + url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern: require($SINK) + - focus-metavariable: $SINK +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + message: "Don\u2019t use the default session cookie name Using the default session + cookie name can open your app to attacks. The security issue posed is similar + to X-Powered-By: a potential attacker can use it to fingerprint the server and + target attacks accordingly." + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + shortlink: https://sg.run/1Z5x + semgrep.dev: + rule: + r_id: 9266 + rv_id: 1263130 + rule_id: eqU8k2 + version_id: bZT536J + url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {name:...} ...>,...) + - pattern-not-inside: | + $OPTS = <... {name:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.name = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + message: 'Default session middleware settings: `secure` not set. It ensures the + browser only sends the cookie over HTTPS.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + shortlink: https://sg.run/9oKz + semgrep.dev: + rule: + r_id: 9267 + rv_id: 1263131 + rule_id: v8Unzw + version_id: NdTzyrv + url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{secure:true}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {secure:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {secure:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.secure = true; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.secure = true; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + message: 'Default session middleware settings: `httpOnly` not set. It ensures the + cookie is sent only over HTTP(S), not client JavaScript, helping to protect against + cross-site scripting attacks.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + shortlink: https://sg.run/ydBO + semgrep.dev: + rule: + r_id: 9268 + rv_id: 1263132 + rule_id: d8UjGo + version_id: kbTzGev + url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{httpOnly:true}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {httpOnly:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {httpOnly:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.httpOnly = true; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.httpOnly = true; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + message: 'Default session middleware settings: `domain` not set. It indicates the + domain of the cookie; use it to compare against the domain of the server in which + the URL is being requested. If they match, then check the path attribute next.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + shortlink: https://sg.run/rd41 + semgrep.dev: + rule: + r_id: 9269 + rv_id: 1263133 + rule_id: ZqU5Pn + version_id: w8TRoyd + url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{domain:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {domain:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {domain:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.domain = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.domain = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + message: 'Default session middleware settings: `path` not set. It indicates the + path of the cookie; use it to compare against the request path. If this and domain + match, then send the cookie in the request.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + shortlink: https://sg.run/b7pd + semgrep.dev: + rule: + r_id: 9270 + rv_id: 1263134 + rule_id: nJUz4X + version_id: xyTjzQD + url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{path:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {path:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {path:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.path = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.path = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + message: 'Default session middleware settings: `expires` not set. Use it to set + expiration date for persistent cookies.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + shortlink: https://sg.run/N4eG + semgrep.dev: + rule: + r_id: 9271 + rv_id: 1263135 + rule_id: EwU2DZ + version_id: O9TpxRq + url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{expires:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {expires:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {expires:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.expires = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: |- + $OPTS = ...; + ... + $OPTS.cookie.expires = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + message: No token revoking configured for `express-jwt`. A leaked token could still + be used and unable to be revoked. Consider using function as the `isRevoked` option. + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecure Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + shortlink: https://sg.run/kXNo + semgrep.dev: + rule: + r_id: 9272 + rv_id: 1263137 + rule_id: 7KUQ9k + version_id: vdT06Bg + url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern: $JWT(...) + - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) + - pattern-not-inside: |- + $OPTS = <... {isRevoked:...} ...>; + ... + $JWT($OPTS,...); +- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + message: Possible writing outside of the destination, make sure that the target + path is nested in the intended destination + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + category: security + references: + - https://owasp.org/www-community/attacks/Path_Traversal + technology: + - express + - node.js + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + shortlink: https://sg.run/weRn + semgrep.dev: + rule: + r_id: 9273 + rv_id: 1263141 + rule_id: L1Uyb8 + version_id: ExTExX0 + url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern-inside: | + $PATH = require('path'); + ... + - pattern-inside: | + import $PATH from 'path'; + ... + - pattern-either: + - pattern: $PATH.join(...,$SINK,...) + - pattern: $PATH.resolve(...,$SINK,...) + - patterns: + - focus-metavariable: $SINK + - pattern-inside: | + import 'path'; + ... + - pattern-either: + - pattern: path.join(...,$SINK,...) + - pattern: path.resolve(...,$SINK,...) + pattern-sanitizers: + - pattern: $Y.replace(...) + - pattern: $Y.indexOf(...) + - pattern: | + function ... (...) { + ... + <... $Y.indexOf(...) ...> + ... + } + - patterns: + - pattern: $FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: sanitize +- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + message: Xml Parser is used inside Request Event. Make sure that unverified user + data can not reach the XML Parser, as it can result in XML External or Internal + Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + shortlink: https://sg.run/x1AA + semgrep.dev: + rule: + r_id: 9274 + rv_id: 1263146 + rule_id: 8GUjkk + version_id: QkTGqgo + url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) + - focus-metavariable: $INPUT +- id: javascript.express.security.audit.res-render-injection.res-render-injection + message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to + the loading of other HTML/templating pages that they may not be authorized to + render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index` + to access other HTML pages on the file system. Where possible, do not allow users + to define what should be loaded in $RES.render or use an allow list for the existing + application. + options: + interfile: true + metadata: + interfile: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + category: security + technology: + - express + references: + - http://expressjs.com/en/4x/api.html#res.render + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection + shortlink: https://sg.run/eLjd + semgrep.dev: + rule: + r_id: 9276 + rv_id: 1263149 + rule_id: QrUzrq + version_id: PkTR3OY + url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.render($SINK, ...) + - focus-metavariable: $SINK +- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write + message: Detected directly writing to a Response object from user-defined input. + This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting + (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + vulnerability_class: + - Cross-Site-Scripting (XSS) + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write + shortlink: https://sg.run/vzGl + semgrep.dev: + rule: + r_id: 9277 + rv_id: 1263150 + rule_id: 3qUPA1 + version_id: JdTzxeg + url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.set('$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.set('$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.set('$TYPE') + } + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response) => { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.set('$TYPE') + } + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: function ... (..., $RES,...) {...} + - pattern-either: + - pattern: $RES.write($ARG) + - pattern: $RES.send($ARG) + - pattern-not: $RES. ... .set('...'). ... .send($ARG) + - pattern-not: $RES. ... .type('...'). ... .send($ARG) + - pattern-not-inside: $RES.$METHOD({ ... }) + - focus-metavariable: $ARG + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'express-xss-sanitizer'; + ... + - pattern-inside: | + import * as $S from "express-xss-sanitizer"; + ... + - pattern-inside: | + const { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + var { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + let { ...,$S,... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + $S = require("express-xss-sanitizer") + ... + - pattern: $S(...) + - patterns: + - pattern: $RES. ... .type('$F'). ... .send(...) + - metavariable-regex: + metavariable: $F + regex: (?!.*text/html) + - patterns: + - pattern-inside: | + $X = [...]; + ... + - pattern: | + if(<... !$X.includes($SOURCE)...>) { + ... + return ... + } + ... + - pattern: $SOURCE +- id: javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape + message: Detected an explicit unescape in an EJS template, using '<%- ... %>' If + external data can reach these locations, your application is exposed to a cross-site + scripting (XSS) vulnerability. Use '<%= ... %>' to escape this data. If you need + escaping, ensure no external data can reach this location. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - http://www.managerjs.com/blog/2015/05/will-ejs-escape-save-me-from-xss-sorta/ + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape + shortlink: https://sg.run/dKXQ + semgrep.dev: + rule: + r_id: 9278 + rv_id: 1263151 + rule_id: 4bUkPO + version_id: 5PTo13n + url: https://semgrep.dev/playground/r/5PTo13n/javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape + origin: community + languages: + - regex + severity: WARNING + paths: + include: + - '*.ejs' + - '*.html' + pattern-regex: <%-((?!include).)*?%> + fix-regex: + regex: <%-(.*?)%> + replacement: <%=\1%> +- id: javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src + message: Detected a template variable used as the 'src' in a script tag. Although + template variables are HTML escaped, HTML escaping does not always prevent malicious + URLs from being injected and could results in a cross-site scripting (XSS) vulnerability. + Prefer not to dynamically generate the 'src' attribute and use static URLs instead. + If you must do this, carefully check URLs against an allowlist and be sure to + URL-encode the result. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.veracode.com/blog/secure-development/nodejs-template-engines-why-default-encoders-are-not-enough + - https://github.com/ESAPI/owasp-esapi-js + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src + shortlink: https://sg.run/ndxZ + semgrep.dev: + rule: + r_id: 9280 + rv_id: 1263153 + rule_id: JDUyrJ + version_id: RGT0LwD + url: https://semgrep.dev/playground/r/RGT0LwD/javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src + origin: community + languages: + - generic + severity: WARNING + patterns: + - pattern-inside: + - pattern-not-inside: + - pattern-not: <%= j ... > + - pattern-not: <%= escape_javascript ... > + - pattern: <%= ... > +- id: terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push + patterns: + - pattern: resource + - pattern-not-inside: | + resource "aws_ecr_repository" "..." { + ... + image_scanning_configuration { + ... + scan_on_push=true + ... + } + ... + } + - pattern-inside: | + resource "aws_ecr_repository" "..." { + ... + } + languages: + - hcl + message: The ECR Repository isn't configured to scan images on push + severity: WARNING + metadata: + cwe: + - 'CWE-1104: Use of Unmaintained Third Party Components' + category: security + technology: + - terraform + - aws + owasp: + - A06:2021 - Vulnerable and Outdated Components + - A03:2025 - Software Supply Chain Failures + references: + - https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push + shortlink: https://sg.run/R8eE + semgrep.dev: + rule: + r_id: 9749 + rv_id: 1263885 + rule_id: 0oUELR + version_id: xyTjzzO + url: https://semgrep.dev/playground/r/xyTjzzO/terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push + origin: community +- id: terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled + patterns: + - pattern: | + resource + - pattern-inside: | + resource "aws_eks_cluster" "..." {...} + - pattern-not-inside: | + resource "aws_eks_cluster" "..."{ + ... + vpc_config{ + ... + endpoint_public_access = false + ... + } + ... + } + languages: + - hcl + message: The vpc_config resource inside the eks cluster has not explicitly disabled + public endpoint access + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled + shortlink: https://sg.run/Albg + semgrep.dev: + rule: + r_id: 9750 + rv_id: 1263887 + rule_id: KxU4v6 + version_id: e1TyjjB + url: https://semgrep.dev/playground/r/e1TyjjB/terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled + origin: community +- id: terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest + patterns: + - pattern: | + resource + - pattern-not-inside: | + resource "aws_elasticsearch_domain" "..."{ + ... + encrypt_at_rest{ + ... + enabled = true + ... + } + ... + } + - pattern-inside: | + resource "aws_elasticsearch_domain" "..." {...} + languages: + - hcl + message: Encryption at rest is not enabled for the elastic search domain resource + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest + shortlink: https://sg.run/B4Yb + semgrep.dev: + rule: + r_id: 9751 + rv_id: 1263888 + rule_id: qNUo2d + version_id: vdT066y + url: https://semgrep.dev/playground/r/vdT066y/terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest + origin: community +- id: terraform.lang.security.s3-cors-all-origins.all-origins-allowed + patterns: + - pattern-inside: cors_rule { ... } + - pattern: allowed_origins = ["*"] + languages: + - hcl + severity: WARNING + message: CORS rule on bucket permits any origin + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#using-cors + cwe: + - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' + category: security + technology: + - terraform + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/terraform.lang.security.s3-cors-all-origins.all-origins-allowed + shortlink: https://sg.run/DJb2 + semgrep.dev: + rule: + r_id: 9752 + rv_id: 1263898 + rule_id: lBUd4g + version_id: 3ZT4XXJ + url: https://semgrep.dev/playground/r/3ZT4XXJ/terraform.lang.security.s3-cors-all-origins.all-origins-allowed + origin: community +- id: terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket + patterns: + - pattern-either: + - pattern: acl = "public-read" + - pattern: acl = "authenticated-read" + - pattern-not-inside: | + resource "aws_s3_bucket" "..." { + ... + website { ... } + ... + } + languages: + - hcl + severity: WARNING + message: S3 bucket with public read access detected. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl + - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket + shortlink: https://sg.run/WgAy + semgrep.dev: + rule: + r_id: 9753 + rv_id: 1263899 + rule_id: YGUrp5 + version_id: 44TEjjv + url: https://semgrep.dev/playground/r/44TEjjv/terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket + origin: community +- id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + pattern: acl = "public-read-write" + languages: + - hcl + severity: ERROR + message: S3 bucket with public read-write access detected. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl + - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + shortlink: https://sg.run/0nok + semgrep.dev: + rule: + r_id: 9754 + rv_id: 1263900 + rule_id: 6JUqvn + version_id: PkTR3y5 + url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + origin: community +- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting + (XSS) vulnerability if this comes from user-provided input. If you have to use + `$TRUST`, ensure it does not come from user-input or use the appropriate prevention + mechanism e.g. input validation or sanitization depending on the context. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://angular.io/api/platform-browser/DomSanitizer + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + confidence: MEDIUM + category: security + technology: + - angular + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + shortlink: https://sg.run/KWxP + semgrep.dev: + rule: + r_id: 9755 + rv_id: 1263902 + rule_id: oqUzgA + version_id: 5PTo1zk + url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + origin: community + languages: + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X: string, ...}) { ... } + - pattern-inside: | + function ...(..., $X: string, ...) { ... } + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.$TRUST($Y) + - focus-metavariable: $Y + - pattern-not: | + $X.$TRUST(`...`) + - pattern-not: | + $X.$TRUST("...") + - metavariable-regex: + metavariable: $TRUST + regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern: sanitizer.sanitize(...) + - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); +- id: typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any + message: Access-Control-Allow-Origin response header is set to "*". This will disable + CORS Same Origin Policy restrictions. + metadata: + cwe: + - 'CWE-183: Permissive List of Allowed Inputs' + asvs: + section: 'V14: Configuration Verification Requirements' + control_id: 14.4.8 Permissive CORS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x22-V14-Config.md#v144-http-security-headers-requirements + version: '4' + category: security + technology: + - nestjs + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any + shortlink: https://sg.run/ljBL + semgrep.dev: + rule: + r_id: 9757 + rv_id: 1263909 + rule_id: pKUG17 + version_id: 0bTKzXw + url: https://semgrep.dev/playground/r/0bTKzXw/typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any + origin: community + languages: + - typescript + severity: WARNING + pattern-either: + - pattern: | + class $CN { + @Header("=~/[Aa][Cc][Cc][Ee][Ss][Ss]-[Cc][Oo][Nn][Tt][Rr][Oo][Ll]-[Aa][Ll][Ll][Oo][Ww]-[Oo][Rr][Ii][Gg][Ii][Nn]/", '*') + $FN(...) { + ... + } + } + - pattern: | + NestFactory.create($MODULE, {cors: true}) + - pattern: | + NestFactory.create($MODULE, {cors: {origin: '*'}}) + - pattern: | + $APP.enableCors() + - pattern: | + $APP.enableCors({origin: '*'}) +- id: typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled + message: X-XSS-Protection header is set to 0. This will disable the browser's XSS + Filter. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + category: security + technology: + - nestjs + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled + shortlink: https://sg.run/YgGW + semgrep.dev: + rule: + r_id: 9758 + rv_id: 1263910 + rule_id: 2ZU4zx + version_id: K3TKkXw + url: https://semgrep.dev/playground/r/K3TKkXw/typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled + origin: community + languages: + - typescript + severity: WARNING + pattern: | + class $CN { + ... + @Header("=~/[Xx]-[Xx][Ss][Ss]-[Pp][Rr][Oo][Tt][Ee][Cc][Tt][Ii][Oo][Nn]/", '0') + $FN(...) { + ... + } + ... + } +- id: typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect + message: 'Untrusted user input in {url: ...} can result in Open Redirect vulnerability.' + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + category: security + technology: + - nestjs + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect + shortlink: https://sg.run/6rJw + semgrep.dev: + rule: + r_id: 9759 + rv_id: 1263911 + rule_id: X5UZQK + version_id: qkTR7y4 + url: https://semgrep.dev/playground/r/qkTR7y4/typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect + origin: community + languages: + - typescript + severity: WARNING + patterns: + - pattern: | + return {url: $URL} + - pattern-inside: | + class $CN { + @Redirect(...) + $FN(...) { + ... + } + } + - pattern-not: | + return {url: "..."} +- id: typescript.react.security.react-insecure-request.react-insecure-request + message: Unencrypted request over HTTP detected. + metadata: + vulnerability: Insecure Transport + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://www.npmjs.com/package/axios + category: security + technology: + - react + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request + shortlink: https://sg.run/1n0b + semgrep.dev: + rule: + r_id: 9766 + rv_id: 1263918 + rule_id: NbUA3O + version_id: A8Tgd2p + url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request + origin: community + languages: + - typescript + - javascript + severity: ERROR + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + import $AXIOS from 'axios'; + ... + $AXIOS.$METHOD(...) + - pattern-inside: | + $AXIOS = require('axios'); + ... + $AXIOS.$METHOD(...) + - pattern: $AXIOS.$VERB("$URL",...) + - metavariable-regex: + metavariable: $VERB + regex: ^(get|post|delete|head|patch|put|options) + - patterns: + - pattern-either: + - pattern-inside: | + import $AXIOS from 'axios'; + ... + $AXIOS(...) + - pattern-inside: | + $AXIOS = require('axios'); + ... + $AXIOS(...) + - pattern-either: + - pattern: '$AXIOS({url: "$URL"}, ...)' + - pattern: | + $OPTS = {url: "$URL"} + ... + $AXIOS($OPTS, ...) + - pattern: fetch("$URL", ...) + - metavariable-regex: + metavariable: $URL + regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) +- id: typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html + message: Overwriting `transformLinkUri` or `transformImageUri` to something insecure, + or turning `allowDangerousHtml` on, or turning `escapeHtml` off, will open the + code up to XSS vectors. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.npmjs.com/package/react-markdown#security + category: security + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html + shortlink: https://sg.run/9qAk + semgrep.dev: + rule: + r_id: 9767 + rv_id: 1263919 + rule_id: kxURd4 + version_id: BjTkZA8 + url: https://semgrep.dev/playground/r/BjTkZA8/typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html + origin: community + languages: + - typescript + - javascript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $X = require('react-markdown/with-html'); + ... + - pattern-inside: | + $X = require('react-markdown'); + ... + - pattern-inside: | + import 'react-markdown/with-html'; + ... + - pattern-inside: | + import 'react-markdown'; + ... + - pattern-either: + - pattern: | + <$EL allowDangerousHtml /> + - pattern: | + <$EL escapeHtml={false} /> + - pattern: | + <$EL transformLinkUri=... /> + - pattern: | + <$EL transformImageUri=... /> +- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + message: Detection of dangerouslySetInnerHTML from non-constant definition. This + can inadvertently expose users to cross-site scripting (XSS) attacks if this comes + from user-provided input. If you have to use dangerouslySetInnerHTML, consider + using a sanitization library such as DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + shortlink: https://sg.run/rAx6 + semgrep.dev: + rule: + r_id: 9769 + rv_id: 1263912 + rule_id: x8UWvK + version_id: l4TJR0v + url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-not-inside: | + $F. ... .$SANITIZEUNC(...) + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern-either: + - pattern: | + {...,dangerouslySetInnerHTML: {__html: $X},...} + - pattern: | + <$Y ... dangerouslySetInnerHTML={{__html: $X}} /> + - pattern-not: | + <$Y ... dangerouslySetInnerHTML={{__html: "..."}} /> + - pattern-not: | + {...,dangerouslySetInnerHTML:{__html: "..."},...} + - metavariable-pattern: + patterns: + - pattern-not: | + {...} + metavariable: $X + - pattern-not: | + <... {__html: "..."} ...> + - pattern-not: | + <... {__html: `...`} ...> + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property + message: Property decoded from JWT token without verifying and cannot be trustworthy. + metadata: + cwe: + - 'CWE-922: Insecure Storage of Sensitive Information' + references: + - https://pragmaticwebsecurity.com/articles/oauthoidc/localstorage-xss.html + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - react + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property + shortlink: https://sg.run/wx8x + semgrep.dev: + rule: + r_id: 9773 + rv_id: 1263914 + rule_id: d8Uzqz + version_id: JdTzxjz + url: https://semgrep.dev/playground/r/JdTzxjz/typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property + origin: community + languages: + - typescript + - javascript + severity: INFO + patterns: + - pattern-inside: | + import jwt_decode from "jwt-decode"; + ... + - pattern-inside: | + $DECODED = jwt_decode($TOKEN,...); + ... + - pattern: $DECODED.$PROPERTY +- id: typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage + message: Storing JWT tokens in localStorage known to be a bad practice, consider + moving your tokens from localStorage to a HTTP cookie. + metadata: + cwe: + - 'CWE-922: Insecure Storage of Sensitive Information' + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - react + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage + shortlink: https://sg.run/xYye + semgrep.dev: + rule: + r_id: 9774 + rv_id: 1263915 + rule_id: ZqUq6g + version_id: 5PTo1zq + url: https://semgrep.dev/playground/r/5PTo1zq/typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage + origin: community + languages: + - typescript + - javascript + severity: INFO + patterns: + - pattern-inside: | + import jwt_decode from "jwt-decode"; + ... + - pattern-either: + - pattern: | + $DECODED = jwt_decode($TOKEN,...); + ... + localStorage.setItem($NAME, <... $TOKEN ...>); + - pattern: | + $DECODED = jwt_decode(...); + ... + localStorage.setItem($NAME, <... $DECODED ...>); +- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + message: Detection of $HTML from non-constant definition. This can inadvertently + expose users to cross-site scripting (XSS) attacks if this comes from user-provided + input. If you have to use $HTML, consider using a sanitization library such as + DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln + - https://developer.mozilla.org/en-US/docs/Web/API/Document/write + - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + shortlink: https://sg.run/E5x8 + semgrep.dev: + rule: + r_id: 9781 + rv_id: 1263916 + rule_id: QrU68w + version_id: GxTkeRl + url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" + - pattern: "window.document. ... .$HTML('...',$SINK) \n" + - pattern: "document.$HTML($SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (writeln|write) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: "$PROP. ... .$HTML('...',$SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (insertAdjacentHTML) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: ruby.lang.security.dangerous-exec.dangerous-exec + mode: taint + pattern-sources: + - patterns: + - pattern: | + def $F(...,$ARG,...) + ... + end + - focus-metavariable: $ARG + - pattern: params + - pattern: cookies + pattern-sinks: + - patterns: + - pattern: | + $EXEC(...) + - pattern-not: | + $EXEC("...","...","...",...) + - pattern-not: | + $EXEC(["...","...","...",...],...) + - pattern-not: | + $EXEC({...},"...","...","...",...) + - pattern-not: | + $EXEC({...},["...","...","...",...],...) + - metavariable-regex: + metavariable: $EXEC + regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ + message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If + unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + - rails + references: + - https://guides.rubyonrails.org/security.html#command-line-injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec + shortlink: https://sg.run/R8GY + semgrep.dev: + rule: + r_id: 9805 + rv_id: 1409405 + rule_id: WAUZOw + version_id: WrT7erb + url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec + origin: community + severity: WARNING + languages: + - ruby +- id: ruby.lang.security.dangerous-open.dangerous-open + patterns: + - pattern: | + open($CMD,...) + - pattern-not: | + open("...",...) + - metavariable-regex: + metavariable: $CMD + regex: '|' + message: Detected non-static command inside 'open'. Audit the input to 'open'. If + unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-open.dangerous-open + shortlink: https://sg.run/Al8Q + semgrep.dev: + rule: + r_id: 9806 + rv_id: 1263599 + rule_id: 0oUEyd + version_id: 5PTo1WL + url: https://semgrep.dev/playground/r/5PTo1WL/ruby.lang.security.dangerous-open.dangerous-open + origin: community + severity: WARNING + languages: + - ruby +- id: ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline + patterns: + - pattern: | + Open3.$PIPE(...) + - pattern-not: | + Open3.$PIPE(...,"...",...) + - metavariable-regex: + metavariable: $PIPE + regex: ^(pipeline|pipeline_r|pipeline_rw|pipeline_start|pipeline_w)$ + message: Detected non-static command inside $PIPE. Audit the input to '$PIPE'. If + unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline + shortlink: https://sg.run/B4jv + semgrep.dev: + rule: + r_id: 9807 + rv_id: 1263600 + rule_id: KxU4nd + version_id: GxTkeNz + url: https://semgrep.dev/playground/r/GxTkeNz/ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline + origin: community + severity: WARNING + languages: + - ruby +- id: ruby.lang.security.dangerous-syscall.dangerous-syscall + pattern: | + syscall + message: '''syscall'' is essentially unsafe and unportable. The DL (https://apidock.com/ruby/Fiddle) + library is preferred for safer and a bit more portable programming.' + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-syscall.dangerous-syscall + shortlink: https://sg.run/DJkv + semgrep.dev: + rule: + r_id: 9808 + rv_id: 1263602 + rule_id: qNUo50 + version_id: A8TgdDN + url: https://semgrep.dev/playground/r/A8TgdDN/ruby.lang.security.dangerous-syscall.dangerous-syscall + origin: community + severity: WARNING + languages: + - ruby +- id: ruby.lang.security.dangerous-subshell.dangerous-subshell + patterns: + - pattern: | + `...#{$VAL}...` + - pattern-not: | + `...#{"..."}...` + - pattern-not-inside: | + $VAL = "..." + ... + message: Detected non-static command inside `...`. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can + inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-subshell.dangerous-subshell + shortlink: https://sg.run/NrxL + semgrep.dev: + rule: + r_id: 9827 + rv_id: 1263601 + rule_id: OrUGn8 + version_id: RGT0LJK + url: https://semgrep.dev/playground/r/RGT0LJK/ruby.lang.security.dangerous-subshell.dangerous-subshell + origin: community + severity: WARNING + languages: + - ruby +- id: javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell + message: Detected non-literal calls to $EXEC(). This could lead to a command injection + vulnerability. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-child-process.js + category: security + technology: + - javascript + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html#do-not-use-dangerous-functions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell + shortlink: https://sg.run/DJ8v + semgrep.dev: + rule: + r_id: 9852 + rv_id: 1263193 + rule_id: qNUo10 + version_id: PkTR3nY + url: https://semgrep.dev/playground/r/PkTR3nY/javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + function ... (...,$FUNC,...) { + ... + } + - focus-metavariable: $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('child_process') + ... + - pattern-inside: | + import 'child_process' + ... + - pattern-either: + - pattern: spawn(...) + - pattern: spawnSync(...) + - pattern: $CP.spawn(...) + - pattern: $CP.spawnSync(...) + - pattern-either: + - pattern: | + $EXEC("=~/(sh|bash|ksh|csh|tcsh|zsh)/",["-c", $ARG, ...],...) + - patterns: + - pattern: $EXEC($CMD,["-c", $ARG, ...],...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" + ... + - pattern: | + $EXEC("=~/(sh|bash|ksh|csh|tcsh|zsh)/",[$ARG, ...],...) + - patterns: + - pattern: $EXEC($CMD,[$ARG, ...],...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" + ... + - focus-metavariable: $ARG +- id: javascript.lang.security.audit.spawn-shell-true.spawn-shell-true + message: 'Found ''$SPAWN'' with ''{shell: $SHELL}''. This is dangerous because this + call will spawn the command using a shell process. Doing so propagates current + shell settings and variables, which makes it much easier for a malicious actor + to execute commands. Use ''{shell: false}'' instead.' + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + category: security + technology: + - javascript + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.spawn-shell-true.spawn-shell-true + shortlink: https://sg.run/Wgeo + semgrep.dev: + rule: + r_id: 9853 + rv_id: 1263204 + rule_id: lBUdr5 + version_id: qkTR79W + url: https://semgrep.dev/playground/r/qkTR79W/javascript.lang.security.audit.spawn-shell-true.spawn-shell-true + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-either: + - pattern: | + spawn(...,{shell: $SHELL}) + - pattern: | + spawnSync(...,{shell: $SHELL}) + - pattern: | + $CP.spawn(...,{shell: $SHELL}) + - pattern: | + $CP.spawnSync(...,{shell: $SHELL}) + - pattern-not: | + spawn(...,{shell: false}) + - pattern-not: | + spawnSync(...,{shell: false}) + - pattern-not: | + $CP.spawn(...,{shell: false}) + - pattern-not: | + $CP.spawnSync(...,{shell: false}) +- id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + message: Detected non-literal calls to Deno.run(). This could lead to a command + injection vulnerability. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - deno + references: + - https://deno.land/manual/examples/subprocess#simple-example + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + shortlink: https://sg.run/Nrrn + semgrep.dev: + rule: + r_id: 9927 + rv_id: 1409397 + rule_id: x8UWWg + version_id: PkTe7AP + url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: function ... (..., $ARG,...) {...} + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + Deno.run({cmd: [$INPUT,...]},...) + - pattern: | + Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...) + - patterns: + - pattern: | + Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" + ... + - focus-metavariable: $INPUT +- id: java.lang.security.audit.command-injection-process-builder.command-injection-process-builder + pattern-either: + - patterns: + - pattern: | + new ProcessBuilder($CMD,...) + - pattern-not-inside: | + $CMD = "..."; + ... + - pattern-not-inside: | + $CMD = Arrays.asList("...",...); + ... + - pattern-not-inside: | + $CMD = new String[]{"...",...}; + ... + - pattern-not: | + new ProcessBuilder("...",...) + - pattern-not: | + new ProcessBuilder(new String[]{"...",...},...) + - pattern-not: | + new ProcessBuilder(Arrays.asList("...",...),...) + - patterns: + - pattern: | + $PB.command($CMD,...) + - pattern-inside: | + $TYPE $PB = new ProcessBuilder(...); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - pattern-not-inside: | + $CMD = Arrays.asList("...",...); + ... + - pattern-not-inside: | + $CMD = new String[]{"...",...}; + ... + - pattern-not: | + $PB.command("...",...) + - pattern-not: | + $PB.command(new String[]{"...",...},...) + - pattern-not: | + $PB.command(Arrays.asList("...",...),...) + - patterns: + - pattern-either: + - pattern: | + new ProcessBuilder("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...) + - pattern: | + new ProcessBuilder("cmd","/c",$ARG,...) + - pattern: | + new ProcessBuilder(Arrays.asList("cmd","/c",$ARG,...),...) + - pattern: | + new ProcessBuilder(new String[]{"cmd","/c",$ARG,...},...) + - patterns: + - pattern-either: + - pattern: | + new ProcessBuilder($CMD,"/c",$ARG,...) + - pattern: | + new ProcessBuilder(Arrays.asList($CMD,"/c",$ARG,...),...) + - pattern: | + new ProcessBuilder(new String[]{$CMD,"/c",$ARG,...},...) + - pattern-inside: | + $CMD = "cmd"; + ... + - pattern-not-inside: | + $ARG = "..."; + ... + - pattern-not: | + new ProcessBuilder("...","...","...",...) + - pattern-not: | + new ProcessBuilder(new String[]{"...","...","...",...},...) + - pattern-not: | + new ProcessBuilder(Arrays.asList("...","...","...",...),...) + - patterns: + - pattern-either: + - pattern: | + $PB.command("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...) + - pattern: | + $PB.command("cmd","/c",$ARG,...) + - pattern: | + $PB.command(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...),...) + - pattern: | + $PB.command(Arrays.asList("cmd","/c",$ARG,...),...) + - pattern: | + $PB.command(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...},...) + - pattern: | + $PB.command(new String[]{"cmd","/c",$ARG,...},...) + - patterns: + - pattern-either: + - pattern: | + $PB.command($CMD,"-c",$ARG,...) + - pattern: | + $PB.command(Arrays.asList($CMD,"-c",$ARG,...),...) + - pattern: | + $PB.command(new String[]{$CMD,"-c",$ARG,...},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; + ... + - patterns: + - pattern-either: + - pattern: | + $PB.command($CMD,"/c",$ARG,...) + - pattern: | + $PB.command(Arrays.asList($CMD,"/c",$ARG,...),...) + - pattern: | + $PB.command(new String[]{$CMD,"/c",$ARG,...},...) + - pattern-inside: | + $CMD = "cmd"; + ... + - pattern-inside: | + $TYPE $PB = new ProcessBuilder(...); + ... + - pattern-not-inside: | + $ARG = "..."; + ... + - pattern-not: | + $PB.command("...","...","...",...) + - pattern-not: | + $PB.command(new String[]{"...","...","...",...},...) + - pattern-not: | + $PB.command(Arrays.asList("...","...","...",...),...) + message: A formatted or concatenated string was detected as input to a ProcessBuilder + call. This is dangerous if a variable is controlled by user input and could result + in a command injection. Ensure your variables are not controlled by users or sufficiently + sanitized. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.command-injection-process-builder.command-injection-process-builder + shortlink: https://sg.run/gJJe + semgrep.dev: + rule: + r_id: 9941 + rv_id: 1262992 + rule_id: 4bUzzo + version_id: JdTzxnn + url: https://semgrep.dev/playground/r/JdTzxnn/java.lang.security.audit.command-injection-process-builder.command-injection-process-builder + origin: community + severity: ERROR + languages: + - java +- id: java.spring.security.audit.spring-jsp-eval.spring-jsp-eval + pattern: | + + message: A Spring expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + severity: WARNING + languages: + - generic + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#JSP_SPRING_EVAL + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.spring.security.audit.spring-jsp-eval.spring-jsp-eval + shortlink: https://sg.run/Q88o + semgrep.dev: + rule: + r_id: 9942 + rv_id: 1263081 + rule_id: PeUkkL + version_id: d6TyxL7 + url: https://semgrep.dev/playground/r/d6TyxL7/java.spring.security.audit.spring-jsp-eval.spring-jsp-eval + origin: community + paths: + include: + - '*.jsp' +- id: javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls + message: 'If TLS is disabled on server side (Postgresql server), Sequelize establishes + connection without TLS and no error will be thrown. To prevent MITN (Man In The + Middle) attack, TLS must be enforce by Sequelize. Set "ssl: true" or define settings + "ssl: {...}"' + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://node-postgres.com/features/ssl + - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket + - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options + - https://nodejs.org/api/tls.html#tls_tls_default_min_version + category: security + technology: + - sequelize + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls + shortlink: https://sg.run/yz6Z + semgrep.dev: + rule: + r_id: 9968 + rv_id: 1263240 + rule_id: NbUAYW + version_id: ZRTKAJ4 + url: https://semgrep.dev/playground/r/ZRTKAJ4/javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern: | + { + host: $HOST, + database: $DATABASE, + dialect: $DIALECT + } + - pattern-not: | + { + host: $HOST, + database: $DATABASE, + dialect: "postgres", + dialectOptions: { + ssl: true + } + } + - pattern-not: | + { + host: $HOST, + database: $DATABASE, + dialect: $DIALECT, + dialectOptions: { + ssl: { ... } + } + } + - metavariable-regex: + metavariable: $DIALECT + regex: '[''"](mariadb|mysql|postgres)[''"]' +- id: javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation + message: Set "rejectUnauthorized" to false is a convenient way to resolve certificate + error. But this method is unsafe because it disables the server certificate verification, + making the Node app open to MITM attack. "rejectUnauthorized" option must be alway + set to True (default value). With self -signed certificate or custom CA, use "ca" + option to define Root Certificate. This rule checks TLS configuration only for + Postgresql, MariaDB and MySQL. SQLite is not really concerned by TLS configuration. + This rule could be extended for MSSQL, but the dialectOptions is specific for + Tedious. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://node-postgres.com/features/ssl + - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket + - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options + category: security + technology: + - sequelize + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation + shortlink: https://sg.run/rAkj + semgrep.dev: + rule: + r_id: 9969 + rv_id: 1263243 + rule_id: kxUR80 + version_id: 7ZTE3w1 + url: https://semgrep.dev/playground/r/7ZTE3w1/javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + { + host: $HOST, + database: $DATABASE, + dialect: $DIALECT, + dialectOptions: { + ssl: { + rejectUnauthorized: false + } + } + } + - metavariable-regex: + metavariable: $DIALECT + regex: '[''"](mariadb|mysql|postgres)[''"]' +- id: javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version + message: TLS1.0 and TLS1.1 are deprecated and should not be used anymore. By default, + NodeJS used TLSv1.2. So, TLS min version must not be downgrade to TLS1.0 or TLS1.1. + Enforce TLS1.3 is highly recommended This rule checks TLS configuration only for + PostgreSQL, MariaDB and MySQL. SQLite is not really concerned by TLS configuration. + This rule could be extended for MSSQL, but the dialectOptions is specific for + Tedious. + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://node-postgres.com/features/ssl + - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket + - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options + - https://nodejs.org/api/tls.html#tls_tls_default_min_version + category: security + technology: + - sequelize + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version + shortlink: https://sg.run/bDrq + semgrep.dev: + rule: + r_id: 9970 + rv_id: 1263244 + rule_id: wdU8GB + version_id: LjTkgJy + url: https://semgrep.dev/playground/r/LjTkgJy/javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + { + host: $HOST, + database: $DATABASE, + dialect: $DIALECT, + dialectOptions: + { ssl: ... } + } + - pattern-either: + - pattern: | + { + minVersion: 'TLSv1' + } + - pattern: | + { + minVersion: 'TLSv1.1' + } + - metavariable-regex: + metavariable: $DIALECT + regex: '[''"](mariadb|mysql|postgres)[''"]' +- id: java.jboss.security.seam-log-injection.seam-log-injection + patterns: + - pattern: | + $LOG.$INFO($X + $Y,...) + - pattern-either: + - pattern-inside: | + import org.jboss.seam.log.Log; + ... + - pattern-inside: | + org.jboss.seam.log.Log $LOG = ...; + ... + - metavariable-regex: + metavariable: $INFO + regex: (debug|error|fatal|info|trace|warn) + languages: + - java + message: Seam Logging API support an expression language to introduce bean property + to log messages. The expression language can also be the source to unwanted code + execution. In this context, an expression is built with a dynamic value. The source + of the value(s) should be verified to avoid that unfiltered values fall into this + risky code evaluation. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SEAM_LOG_INJECTION + category: security + technology: + - jboss + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.jboss.security.seam-log-injection.seam-log-injection + shortlink: https://sg.run/3A4o + semgrep.dev: + rule: + r_id: 9987 + rv_id: 1262985 + rule_id: JDUPQ7 + version_id: LjTkgRE + url: https://semgrep.dev/playground/r/LjTkgRE/java.jboss.security.seam-log-injection.seam-log-injection + origin: community + severity: ERROR +- id: java.lang.security.audit.unsafe-reflection.unsafe-reflection + patterns: + - pattern: | + Class.forName($CLASS,...) + - pattern-not: | + Class.forName("...",...) + - pattern-not-inside: | + $CLASS = "..."; + ... + message: If an attacker can supply values that the application then uses to determine + which class to instantiate or which method to invoke, the potential exists for + the attacker to create control flow paths through the application that were not + intended by the application developers. This attack vector may allow the attacker + to bypass authentication or access control checks or otherwise cause the application + to behave in an unexpected manner. + metadata: + cwe: + - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe + Reflection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://owasp.org/www-community/vulnerabilities/Unsafe_use_of_Reflection + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/java.lang.security.audit.unsafe-reflection.unsafe-reflection + shortlink: https://sg.run/R8X8 + semgrep.dev: + rule: + r_id: 9993 + rv_id: 1263047 + rule_id: DbUW1W + version_id: 44TEj5L + url: https://semgrep.dev/playground/r/44TEj5L/java.lang.security.audit.unsafe-reflection.unsafe-reflection + origin: community + severity: WARNING + languages: + - java +- id: go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + patterns: + - pattern-either: + - pattern: | + $SMTH.MethodByName($NAME,...) + - pattern: | + $SMTH.FieldByName($NAME,...) + - pattern-not: | + $SMTH.MethodByName("...",...) + - pattern-not: | + $SMTH.FieldByName("...",...) + - pattern-inside: | + import "reflect" + ... + message: If an attacker can supply values that the application then uses to determine + which method or field to invoke, the potential exists for the attacker to create + control flow paths through the application that were not intended by the application + developers. This attack vector may allow the attacker to bypass authentication + or access control checks or otherwise cause the application to behave in an unexpected + manner. + metadata: + cwe: + - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe + Reflection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + shortlink: https://sg.run/R8Xv + semgrep.dev: + rule: + r_id: 10005 + rv_id: 1262955 + rule_id: BYUBdJ + version_id: WrTqK8e + url: https://semgrep.dev/playground/r/WrTqK8e/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + origin: community + severity: WARNING + languages: + - go +- id: yaml.docker-compose.security.privileged-service.privileged-service + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + $SERVICE: + ... + privileged: $TRUE + - focus-metavariable: $TRUE + - metavariable-regex: + metavariable: $TRUE + regex: (true) + fix: | + false + message: Service '$SERVICE' is running in privileged mode. This grants the container + the equivalent of root capabilities on the host machine. This can lead to container + escapes, privilege escalation, and other security concerns. Remove the 'privileged' + key to disable this capability. + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html + - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ + category: security + technology: + - docker-compose + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service + shortlink: https://sg.run/AlX0 + semgrep.dev: + rule: + r_id: 10006 + rv_id: 1263922 + rule_id: DbUW17 + version_id: 0bTKzXZ + url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service + origin: community + languages: + - yaml + severity: WARNING +- id: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash + pattern-regex: \$2[aby]?\$[\d]+\$[./A-Za-z0-9]{53} + languages: + - regex + message: bcrypt hash detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - bcrypt + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash + shortlink: https://sg.run/3A8G + semgrep.dev: + rule: + r_id: 10043 + rv_id: 1262864 + rule_id: PeUk0Q + version_id: 2KTv236 + url: https://semgrep.dev/playground/r/2KTv236/generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash + origin: community +- id: generic.secrets.security.detected-etc-shadow.detected-etc-shadow + patterns: + - pattern-regex: ^(\s*)(?Proot:[x!*]*:[0-9]*:[0-9]*) + - focus-metavariable: $ROOT + languages: + - regex + message: linux shadow file detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-etc-shadow.detected-etc-shadow + shortlink: https://sg.run/4ylL + semgrep.dev: + rule: + r_id: 10044 + rv_id: 1262866 + rule_id: JDUP6p + version_id: jQTn5yp + url: https://semgrep.dev/playground/r/jQTn5yp/generic.secrets.security.detected-etc-shadow.detected-etc-shadow + origin: community +- id: generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token + patterns: + - pattern: $AUTHTOKEN = $VALUE + - metavariable-regex: + metavariable: $AUTHTOKEN + regex: _(authToken|auth|password) + - pattern-not: $AUTHTOKEN = ${...} + languages: + - generic + message: NPM registry authentication token detected + paths: + include: + - '*npmrc*' + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - npm + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token + shortlink: https://sg.run/Ppg3 + semgrep.dev: + rule: + r_id: 10045 + rv_id: 1262883 + rule_id: 5rU4pe + version_id: 7ZTE3n2 + url: https://semgrep.dev/playground/r/7ZTE3n2/generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token + origin: community +- id: javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket + message: Insecure WebSocket Detected. WebSocket Secure (wss) should be used for + all WebSocket connections. + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + asvs: + section: 'V13: API and Web Service Verification Requirements' + control_id: 13.5.1 Insecure WebSocket + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x21-V13-API.md#v135-websocket-security-requirements + version: '4' + category: security + technology: + - regex + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket + shortlink: https://sg.run/GWyz + semgrep.dev: + rule: + r_id: 10048 + rv_id: 1263215 + rule_id: AbUWeE + version_id: 0bTKzQ9 + url: https://semgrep.dev/playground/r/0bTKzQ9/javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket + origin: community + languages: + - regex + severity: ERROR + patterns: + - pattern-regex: \bws:\/\/ + - pattern-not-inside: \bws:\/\/localhost.* + - pattern-not-inside: \bws:\/\/127.0.0.1.* +- id: yaml.docker-compose.security.no-new-privileges.no-new-privileges + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + - pattern: | + $SERVICE: + ... + image: ... + - pattern-not: | + $SERVICE: + ... + image: ... + ... + security_opt: + - ... + - no-new-privileges:true + - ... + - focus-metavariable: $SERVICE + message: Service '$SERVICE' allows for privilege escalation via setuid or setgid + binaries. Add 'no-new-privileges:true' in 'security_opt' to prevent this. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://raesene.github.io/blog/2019/06/01/docker-capabilities-and-no-new-privs/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - docker-compose + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.no-new-privileges.no-new-privileges + shortlink: https://sg.run/0n8q + semgrep.dev: + rule: + r_id: 10054 + rv_id: 1263921 + rule_id: qNUoWr + version_id: WrTqKwk + url: https://semgrep.dev/playground/r/WrTqKwk/yaml.docker-compose.security.no-new-privileges.no-new-privileges + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + - pattern: | + $SERVICE: + ... + image: ... + ... + security_opt: + - ... + - seccomp:unconfined + message: Service '$SERVICE' is explicitly disabling seccomp confinement. This runs + the service in an unrestricted state. Remove 'seccomp:unconfined' to prevent this. + metadata: + cwe: + - 'CWE-284: Improper Access Control' + references: + - https://docs.docker.com/engine/security/seccomp/ + category: security + technology: + - docker-compose + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled + shortlink: https://sg.run/KWkY + semgrep.dev: + rule: + r_id: 10055 + rv_id: 1263923 + rule_id: lBUdW3 + version_id: K3TKkXA + url: https://semgrep.dev/playground/r/K3TKkXA/yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + - pattern: | + $SERVICE: + ... + image: ... + ... + security_opt: + - ... + - label:disable + message: Service '$SERVICE' is explicitly disabling SELinux separation. This runs + the service as an unconfined type. Remove 'label:disable' to prevent this. + metadata: + cwe: + - 'CWE-284: Improper Access Control' + references: + - https://www.projectatomic.io/blog/2016/03/dwalsh_selinux_containers/ + - https://docs.docker.com/engine/reference/run/#security-configuration + category: security + technology: + - docker-compose + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled + shortlink: https://sg.run/qryb + semgrep.dev: + rule: + r_id: 10056 + rv_id: 1263924 + rule_id: YGUrAG + version_id: qkTR7yg + url: https://semgrep.dev/playground/r/qkTR7yg/yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - name: $CONTAINER + ... + - pattern: | + image: ... + ... + - pattern-inside: | + image: ... + ... + $SC: + ... + - metavariable-regex: + metavariable: $SC + regex: ^(securityContext)$ + - pattern-not-inside: | + image: ... + ... + securityContext: + ... + allowPrivilegeEscalation: $VAL + - focus-metavariable: $SC + fix: | + securityContext: + allowPrivilegeEscalation: false # + message: In Kubernetes, each pod runs in its own isolated environment with its own + set of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation` + parameter to your the `securityContext`, you can help to ensure that your containerized + applications are more secure and less vulnerable to privilege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + shortlink: https://sg.run/ljp6 + semgrep.dev: + rule: + r_id: 10057 + rv_id: 1263933 + rule_id: 6JUqEO + version_id: jQTn527 + url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.privileged-container.privileged-container + pattern-either: + - patterns: + - pattern-inside: | + containers: + ... + - pattern: | + image: ... + ... + securityContext: + ... + privileged: true + - patterns: + - pattern-inside: | + spec: + ... + - pattern-not-inside: | + image: ... + ... + - pattern: | + privileged: true + message: Container or pod is running in privileged mode. This grants the container + the equivalent of root capabilities on the host machine. This can lead to container + escapes, privilege escalation, and other security concerns. Remove the 'privileged' + key to disable this capability. + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privileged + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html + category: security + technology: + - kubernetes + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.privileged-container.privileged-container + shortlink: https://sg.run/Ygr5 + semgrep.dev: + rule: + r_id: 10058 + rv_id: 947059 + rule_id: oqUz2p + version_id: gETeWJA + url: https://semgrep.dev/playground/r/gETeWJA/yaml.kubernetes.security.privileged-container.privileged-container + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + patterns: + - pattern-inside: | + containers: + ... + - pattern: | + image: ... + ... + securityContext: + ... + seccompProfile: unconfined + message: 'Container is explicitly disabling seccomp confinement. This runs the service + in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.' + metadata: + cwe: + - 'CWE-284: Improper Access Control' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + category: security + technology: + - kubernetes + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + shortlink: https://sg.run/6rgY + semgrep.dev: + rule: + r_id: 10059 + rv_id: 1263941 + rule_id: zdUynw + version_id: w8TRoL3 + url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + origin: community + languages: + - yaml + severity: WARNING +- id: python.lang.security.dangerous-globals-use.dangerous-globals-use + patterns: + - pattern-either: + - pattern: globals().get(...) + - pattern: locals().get(...) + - pattern: globals()[...] + - pattern: locals()[...] + - patterns: + - pattern-either: + - pattern-inside: | + $G = globals() + ... + - pattern-inside: | + $G = locals() + ... + - pattern-either: + - pattern: $G.get(...) + - pattern: $G[...] + - pattern: $FUNC.__globals__[...] + - pattern-not: globals().get("...") + - pattern-not: locals().get("...") + - pattern-not: globals()["..."] + - pattern-not: locals()["..."] + - pattern-not: $G.get("...") + - pattern-not: $G.get["..."] + - pattern-not: $G["..."] + - pattern-not: $FUNC.__globals__["..."] + - pattern-not-inside: globals()[...] = ... + - pattern-not-inside: locals()[...] = ... + - pattern-not-inside: $G[...] = ... + - pattern-not-inside: $FUNC.__globals__[...] = ... + message: Found non static data as an index to 'globals()'. This is extremely dangerous + because it allows an attacker to execute arbitrary code on the system. Refactor + your code not to use 'globals()'. + metadata: + cwe: + - 'CWE-96: Improper Neutralization of Directives in Statically Saved Code (''Static + Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/mpirnat/lets-be-bad-guys/blob/d92768fb3ade32956abd53bd6bb06e19d634a084/badguys/vulnerable/views.py#L181-L186 + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-globals-use.dangerous-globals-use + shortlink: https://sg.run/jNzn + semgrep.dev: + rule: + r_id: 10065 + rv_id: 1263522 + rule_id: 9AUOZP + version_id: YDTZeB4 + url: https://semgrep.dev/playground/r/YDTZeB4/python.lang.security.dangerous-globals-use.dangerous-globals-use + origin: community + severity: WARNING + languages: + - python +- id: java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell + patterns: + - pattern-either: + - pattern: | + $SHELL.parse(...) + - pattern: | + $SHELL.evaluate(...) + - pattern: | + $SHELL.parseClass(...) + - pattern-either: + - pattern-inside: | + groovy.lang.GroovyShell $SHELL = ...; + ... + - pattern-inside: | + groovy.lang.GroovyClassLoader $SHELL = ...; + ... + - pattern-not: | + $SHELL.parse("...",...) + - pattern-not: | + $SHELL.evaluate("...",...) + - pattern-not: | + $SHELL.parseClass("...",...) + message: A expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#GROOVY_SHELL + category: security + technology: + - groovy + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell + shortlink: https://sg.run/58LK + semgrep.dev: + rule: + r_id: 10091 + rv_id: 1263020 + rule_id: ReUPKp + version_id: zyTb2Nq + url: https://semgrep.dev/playground/r/zyTb2Nq/java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell + origin: community + languages: + - java + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + pattern: | + cluster: + ... + insecure-skip-tls-verify: true + message: 'Cluster is disabling TLS certificate verification when communicating with + the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify: + true'' key to secure communication.' + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster + category: security + technology: + - kubernetes + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + shortlink: https://sg.run/okyn + semgrep.dev: + rule: + r_id: 10116 + rv_id: 1263943 + rule_id: zdUyWx + version_id: O9Tpxbo + url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + pattern: | + spec: + ... + insecureSkipTLSVerify: true + message: 'Service is disabling TLS certificate verification when communicating with + the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify: + true'' key to secure communication.' + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io + category: security + technology: + - kubernetes + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + shortlink: https://sg.run/zk10 + semgrep.dev: + rule: + r_id: 10117 + rv_id: 1263944 + rule_id: pKUGXr + version_id: e1TyjnR + url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + origin: community + languages: + - yaml + severity: WARNING +- id: python.flask.security.flask-api-method-string-format.flask-api-method-string-format + patterns: + - pattern-either: + - pattern: | + def $METHOD(...,$ARG,...): + ... + $STRING = "...".format(...,$ARG,...) + ... + ... = requests.$REQMETHOD($STRING,...) + - pattern: | + def $METHOD(...,$ARG,...): + ... + ... = requests.$REQMETHOD("...".format(...,$ARG,...),...) + - pattern-inside: | + class $CLASS(...): + method_decorators = ... + ... + message: Method $METHOD in API controller $CLASS provides user arg $ARG to requests + method $REQMETHOD + severity: ERROR + languages: + - python + metadata: + cwe: + - 'CWE-134: Use of Externally-Controlled Format String' + category: security + technology: + - flask + references: + - https://cwe.mitre.org/data/definitions/134.html + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.flask.security.flask-api-method-string-format.flask-api-method-string-format + shortlink: https://sg.run/bDWr + semgrep.dev: + rule: + r_id: 10126 + rv_id: 946219 + rule_id: NbUAeY + version_id: WrTEo0r + url: https://semgrep.dev/playground/r/WrTEo0r/python.flask.security.flask-api-method-string-format.flask-api-method-string-format + origin: community +- id: yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume + patterns: + - pattern-inside: | + version: ... + ... + - pattern-either: + - pattern: | + volumes: + - ... + - /var/run/docker.sock:/var/run/docker.sock + - ... + - pattern: | + volumes: + - ... + - /run/docker.sock:/run/docker.sock + - ... + - pattern: | + volumes: + - ... + - /var/run/docker.sock:/run/docker.sock + - ... + - pattern: | + volumes: + - ... + - /run/docker.sock:/var/run/docker.sock + - ... + - pattern: | + volumes: + - ... + - /var/run/docker.sock + - ... + - pattern: | + volumes: + - ... + - /run/docker.sock + - ... + - pattern: | + volumes: + - ... + - ... + source: /var/run/docker.sock + ... + - ... + - pattern: | + volumes: + - ... + - ... + source: /run/docker.sock + ... + - ... + message: Exposing host's Docker socket to containers via a volume. The owner of + this socket is root. Giving someone access to it is equivalent to giving unrestricted + root access to your host. Remove 'docker.sock' from volumes to prevent this. + metadata: + references: + - https://docs.docker.com/compose/compose-file/compose-file-v3/#volume-configuration-reference + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-1-do-not-expose-the-docker-daemon-socket-even-to-the-containers + category: security + technology: + - docker-compose + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume + shortlink: https://sg.run/O14b + semgrep.dev: + rule: + r_id: 10131 + rv_id: 1263920 + rule_id: eqUvZ9 + version_id: DkTRbje + url: https://semgrep.dev/playground/r/DkTRbje/yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + - pattern: | + $SERVICE: + ... + image: ... + ... + - pattern-not: | + $SERVICE: + ... + image: ... + ... + read_only: true + - focus-metavariable: $SERVICE + message: 'Service ''$SERVICE'' is running with a writable root filesystem. This + may allow malicious applications to download and run additional payloads, or modify + container files. If an application inside a container has to save something temporarily + consider using a tmpfs. Add ''read_only: true'' to this service to prevent this.' + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://docs.docker.com/compose/compose-file/compose-file-v3/#domainname-hostname-ipc-mac_address-privileged-read_only-shm_size-stdin_open-tty-user-working_dir + - https://blog.atomist.com/security-of-docker-kubernetes/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-8-set-filesystem-and-volumes-to-read-only + category: security + technology: + - docker-compose + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service + shortlink: https://sg.run/e4JE + semgrep.dev: + rule: + r_id: 10132 + rv_id: 1263925 + rule_id: v8U5vN + version_id: l4TJR0w + url: https://semgrep.dev/playground/r/l4TJR0w/yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath + patterns: + - pattern-inside: | + volumes: + ... + - pattern: | + hostPath: + ... + path: /var/run/docker.sock + message: Exposing host's Docker socket to containers via a volume. The owner of + this socket is root. Giving someone access to it is equivalent to giving unrestricted + root access to your host. Remove 'docker.sock' from hostpath to prevent this. + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + references: + - https://kubernetes.io/docs/concepts/storage/volumes/#hostpath + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#volumes-and-file-systems + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-1-do-not-expose-the-docker-daemon-socket-even-to-the-containers + category: security + technology: + - kubernetes + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath + shortlink: https://sg.run/v0pR + semgrep.dev: + rule: + r_id: 10133 + rv_id: 947054 + rule_id: d8Uz6v + version_id: nWTpYZe + url: https://semgrep.dev/playground/r/nWTpYZe/yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.run-as-non-root.run-as-non-root + patterns: + - pattern-inside: | + $SPEC: + ... + containers: + ... + ... + - metavariable-regex: + metavariable: $SPEC + regex: ^(spec)$ + - pattern-not-inside: | + spec: + ... + securityContext: + ... + ... + - pattern-inside: | + $SPEC: + ... + containers: + ... + - pattern-not-inside: | + $SPEC: + ... + containers: + ... + - name: $NAME + image: ... + ... + securityContext: + ... + runAsNonRoot: $VALUE + - focus-metavariable: $SPEC + fix: | + $SPEC: + securityContext: + runAsNonRoot: true # + message: When running containers in Kubernetes, it's important to ensure that they are + properly secured to prevent privilege escalation attacks. One potential vulnerability + is when a container is allowed to run applications as the root user, which could + allow an attacker to gain access to sensitive resources. To mitigate this risk, + it's recommended to add a `securityContext` to the container, with the parameter + `runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root + user, limiting the damage that could be caused by any potential attacks. By adding + a `securityContext` to the container in your Kubernetes pod, you can help to + ensure that your containerized applications are more secure and less vulnerable + to privilege escalation attacks. + metadata: + references: + - https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/ + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user + category: security + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + technology: + - kubernetes + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root.run-as-non-root + shortlink: https://sg.run/dgP5 + semgrep.dev: + rule: + r_id: 10134 + rv_id: 1263940 + rule_id: ZqUqeK + version_id: kbTzGbo + url: https://semgrep.dev/playground/r/kbTzGbo/yaml.kubernetes.security.run-as-non-root.run-as-non-root + origin: community + languages: + - yaml + severity: INFO +- id: yaml.kubernetes.security.hostipc-pod.hostipc-pod + patterns: + - pattern-inside: | + spec: + ... + - pattern: | + hostIPC: true + message: Pod is sharing the host IPC namespace. This allows container processes + to communicate with processes on the host which reduces isolation and bypasses + container protection models. Remove the 'hostIPC' key to disable this functionality. + metadata: + cwe: + - 'CWE-693: Protection Mechanism Failure' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces + category: security + technology: + - kubernetes + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.hostipc-pod.hostipc-pod + shortlink: https://sg.run/nqGO + semgrep.dev: + rule: + r_id: 10236 + rv_id: 947055 + rule_id: nJUYPE + version_id: ExTg4KB + url: https://semgrep.dev/playground/r/ExTg4KB/yaml.kubernetes.security.hostipc-pod.hostipc-pod + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod + patterns: + - pattern-inside: | + spec: + ... + - pattern: | + hostNetwork: true + message: Pod may use the node network namespace. This gives the pod access to the + loopback device, services listening on localhost, and could be used to snoop on + network activity of other pods on the same node. Remove the 'hostNetwork' key + to disable this functionality. + metadata: + cwe: + - 'CWE-406: Insufficient Control of Network Message Volume (Network Amplification)' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces + category: security + technology: + - kubernetes + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod + shortlink: https://sg.run/E51A + semgrep.dev: + rule: + r_id: 10237 + rv_id: 947056 + rule_id: EwU4NO + version_id: 7ZTreWz + url: https://semgrep.dev/playground/r/7ZTreWz/yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.hostpid-pod.hostpid-pod + patterns: + - pattern-inside: | + spec: + ... + - pattern: | + hostPID: true + message: Pod is sharing the host process ID namespace. When paired with ptrace this + can be used to escalate privileges outside of the container. Remove the 'hostPID' + key to disable this functionality. + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces + category: security + technology: + - kubernetes + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.hostpid-pod.hostpid-pod + shortlink: https://sg.run/708R + semgrep.dev: + rule: + r_id: 10238 + rv_id: 1263934 + rule_id: 7KUeo0 + version_id: 1QTypvL + url: https://semgrep.dev/playground/r/1QTypvL/yaml.kubernetes.security.hostpid-pod.hostpid-pod + origin: community + languages: + - yaml + severity: WARNING +- id: go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + patterns: + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = fmt.Sprintf("...", $PARAM1, ...) + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: | + $DB, ... = sql.Open(...) + ... + - pattern-inside: | + func $FUNCNAME(..., $DB *sql.DB, ...) { + ... + } + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecContent|Query|QueryContext|QueryRow|QueryRowContext)$ + languages: + - go + message: Detected string concatenation with a non-literal variable in a "database/sql" + Go SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use prepared statements with the + 'Prepare' and 'PrepareContext' calls. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + references: + - https://golang.org/pkg/database/sql/ + category: security + technology: + - go + confidence: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + shortlink: https://sg.run/YgOX + semgrep.dev: + rule: + r_id: 10258 + rv_id: 1262951 + rule_id: YGUrnQ + version_id: RGT0Lpr + url: https://semgrep.dev/playground/r/RGT0Lpr/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + origin: community + severity: ERROR +- id: go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + patterns: + - pattern-inside: | + import ( + ... + "$IMPORT" + ) + ... + - metavariable-regex: + metavariable: $IMPORT + regex: .*go-pg + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = fmt.Sprintf("...", $PARAM1, ...) + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern: | + $DB.$INTFUNC1(...).$METHOD(..., $X + $Y, ...).$INTFUNC2(...) + - pattern: | + $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-inside: | + $DB = pg.Connect(...) + ... + - pattern-inside: | + func $FUNCNAME(..., $DB *pg.DB, ...) { + ... + } + - pattern-not-inside: | + $QUERY = fmt.Sprintf("...", ...,"...", ...) + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not: $DB.$METHOD(...,"...",...) + - pattern-not: | + $DB.$INTFUNC1(...).$METHOD(..., "...", ...).$INTFUNC2(...) + - pattern-not-inside: | + $QUERY = "..." + "..." + - pattern-not: | + "..." + - pattern-not: path.Join(...) + - pattern-not: filepath.Join(...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Where|WhereOr|Join|GroupExpr|OrderExpr|ColumnExpr)$ + languages: + - go + message: Detected string concatenation with a non-literal variable in a go-pg ORM + SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, do not use strings + concatenated with user-controlled input. Instead, use parameterized statements. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + references: + - https://pg.uptrace.dev/queries/ + category: security + technology: + - go-pg + confidence: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + shortlink: https://sg.run/6rA6 + semgrep.dev: + rule: + r_id: 10259 + rv_id: 1262952 + rule_id: 6JUqQ1 + version_id: A8Tgdqn + url: https://semgrep.dev/playground/r/A8Tgdqn/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + origin: community + severity: ERROR +- id: go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + languages: + - go + message: 'Detected string concatenation with a non-literal variable in a pgx Go + SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries instead. You can use parameterized queries like so: (`SELECT $1 FROM table`, + `data1)' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + references: + - https://github.com/jackc/pgx + - https://pkg.go.dev/github.com/jackc/pgx/v4#hdr-Connection_Pool + category: security + technology: + - pgx + confidence: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + shortlink: https://sg.run/okKN + semgrep.dev: + rule: + r_id: 10260 + rv_id: 1262954 + rule_id: oqUz92 + version_id: DkTRbkL + url: https://semgrep.dev/playground/r/DkTRbkL/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = fmt.Sprintf("...", $PARAM1, ...) + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: | + $DB, ... = pgx.Connect(...) + ... + - pattern-inside: | + $DB, ... = pgx.NewConnPool(...) + ... + - pattern-inside: | + $DB, ... = pgx.ConnectConfig(...) + ... + - pattern-inside: | + func $FUNCNAME(..., $DB *pgx.Conn, ...) { + ... + } + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecEx|Query|QueryEx|QueryRow|QueryRowEx)$ + severity: ERROR +- id: go.lang.security.audit.sqli.pg-sqli.pg-sqli + languages: + - go + message: 'Detected string concatenation with a non-literal variable in a go-pg SQL + statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries instead of string concatenation. You can use parameterized queries like + so: ''(SELECT ? FROM table, data1)''' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + references: + - https://pg.uptrace.dev/ + - https://pkg.go.dev/github.com/go-pg/pg/v10 + category: security + technology: + - go-pg + confidence: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-sqli.pg-sqli + shortlink: https://sg.run/Al94 + semgrep.dev: + rule: + r_id: 10294 + rv_id: 1262953 + rule_id: AbUWXY + version_id: BjTkZbQ + url: https://semgrep.dev/playground/r/BjTkZbQ/go.lang.security.audit.sqli.pg-sqli.pg-sqli + origin: community + severity: ERROR + patterns: + - pattern-either: + - patterns: + - pattern: | + $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = fmt.Sprintf("...", $PARAM1, ...) + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: | + $DB = pg.Connect(...) + ... + - pattern-inside: | + func $FUNCNAME(..., $DB *pg.DB, ...) { + ... + } + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecContext|ExecOne|ExecOneContext|Query|QueryOne|QueryContext|QueryOneContext)$ +- id: python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli + languages: + - python + message: 'Detected string concatenation with a non-literal variable in an aiopg + Python SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries instead. You can create parameterized queries like so: ''cur.execute("SELECT + %s FROM table", (user_value,))''.' + metadata: + references: + - https://github.com/aio-libs/aiopg + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aiopg + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli + shortlink: https://sg.run/WgGL + semgrep.dev: + rule: + r_id: 10309 + rv_id: 1263512 + rule_id: DbUWRY + version_id: GxTke3z + url: https://semgrep.dev/playground/r/GxTke3z/python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: $CUR.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = '...'.format(...) + ... + - pattern-inside: | + $QUERY = '...' % (...) + ... + - pattern-inside: | + $QUERY = f'...{$USERINPUT}...' + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern-not-inside: | + $QUERY = '...'.format() + ... + - pattern-not-inside: | + $QUERY = '...' % () + ... + - pattern: $CUR.$METHOD(..., $X + $Y, ...) + - pattern: $CUR.$METHOD(..., '...'.format(...), ...) + - pattern: $CUR.$METHOD(..., '...' % (...), ...) + - pattern: $CUR.$METHOD(..., f'...{$USERINPUT}...', ...) + - pattern-either: + - pattern-inside: | + $CONN = await aiopg.connect(...) + ... + $CUR = await $CONN.cursor(...) + ... + - pattern-inside: | + $POOL = await aiopg.create_pool(...) + ... + async with $POOL.acquire(...) as $CONN: + ... + async with $CONN.cursor(...) as $CUR: + ... + - pattern-inside: | + $POOL = await aiopg.create_pool(...) + ... + with (await $POOL.cursor(...)) as $CUR: + ... + - pattern-inside: | + $POOL = await aiopg.create_pool(...) + ... + async with $POOL as $CONN: + ... + $CUR = await $CONN.cursor(...) + ... + - pattern-inside: | + $POOL = await aiopg.create_pool(...) + ... + async with $POOL.cursor(...) as $CUR: + ... + - pattern-not: $CUR.$METHOD(..., "..." + "...", ...) + - pattern-not: $CUR.$METHOD(..., '...'.format(), ...) + - pattern-not: $CUR.$METHOD(..., '...'%(), ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(execute)$ + severity: WARNING +- id: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli + languages: + - python + message: 'Detected string concatenation with a non-literal variable in a asyncpg + Python SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can create parameterized queries like + so: ''conn.fetch("SELECT $1 FROM table", value)''. You can also create prepared + statements with ''Connection.prepare'': ''stmt = conn.prepare("SELECT $1 FROM + table"); await stmt.fetch(user_value)''' + metadata: + references: + - https://github.com/MagicStack/asyncpg + - https://magicstack.github.io/asyncpg/current/ + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - asyncpg + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli + shortlink: https://sg.run/0nBB + semgrep.dev: + rule: + r_id: 10310 + rv_id: 1263513 + rule_id: WAUZqq + version_id: RGT0L8K + url: https://semgrep.dev/playground/r/RGT0L8K/python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: $CONN.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = '...'.format(...) + ... + - pattern-inside: | + $QUERY = '...' % (...) + ... + - pattern-inside: | + $QUERY = f'...{$USERINPUT}...' + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern-not-inside: | + $QUERY = '...'.format() + ... + - pattern-not-inside: | + $QUERY = '...' % () + ... + - pattern: $CONN.$METHOD(..., $X + $Y, ...) + - pattern: $CONN.$METHOD(..., $Y.format(...), ...) + - pattern: $CONN.$METHOD(..., '...'.format(...), ...) + - pattern: $CONN.$METHOD(..., '...' % (...), ...) + - pattern: $CONN.$METHOD(..., f'...{$USERINPUT}...', ...) + - pattern-either: + - pattern-inside: | + $CONN = await asyncpg.connect(...) + ... + - pattern-inside: | + async with asyncpg.create_pool(...) as $CONN: + ... + - pattern-inside: | + async with $POOL.acquire(...) as $CONN: + ... + - pattern-inside: | + $CONN = await $POOL.acquire(...) + ... + - pattern-inside: | + def $FUNCNAME(..., $CONN: Connection, ...): + ... + - pattern-inside: | + def $FUNCNAME(..., $CONN: asyncpg.Connection, ...): + ... + - pattern-not: $CONN.$METHOD(..., "..." + "...", ...) + - pattern-not: $CONN.$METHOD(..., '...'.format(), ...) + - pattern-not: $CONN.$METHOD(..., '...'%(), ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(fetch|fetchrow|fetchval|execute|executemany|prepare|cursor|copyfromquery)$ + severity: WARNING +- id: python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli + languages: + - python + message: 'Detected string concatenation with a non-literal variable in a pg8000 + Python SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can create parameterized queries like + so: ''conn.run("SELECT :value FROM table", value=myvalue)''. You can also create + prepared statements with ''conn.prepare'': ''conn.prepare("SELECT (:v) FROM table")''' + metadata: + references: + - https://github.com/tlocke/pg8000 + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - pg8000 + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli + shortlink: https://sg.run/KWAL + semgrep.dev: + rule: + r_id: 10311 + rv_id: 1263514 + rule_id: 0oUEKo + version_id: A8TgdKN + url: https://semgrep.dev/playground/r/A8TgdKN/python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: $CONN.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = '...'.format(...) + ... + - pattern-inside: | + $QUERY = '...' % (...) + ... + - pattern-inside: | + $QUERY = f'...{$USERINPUT}...' + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern-not-inside: | + $QUERY = '...'.format() + ... + - pattern-not-inside: | + $QUERY = '...' % () + ... + - pattern: $CONN.$METHOD(..., $X + $Y, ...) + - pattern: $CONN.$METHOD(..., '...'.format(...), ...) + - pattern: $CONN.$METHOD(..., '...' % (...), ...) + - pattern: $CONN.$METHOD(..., f'...{$USERINPUT}...', ...) + - pattern-either: + - pattern-inside: | + $CONN = pg8000.native.Connection(...) + ... + - pattern-inside: | + $CONN = pg8000.dhapi.connect(...) + ... + - pattern-inside: | + $CONN1 = pg8000.connect(...) + ... + $CONN = $CONN1.cursor(...) + ... + - pattern-inside: | + $CONN = pg8000.connect(...) + ... + - pattern-not: $CONN.$METHOD(..., "..." + "...", ...) + - pattern-not: $CONN.$METHOD(..., '...'.format(), ...) + - pattern-not: $CONN.$METHOD(..., '...'%(), ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(run|execute|executemany|prepare)$ + severity: WARNING +- id: python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli + languages: + - python + message: 'Detected string concatenation with a non-literal variable in a psycopg2 + Python SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use prepared statements by creating + a ''sql.SQL'' string. You can also use the pyformat binding style to create parameterized + queries. For example: ''cur.execute(SELECT * FROM table WHERE name=%s, user_input)''' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + references: + - https://www.psycopg.org/docs/sql.html + category: security + technology: + - psycopg + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli + shortlink: https://sg.run/qrLe + semgrep.dev: + rule: + r_id: 10312 + rv_id: 1263515 + rule_id: KxU4Kg + version_id: BjTkZl1 + url: https://semgrep.dev/playground/r/BjTkZl1/python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: $CUR.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: | + $QUERY = $X + $Y + ... + - pattern-inside: | + $QUERY += $X + ... + - pattern-inside: | + $QUERY = '...'.format(...) + ... + - pattern-inside: | + $QUERY = '...' % (...) + ... + - pattern-inside: | + $QUERY = f'...{$USERINPUT}...' + ... + - pattern-not-inside: | + $QUERY += "..." + ... + - pattern-not-inside: | + $QUERY = "..." + "..." + ... + - pattern-not-inside: | + $QUERY = '...'.format() + ... + - pattern-not-inside: | + $QUERY = '...' % () + ... + - pattern: $CUR.$METHOD(..., $X + $Y, ...) + - pattern: $CUR.$METHOD(..., '...'.format(...), ...) + - pattern: $CUR.$METHOD(..., '...' % (...), ...) + - pattern: $CUR.$METHOD(..., f'...{$USERINPUT}...', ...) + - pattern-either: + - pattern-inside: | + $CONN = psycopg2.connect(...) + ... + $CUR = $CONN.cursor(...) + ... + - pattern-inside: | + $CONN = psycopg2.connect(...) + ... + with $CONN.cursor(...) as $CUR: + ... + - pattern-not: $CUR.$METHOD(..., "..." + "...", ...) + - pattern-not: $CUR.$METHOD(..., '...'.format(), ...) + - pattern-not: $CUR.$METHOD(..., '...'%(), ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(execute|executemany|mogrify)$ + severity: WARNING +- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + mode: taint + pattern-propagators: + - pattern: $X << $Y + from: $Y + to: $X + pattern-sources: + - pattern-either: + - pattern: | + params + - pattern: | + cookies + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $CON = PG.connect(...) + ... + - pattern-inside: | + $CON = PG::Connection.open(...) + ... + - pattern-inside: | + $CON = PG::Connection.new(...) + ... + - pattern-either: + - pattern: | + $CON.$METHOD($X,...) + - pattern: | + $CON.$METHOD $X, ... + - focus-metavariable: $X + - metavariable-regex: + metavariable: $METHOD + regex: ^(exec|exec_params)$ + languages: + - ruby + message: 'Detected string concatenation with a non-literal variable in a pg Ruby + SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use parameterized queries like + so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And + you can use prepared statements with `exec_prepared`.' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + shortlink: https://sg.run/kL0o + semgrep.dev: + rule: + r_id: 10328 + rv_id: 1263628 + rule_id: NbUAz7 + version_id: 2KTv2y2 + url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + origin: community + severity: WARNING +- id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + pattern: management.endpoints.web.exposure.include=* + message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints + such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless + you have Spring Security enabled or another means to protect these endpoints, + this functionality is available without authentication, causing a significant + security risk. + severity: ERROR + languages: + - generic + paths: + include: + - '*properties' + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + category: security + technology: + - spring + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + shortlink: https://sg.run/L0vY + semgrep.dev: + rule: + r_id: 10439 + rv_id: 1263077 + rule_id: EwU4vg + version_id: xyTjzwp + url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + origin: community +- id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + patterns: + - pattern-either: + - pattern: | + proxy_http_version 1.1 ...; + ... + proxy_set_header Upgrade ...; + ... + proxy_set_header Connection ...; + - pattern: | + proxy_set_header Upgrade ...; + ... + proxy_set_header Connection ...; + ... + proxy_http_version 1.1 ...; + - pattern: | + proxy_set_header Upgrade ...; + ... + proxy_http_version 1.1 ...; + ... + proxy_set_header Connection ...; + - pattern-inside: | + location ... { + ... + } + languages: + - generic + severity: WARNING + message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading + HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which + can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted + HTTP traffic directly to back-end servers. To mitigate: WebSocket support required: + Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket). + WebSocket support not required: Do not forward Upgrade headers.' + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + metadata: + cwe: + - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response + Smuggling'')' + references: + - https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + shortlink: https://sg.run/ploZ + semgrep.dev: + rule: + r_id: 10562 + rv_id: 1262679 + rule_id: 6JUq0Z + version_id: nWT2Lyp + url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + origin: community +- id: python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query + message: 'Avoiding SQL string concatenation: untrusted input concatenated with raw + SQL query can result in SQL Injection. In order to execute raw query safely, prepared + statement should be used. SQLAlchemy provides TextualSQL to easily used prepared + statement with named parameters. For complex SQL composition, use SQL Expression + Language or Schema Definition Language. In most cases, SQLAlchemy ORM will be + a better option.' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column + category: security + technology: + - sqlalchemy + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query + shortlink: https://sg.run/2b1L + semgrep.dev: + rule: + r_id: 10563 + rv_id: 1263578 + rule_id: oqUz5y + version_id: bZT53rp + url: https://semgrep.dev/playground/r/bZT53rp/python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query + origin: community + severity: ERROR + languages: + - python + pattern-either: + - pattern: | + $CONNECTION.execute( $SQL + ..., ... ) + - pattern: | + $CONNECTION.execute( $SQL % (...), ...) + - pattern: | + $CONNECTION.execute( $SQL.format(...), ... ) + - pattern: | + $CONNECTION.execute(f"...{...}...", ...) + - patterns: + - pattern-inside: | + $QUERY = $SQL + ... + ... + - pattern: | + $CONNECTION.execute($QUERY, ...) + - patterns: + - pattern-inside: | + $QUERY = $SQL % (...) + ... + - pattern: | + $CONNECTION.execute($QUERY, ...) + - patterns: + - pattern-inside: | + $QUERY = $SQL.format(...) + ... + - pattern: | + $CONNECTION.execute($QUERY, ...) + - patterns: + - pattern-inside: | + $QUERY = f"...{...}..." + ... + - pattern: | + $CONNECTION.execute($QUERY, ...) +- id: javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli + message: 'Detected string concatenation with a non-literal variable in a node-postgres + JS SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use parameterized statements like + so: `client.query(''SELECT $1 from table'', [userinput])`' + metadata: + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + references: + - https://node-postgres.com/features/queries + category: security + technology: + - node-postgres + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli + shortlink: https://sg.run/0n3v + semgrep.dev: + rule: + r_id: 10710 + rv_id: 1263208 + rule_id: ReUPN9 + version_id: 5PTo1BA + url: https://semgrep.dev/playground/r/5PTo1BA/javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + function ... (...,$FUNC,...) { + ... + } + - focus-metavariable: $FUNC + - pattern-not-inside: | + $F. ... .$SOURCE(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + const { $CLIENT } = require('pg') + ... + - pattern-inside: | + var { $CLIENT } = require('pg') + ... + - pattern-inside: | + let { $CLIENT } = require('pg') + ... + - pattern-either: + - pattern-inside: | + $DB = new $CLIENT(...) + ... + - pattern-inside: | + $NEWPOOL = new $CLIENT(...) + ... + $NEWPOOL.connect((..., $DB, ...) => { + ... + }) + - pattern: $DB.query($QUERY,...) + - focus-metavariable: $QUERY +- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + category: security + technology: + - .net + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + shortlink: https://sg.run/ZeXW + semgrep.dev: + rule: + r_id: 11135 + rv_id: 1262635 + rule_id: bwUOjK + version_id: nWT2LGp + url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + origin: community + message: The BinaryFormatter type is dangerous and is not recommended for data processing. + Applications should stop using BinaryFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. BinaryFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Binary; + ... + - pattern: | + new BinaryFormatter(); +- id: csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://github.com/mgholam/fastJSON#security-warning-update + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization + shortlink: https://sg.run/nqnd + semgrep.dev: + rule: + r_id: 11136 + rv_id: 1262637 + rule_id: NbUAwk + version_id: 7ZTE3Wn + url: https://semgrep.dev/playground/r/7ZTE3Wn/csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization + origin: community + message: $type extension has the potential to be unsafe, so use it with common sense + and known json sources and not public facing ones to be safe + patterns: + - pattern-inside: | + using fastJSON; + ... + - pattern: | + new JSONParameters + { + BadListTypeChecking = false + } +- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + shortlink: https://sg.run/E5e5 + semgrep.dev: + rule: + r_id: 11137 + rv_id: 1262638 + rule_id: kxURnR + version_id: LjTkgPk + url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + origin: community + message: The FsPickler is dangerous and is not recommended for data processing. + Default configuration tend to insecure deserialization vulnerability. + patterns: + - pattern-inside: | + using MBrace.FsPickler.Json; + ... + - pattern: | + FsPickler.CreateJsonSerializer(); +- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + shortlink: https://sg.run/70pG + semgrep.dev: + rule: + r_id: 11138 + rv_id: 1262641 + rule_id: wdU87G + version_id: QkTGqnA + url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + origin: community + message: The LosFormatter type is dangerous and is not recommended for data processing. + Applications should stop using LosFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. LosFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Web.UI; + ... + - pattern: | + new LosFormatter(); +- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + shortlink: https://sg.run/L0AX + semgrep.dev: + rule: + r_id: 11139 + rv_id: 1262642 + rule_id: x8UW7x + version_id: 3ZT4X6b + url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + origin: community + message: The NetDataContractSerializer type is dangerous and is not recommended + for data processing. Applications should stop using NetDataContractSerializer + as soon as possible, even if they believe the data they're processing to be trustworthy. + NetDataContractSerializer is insecure and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization; + ... + - pattern: | + new NetDataContractSerializer(); +- id: csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization + patterns: + - pattern-either: + - pattern: TypeNameHandling = TypeNameHandling.$TYPEHANDLER + - pattern: | + $SETTINGS.TypeNameHandling = TypeNameHandling.$TYPEHANDLER; + ... + JsonConvert.DeserializeObject<$TYPE>(...,$SETTINGS); + - pattern: | + $SETTINGS.TypeNameHandling = TypeNameHandling.$TYPEHANDLER; + ... + JsonConvert.DeserializeObject(...,$SETTINGS); + - pattern-inside: | + using Newtonsoft.Json; + ... + - metavariable-regex: + metavariable: $TYPEHANDLER + regex: (All|Auto|Objects|Arrays) + message: TypeNameHandling $TYPEHANDLER is unsafe and can lead to arbitrary code + execution in the context of the process. Use a custom SerializationBinder whenever + using a setting other than TypeNameHandling.None. + languages: + - csharp + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://www.newtonsoft.com/json/help/html/T_Newtonsoft_Json_TypeNameHandling.htm#remarks + technology: + - .net + - newtonsoft + - json + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization + shortlink: https://sg.run/8n2g + semgrep.dev: + rule: + r_id: 11140 + rv_id: 1262643 + rule_id: OrUGgl + version_id: 44TEjgG + url: https://semgrep.dev/playground/r/44TEjgG/csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization + origin: community +- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + shortlink: https://sg.run/gJnR + semgrep.dev: + rule: + r_id: 11141 + rv_id: 1262644 + rule_id: eqUvND + version_id: PkTR30n + url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + origin: community + message: The SoapFormatter type is dangerous and is not recommended for data processing. + Applications should stop using SoapFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. SoapFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Soap; + ... + - pattern: | + new SoapFormatter(); +- id: csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization + severity: ERROR + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.web.script.serialization.simpletyperesolver?view=netframework-4.8#remarks + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization + shortlink: https://sg.run/0nJq + semgrep.dev: + rule: + r_id: 11198 + rv_id: 1262640 + rule_id: PeUkrK + version_id: gETB7Jr + url: https://semgrep.dev/playground/r/gETB7Jr/csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization + origin: community + message: The SimpleTypeResolver class is insecure and should not be used. Using + SimpleTypeResolver to deserialize JSON could allow the remote client to execute + malicious code within the app and take control of the web server. + patterns: + - pattern-inside: | + using System.Web.Script.Serialization; + ... + - pattern: | + new JavaScriptSerializer((SimpleTypeResolver $RESOLVER)) +- id: csharp.lang.security.injections.os-command.os-command-injection + severity: ERROR + languages: + - csharp + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/csharp.lang.security.injections.os-command.os-command-injection + shortlink: https://sg.run/Ze6p + semgrep.dev: + rule: + r_id: 11479 + rv_id: 1262634 + rule_id: 9AUOjg + version_id: ZRTKAGe + url: https://semgrep.dev/playground/r/ZRTKAGe/csharp.lang.security.injections.os-command.os-command-injection + origin: community + message: The software constructs all or part of an OS command using externally-influenced + input from an upstream component, but it does not neutralize or incorrectly neutralizes + special elements that could modify the intended OS command when it is sent to + a downstream component. + patterns: + - pattern-inside: | + using System.Diagnostics; + ... + - pattern-inside: | + public $T $F(..., $ARG, ...) + { + ... + } + - pattern-either: + - patterns: + - pattern: | + Process.Start($ARG, ...); + - focus-metavariable: $ARG + - patterns: + - pattern-inside: | + Process $PROC = new Process(); + ... + - pattern-either: + - pattern-inside: | + $PROC.StartInfo.FileName = $ARG; + ... + - pattern-inside: | + $PROC.StartInfo.Arguments = <... $ARG ...>; + ... + - pattern: | + $PROC.Start(); + - patterns: + - patterns: + - pattern-inside: | + ProcessStartInfo $PSINFO = new ProcessStartInfo() + { + ... + }; + ... + - pattern-either: + - pattern-inside: | + FileName = $ARG; + ... + - pattern-inside: | + Arguments = <... $ARG ...>; + ... + - pattern: | + Process.Start($PSINFO); + - focus-metavariable: $PSINFO + - patterns: + - pattern-inside: | + Process $PROC = new Process() + { + StartInfo = new ProcessStartInfo() + { + ... + } + }; + ... + - pattern-either: + - pattern-inside: | + FileName = $ARG; + ... + - pattern-inside: | + Arguments = $ARG; + ... + - pattern: | + $PROC.Start(); +- id: generic.secrets.security.detected-github-token.detected-github-token + patterns: + - pattern-either: + - pattern: | + $VAR = $SECRET + - pattern: | + $VAR: $SECRET + - pattern: | + $VAR = '$SECRET' + - pattern: | + $VAR: '$SECRET' + - pattern: | + '$VAR' = '$SECRET' + - pattern: | + '$VAR': '$SECRET' + - pattern: | + "[hH][tT][tT][pP][sS]?://.*$SECRET.*" + - metavariable-regex: + metavariable: $SECRET + regex: gh[pousr]_[A-Za-z0-9_]{36,251} + - metavariable-analysis: + analyzer: entropy + metavariable: $SECRET + languages: + - generic + message: GitHub Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.blog/changelog/2021-03-04-authentication-token-format-updates/ + category: security + technology: + - secrets + - github + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-github-token.detected-github-token + shortlink: https://sg.run/PpOv + semgrep.dev: + rule: + r_id: 11589 + rv_id: 1262871 + rule_id: eqUv7b + version_id: bZT5397 + url: https://semgrep.dev/playground/r/bZT5397/generic.secrets.security.detected-github-token.detected-github-token + origin: community +- id: trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil + message: The `func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error` function does + not handle `nil` argument, as the `ServerCodec` interface requires. An incorrect + implementation could lead to denial of service + languages: + - go + severity: WARNING + metadata: + category: security + cwe: 'CWE-476: NULL Pointer Dereference' + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: LOW + technology: + - --no-technology-- + description: Possible incorrect `ServerCodec` interface implementation + references: + - https://github.com/golang/go/blob/go1.15.2/src/net/rpc/server.go#L643-L658 + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil + shortlink: https://sg.run/lx09 + semgrep.dev: + rule: + r_id: 11757 + rv_id: 833272 + rule_id: QrUp7k + version_id: yeTN1ek + url: https://semgrep.dev/playground/r/yeTN1ek/trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil + origin: community + patterns: + - pattern: | + func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { + ... + } + - pattern-not: | + func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { + ... + if $ARG == nil { ... } + ... + } + - pattern-not: | + func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { + ... + if $ARG != nil { ... } + ... + } +- id: trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast + message: Downcasting or changing sign of an integer with `$CAST_METHOD` method + languages: + - go + severity: WARNING + metadata: + category: security + cwe: 'CWE-681: Incorrect Conversion between Numeric Types' + subcategory: + - audit + confidence: HIGH + likelihood: LOW + impact: MEDIUM + technology: + - --no-technology-- + description: Integer underflows + references: + - https://github.com/golang/go/issues/30209 + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast + shortlink: https://sg.run/65WB + semgrep.dev: + rule: + r_id: 11759 + rv_id: 833273 + rule_id: 4bU2AZ + version_id: rxTDzNy + url: https://semgrep.dev/playground/r/rxTDzNy/trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast + origin: community + pattern-either: + - patterns: + - metavariable-pattern: + metavariable: $CAST_METHOD + pattern-either: + - pattern: uint8 + - pattern: uint16 + - pattern: uint32 + - pattern: int8 + - pattern: int16 + - pattern: int32 + - pattern-either: + - pattern: | + $X, ... = strconv.Atoi(...) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 64) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 64) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.Atoi(...) + ... + uint64($X) + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 64) + ... + uint64($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 64) + ... + int64($X) + - patterns: + - metavariable-pattern: + metavariable: $CAST_METHOD + pattern-either: + - pattern: uint8 + - pattern: uint16 + - pattern: int8 + - pattern: int16 + - pattern-either: + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 32) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 32) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 32) + ... + uint32($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 32) + ... + int32($X) + - patterns: + - metavariable-pattern: + metavariable: $CAST_METHOD + pattern-either: + - pattern: uint8 + - pattern: int8 + - pattern-either: + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 16) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 16) + ... + $CAST_METHOD($X) + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 16) + ... + uint16($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 16) + ... + int16($X) + - pattern: | + $X, ... = strconv.ParseInt(..., ..., 8) + ... + uint8($X) + - pattern: | + $X, ... = strconv.ParseUint(..., ..., 8) + ... + int8($X) +- id: trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied + message: A `sync.Mutex` is copied in function `$FUNC` given that `$T` is value receiver. As + a result, the struct `$T` may not be locked as intended + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' + subcategory: + - vuln + confidence: HIGH + likelihood: HIGH + impact: LOW + technology: + - --no-technology-- + description: Copying of `sync.Mutex` via value receivers + references: + - https://go101.org/article/concurrent-common-mistakes.html + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied + shortlink: https://sg.run/owlR + semgrep.dev: + rule: + r_id: 11760 + rv_id: 833274 + rule_id: PeUBW1 + version_id: bZTBelR + url: https://semgrep.dev/playground/r/bZTBelR/trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied + origin: community + patterns: + - pattern-either: + - pattern: | + func ($T $TYPE) $FUNC(...){ + ... + $T.Lock() + ... + } + - pattern: | + func ($T $TYPE) $FUNC(...){ + ... + $T.RLock() + ... + } + - pattern-not: | + func ($T2 *$TYPE2) $FUNC(...){ + ... + } +- id: trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine + message: | + Calling `$WG.Add` inside of an anonymous goroutine may result in `$WG.Wait` + waiting for more or less calls to `$WG.Done()` than expected + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-667: Improper Locking' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + technology: + - --no-technology-- + description: Calls to `sync.WaitGroup.Add` inside of anonymous goroutines + references: + - https://go101.org/article/concurrent-common-mistakes.html + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine + shortlink: https://sg.run/z98W + semgrep.dev: + rule: + r_id: 11761 + rv_id: 833276 + rule_id: JDUQ3v + version_id: kbT2l5k + url: https://semgrep.dev/playground/r/kbT2l5k/trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine + origin: community + patterns: + - pattern-either: + - pattern: | + $WG := &sync.WaitGroup{} + ... + go func(...) { + ... + $WG.Add(...) + ... + }(...) + ... + $WG.Wait() + - pattern: | + var $WG sync.WaitGroup + ... + go func(...) { + ... + $WG.Add(...) + ... + }(...) + ... + $WG.Wait() + - pattern-not-inside: | + for ... { + ... + $WG.Add(...) + ... + } +- id: trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop + message: Calling `$WG.Wait()` inside a loop blocks the call to `$WG.Done()` + languages: + - go + severity: WARNING + metadata: + category: security + cwe: 'CWE-667: Improper Locking' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + technology: + - --no-technology-- + description: Calls to `sync.WaitGroup.Wait` inside a loop + references: + - https://go101.org/article/concurrent-common-mistakes.html + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop + shortlink: https://sg.run/pkGL + semgrep.dev: + rule: + r_id: 11762 + rv_id: 833277 + rule_id: 5rU8Po + version_id: w8TAx58 + url: https://semgrep.dev/playground/r/w8TAx58/trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop + origin: community + patterns: + - pattern-either: + - pattern: | + var $WG sync.WaitGroup + ... + for ... { + ... + go func(...){ + ... + defer $WG.Done() + ... + }() + ... + $WG.Wait() + ... + } + - pattern: | + $WG := &sync.WaitGroup{} + ... + for ... { + ... + go func(...){ + ... + defer $WG.Done() + ... + }() + ... + $WG.Wait() + ... + } + - pattern: | + var $WG sync.WaitGroup + ... + for ... { + ... + go func(...){ + ... + $WG.Done() + ... + }() + ... + $WG.Wait() + ... + } + - pattern: | + $WG := &sync.WaitGroup{} + ... + for ... { + ... + go func(...){ + ... + $WG.Done() + ... + }() + ... + $WG.Wait() + ... + } +- id: trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal + message: Possible path traversal through `tarfile.open($PATH).extractall()` if the + source tar is controlled by an attacker + languages: + - python + severity: ERROR + metadata: + category: security + cwe: 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + technology: + - --no-technology-- + description: Potential path traversal in call to `extractall` for a `tarfile` + references: + - https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall + license: AGPL-3.0 license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal + shortlink: https://sg.run/2RLD + semgrep.dev: + rule: + r_id: 11763 + rv_id: 833310 + rule_id: GdUZxq + version_id: pZTXjAW + url: https://semgrep.dev/playground/r/pZTXjAW/trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal + origin: community + patterns: + - pattern-either: + - pattern: | + with tarfile.open(...) as $TAR: + ... + $TAR.extractall(...) + - pattern: | + tarfile.open(...).extractall(...) + - pattern: | + $TAR = tarfile.open(...) + ... + $TAR.extractall(...) + - pattern-not: | + with tarfile.open(...) as $TAR: + ... + $TAR.extractall(..., members=$MEMBERS, ...) + - pattern-not: | + tarfile.open(...).extractall(..., members=$MEMBERS, ...) + - pattern-not: | + $TAR = tarfile.open(...) + ... + $TAR.extractall(..., members=$MEMBERS, ...) +- id: trailofbits.go.racy-append-to-slice.racy-append-to-slice + message: Appending `$SLICE` from multiple goroutines is not concurrency safe + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization + (''Race Condition'')' + subcategory: + - vuln + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + technology: + - --no-technology-- + description: Concurrent calls to `append` from multiple goroutines + references: + - https://go.dev/blog/maps#concurrency + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.racy-append-to-slice.racy-append-to-slice + shortlink: https://sg.run/jkNY + semgrep.dev: + rule: + r_id: 11865 + rv_id: 833270 + rule_id: ReUoP7 + version_id: 1QTPL3x + url: https://semgrep.dev/playground/r/1QTPL3x/trailofbits.go.racy-append-to-slice.racy-append-to-slice + origin: community + patterns: + - pattern: | + $SLICE = append($SLICE, $ITEM) + - pattern-either: + - pattern-inside: | + var $SLICE []$TYPE + ... + for ... { + ... + go func(...) { + ... + $SLICE = append($SLICE, ...) + ... + }(...) + ... + } + - pattern-inside: | + $SLICE := make([]$TYPE, ...) + ... + for ... { + ... + go func(...) { + ... + $SLICE = append($SLICE, ...) + ... + }(...) + ... + } + - pattern-not-inside: | + $MUTEX.Lock() + ... + $MUTEX.Unlock() + - pattern-not-inside: | + $MUTEX.Lock() + ... + defer $MUTEX.Unlock() + ... +- id: trailofbits.go.racy-write-to-map.racy-write-to-map + message: Writing `$MAP` from multiple goroutines is not concurrency safe + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization + (''Race Condition'')' + subcategory: + - vuln + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + technology: + - --no-technology-- + description: Concurrent writes to the same map in multiple goroutines + references: + - https://go.dev/blog/maps#concurrency + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.racy-write-to-map.racy-write-to-map + shortlink: https://sg.run/1Gnw + semgrep.dev: + rule: + r_id: 11866 + rv_id: 833271 + rule_id: AbUGWD + version_id: 9lTJ0qD + url: https://semgrep.dev/playground/r/9lTJ0qD/trailofbits.go.racy-write-to-map.racy-write-to-map + origin: community + patterns: + - pattern: | + $MAP[$KEY] = $VALUE + - pattern-inside: | + $MAP = make(map[$KTYPE]$VTYPE) + ... + for ... { + ... + go func(...) { + ... + $MAP[$KEY] = $VALUE + ... + }(...) + ... + } + - pattern-not-inside: | + $MUTEX.Lock() + ... + $MUTEX.Unlock() + - pattern-not-inside: | + $MUTEX.Lock() + ... + defer $MUTEX.Unlock() + ... +- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + metadata: + functional-categories: + - crypto::search::randomness::javax.crypto + cwe: + - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' + category: security + source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM + technology: + - java + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + shortlink: https://sg.run/Dww2 + semgrep.dev: + rule: + r_id: 11908 + rv_id: 1263000 + rule_id: GdUZZ3 + version_id: 0bTKzGk + url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + origin: community + languages: + - java + message: 'GCM IV/nonce is reused: encryption can be totally useless' + patterns: + - pattern-either: + - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); + - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., + $NONCE, ...); + severity: ERROR +- id: java.lang.security.audit.java-reverse-shell.java-reverse-shell + patterns: + - pattern-either: + - pattern: | + Socket $S=new Socket(...); + ... + InputStream $SI = $S.getInputStream(); + ... + while(!$S.isClosed()) + { + ... + while($SI.available()>0)$PO.write($SI.read()); + ... + $SO.flush(); + ... + } + - pattern-inside: | + Process $P=new ProcessBuilder(...).redirectErrorStream(true).start(); + ... + $P.destroy(); + message: Semgrep found potential reverse shell behavior + severity: WARNING + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + category: security + technology: + - java + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.java-reverse-shell.java-reverse-shell + shortlink: https://sg.run/kkrX + semgrep.dev: + rule: + r_id: 11928 + rv_id: 1263025 + rule_id: KxUY7b + version_id: 1QTyp3Z + url: https://semgrep.dev/playground/r/1QTyp3Z/java.lang.security.audit.java-reverse-shell.java-reverse-shell + origin: community + languages: + - java +- id: typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard + message: 'Unescaped ''.'' character in CORS domain regex $CORS: $PATTERN' + metadata: + cwe: + - 'CWE-183: Permissive List of Allowed Inputs' + category: security + technology: + - cors + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard + shortlink: https://sg.run/w13x + semgrep.dev: + rule: + r_id: 11929 + rv_id: 1263908 + rule_id: qNUbXo + version_id: WrTqKwN + url: https://semgrep.dev/playground/r/WrTqKwN/typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard + origin: community + languages: + - ts + severity: WARNING + patterns: + - pattern-either: + - pattern: $CORS = [...,/$PATTERN/,...] + - pattern: $CORS = /$PATTERN/ + - focus-metavariable: $PATTERN + - metavariable-regex: + metavariable: $PATTERN + regex: .+?(?, ...) + - pattern: format_html("..." % ..., ...) + - pattern: format_html("...".format(...), ...) +- id: python.pymongo.security.mongodb.mongo-client-bad-auth + pattern: | + pymongo.MongoClient(..., authMechanism='MONGODB-CR') + message: Warning MONGODB-CR was deprecated with the release of MongoDB 3.6 and is + no longer supported by MongoDB 4.0 (see https://api.mongodb.com/python/current/examples/authentication.html + for details). + fix-regex: + regex: MONGODB-CR + replacement: SCRAM-SHA-256 + severity: WARNING + languages: + - python + metadata: + cwe: + - 'CWE-477: Use of Obsolete Function' + category: security + technology: + - pymongo + references: + - https://cwe.mitre.org/data/definitions/477.html + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/python.pymongo.security.mongodb.mongo-client-bad-auth + shortlink: https://sg.run/YXRd + semgrep.dev: + rule: + r_id: 12658 + rv_id: 946422 + rule_id: d8UlOX + version_id: 0bT15XY + url: https://semgrep.dev/playground/r/0bT15XY/python.pymongo.security.mongodb.mongo-client-bad-auth + origin: community +- id: java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor + languages: + - java + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://securitylab.github.com/research/swagger-yaml-parser-vulnerability/#snakeyaml-deserialization-vulnerability + category: security + technology: + - snakeyaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor + shortlink: https://sg.run/L8qY + semgrep.dev: + rule: + r_id: 12683 + rv_id: 1263067 + rule_id: 6JU67x + version_id: X0Tzynw + url: https://semgrep.dev/playground/r/X0Tzynw/java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor + origin: community + message: Used SnakeYAML org.yaml.snakeyaml.Yaml() constructor with no arguments, + which is vulnerable to deserialization attacks. Use the one-argument Yaml(...) + constructor instead, with SafeConstructor or a custom Constructor as the argument. + patterns: + - pattern: | + $Y = new org.yaml.snakeyaml.Yaml(); + ... + $Y.load(...); + severity: WARNING +- id: javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp + message: RegExp() called with a `$ARG` function argument, this might allow an attacker + to cause a Regular Expression Denial-of-Service (ReDoS) within your application + as RegExP blocks the main thread. For this reason, it is recommended to use hardcoded + regexes instead. If your regex is run on user-controlled input, consider performing + input validation or use a regex checking/sanitization library such as https://www.npmjs.com/package/recheck + to verify that the regex does not appear vulnerable to ReDoS. + metadata: + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-non-literal-regexp.js + category: security + technology: + - javascript + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp + shortlink: https://sg.run/gr65 + semgrep.dev: + rule: + r_id: 12685 + rv_id: 1263195 + rule_id: zdU1gD + version_id: 5PTo1Yn + url: https://semgrep.dev/playground/r/5PTo1Yn/javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + function ... (...,$ARG,...) {...} + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new RegExp($ARG, ...) + - pattern: RegExp($ARG, ...) + - pattern-not: RegExp("...", ...) + - pattern-not: new RegExp("...", ...) + - pattern-not: RegExp(/.../, ...) + - pattern-not: new RegExp(/.../, ...) +- id: ocaml.lang.portability.crlf-support.broken-input-line + pattern: | + input_line + message: '''input_line'' leaves a ''\r'' (CR) character when reading lines from + a Windows text file, whose lines end in "\r\n" (CRLF). This is a problem for any + Windows file that is being read either on a Unix-like platform or on Windows in + binary mode. If the code already takes care of removing any trailing ''\r'' after + reading the line, add a ''(* nosemgrep *)'' comment to disable this warning.' + languages: + - ocaml + severity: WARNING + metadata: + category: portability + technology: + - ocaml + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.broken-input-line + shortlink: https://sg.run/v2gY + semgrep.dev: + rule: + r_id: 12777 + rv_id: 945971 + rule_id: DbUKZX + version_id: BjT1Ngb + url: https://semgrep.dev/playground/r/BjT1Ngb/ocaml.lang.portability.crlf-support.broken-input-line + origin: community +- id: ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode + pattern: open_in + fix: open_in_bin + message: '''open_in'' behaves differently on Windows and on Unix-like systems with + respect to line endings. To get the same behavior everywhere, use ''open_in_bin'' + or ''open_in_gen [Open_binary]''. If you really want CRLF-to-LF translations to + take place when running on Windows, use ''open_in_gen [Open_text]''.' + languages: + - ocaml + severity: WARNING + metadata: + category: portability + technology: + - ocaml + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode + shortlink: https://sg.run/d0YE + semgrep.dev: + rule: + r_id: 12778 + rv_id: 945972 + rule_id: WAUPAJ + version_id: DkTNpPw + url: https://semgrep.dev/playground/r/DkTNpPw/ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode + origin: community +- id: ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode + pattern: open_out + fix: open_out_bin + message: '''open_out'' behaves differently on Windows and on Unix-like systems with + respect to line endings. To get the same behavior everywhere, use ''open_out_bin'' + or ''open_out_gen [Open_binary]''. If you really want LF-to-CRLF translations + to take place when running on Windows, use ''open_out_gen [Open_text]''.' + languages: + - ocaml + severity: WARNING + metadata: + category: portability + technology: + - ocaml + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode + shortlink: https://sg.run/ZkGw + semgrep.dev: + rule: + r_id: 12779 + rv_id: 945973 + rule_id: 0oUJY9 + version_id: WrTEoXG + url: https://semgrep.dev/playground/r/WrTEoXG/ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode + origin: community +- id: ocaml.lang.portability.slash-tmp.not-portable-tmp-string + pattern: | + "=~/\/tmp/" + message: You should probably use Filename.get_temp_dirname(). + languages: + - ocaml + severity: WARNING + metadata: + category: portability + technology: + - ocaml + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ocaml.lang.portability.slash-tmp.not-portable-tmp-string + shortlink: https://sg.run/Q4ZZ + semgrep.dev: + rule: + r_id: 12786 + rv_id: 945974 + rule_id: zdU100 + version_id: 0bT158q + url: https://semgrep.dev/playground/r/0bT158q/ocaml.lang.portability.slash-tmp.not-portable-tmp-string + origin: community +- id: javascript.express.security.express-data-exfiltration.express-data-exfiltration + message: Depending on the context, user control data in `Object.assign` can cause + web response to include data that it should not have or can lead to a mass assignment + vulnerability. + metadata: + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + references: + - https://en.wikipedia.org/wiki/Mass_assignment_vulnerability + - https://cheatsheetseries.owasp.org/cheatsheets/Mass_Assignment_Cheat_Sheet.html + category: security + technology: + - express + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/javascript.express.security.express-data-exfiltration.express-data-exfiltration + shortlink: https://sg.run/pkpL + semgrep.dev: + rule: + r_id: 12818 + rv_id: 1263163 + rule_id: ReUo60 + version_id: 6xT290x + url: https://semgrep.dev/playground/r/6xT290x/javascript.express.security.express-data-exfiltration.express-data-exfiltration + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - pattern: Object.assign(...) +- id: javascript.lang.security.insecure-object-assign.insecure-object-assign + message: Depending on the context, user control data in `Object.assign` can cause + web response to include data that it should not have or can lead to a mass assignment + vulnerability. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Mass_Assignment_Cheat_Sheet.html + - https://en.wikipedia.org/wiki/Mass_assignment_vulnerability + category: security + technology: + - javascript + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.lang.security.insecure-object-assign.insecure-object-assign + shortlink: https://sg.run/2R0D + semgrep.dev: + rule: + r_id: 12819 + rv_id: 1263219 + rule_id: AbUGOq + version_id: YDTZezg + url: https://semgrep.dev/playground/r/YDTZezg/javascript.lang.security.insecure-object-assign.insecure-object-assign + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: JSON.parse(...) + - pattern-not: JSON.parse("...",...) + pattern-sinks: + - pattern: Object.assign(...) +- id: javascript.express.security.express-vm-injection.express-vm-injection + message: Make sure that unverified user data can not reach `$VM`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection + shortlink: https://sg.run/jkqJ + semgrep.dev: + rule: + r_id: 12821 + rv_id: 1263170 + rule_id: DbUKPX + version_id: 1QTypXQ + url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $VM = require('vm'); + ... + - pattern-either: + - pattern: | + $VM.runInContext(...) + - pattern: | + $VM.runInNewContext(...) + - pattern: | + $VM.compileFunction(...) + - pattern: | + $VM.runInThisContext(...) + - pattern: new $VM.Script(...) +- id: javascript.express.security.express-vm2-injection.express-vm2-injection + message: Make sure that unverified user data can not reach `vm2`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection + shortlink: https://sg.run/1GWv + semgrep.dev: + rule: + r_id: 12822 + rv_id: 1263171 + rule_id: WAUPXJ + version_id: 9lT4bnX + url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + require('vm2') + ... + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $VM = new VM(...) + ... + - pattern-inside: | + $VM = new NodeVM(...) + ... + - pattern: | + $VM.run(...) + - pattern: | + new VM(...).run(...) + - pattern: | + new NodeVM(...).run(...) + - pattern: | + new VMScript(...) + - pattern: | + new VM(...) + - pattern: new NodeVM(...) +- id: generic.secrets.security.detected-jwt-token.detected-jwt-token + pattern-regex: eyJ[A-Za-z0-9-_=]{14,}\.[A-Za-z0-9-_=]{13,}\.?[A-Za-z0-9-_.+/=]*? + languages: + - regex + message: JWT token detected + severity: ERROR + metadata: + source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/jwt.py + category: security + technology: + - secrets + - jwt + confidence: LOW + references: + - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + cwe: + - 'CWE-321: Use of Hard-coded Cryptographic Key' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.secrets.security.detected-jwt-token.detected-jwt-token + shortlink: https://sg.run/05N5 + semgrep.dev: + rule: + r_id: 12854 + rv_id: 1262879 + rule_id: kxU8E8 + version_id: d6Tyxvg + url: https://semgrep.dev/playground/r/d6Tyxvg/generic.secrets.security.detected-jwt-token.detected-jwt-token + origin: community +- id: generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key + pattern-regex: SG\.[a-zA-Z0-9]{22}\.[a-zA-Z0-9-]{43}\b + languages: + - regex + message: SendGrid API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/narendrakadali/gitrob/blob/master/rules/contentsignatures.json + category: security + technology: + - secrets + - sendgrid + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key + shortlink: https://sg.run/qqOy + semgrep.dev: + rule: + r_id: 12856 + rv_id: 1262890 + rule_id: x8U2EG + version_id: PkTR3RD + url: https://semgrep.dev/playground/r/PkTR3RD/generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key + origin: community +- id: generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key + pattern-regex: (?i)snyk.{0,50}['|"|`]?[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}['"\s]? + languages: + - regex + message: Snyk API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - snyk + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key + shortlink: https://sg.run/lxO9 + semgrep.dev: + rule: + r_id: 12857 + rv_id: 1262893 + rule_id: OrUD9J + version_id: GxTkek0 + url: https://semgrep.dev/playground/r/GxTkek0/generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key + origin: community +- id: generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key + pattern-regex: (?i)softlayer.{0,50}["|'|`]?[a-z0-9]{64}["|'|`]? + languages: + - regex + message: SoftLayer API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/softlayer.py + category: security + technology: + - secrets + - softlayer + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key + shortlink: https://sg.run/YXq4 + semgrep.dev: + rule: + r_id: 12858 + rv_id: 1262894 + rule_id: eqUplZ + version_id: RGT0L0o + url: https://semgrep.dev/playground/r/RGT0L0o/generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key + origin: community +- id: javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf + message: User-controllable argument $DATAVAL to $METHOD passed to Axios via internal + handler $INNERFUNC. This could be a server-side request forgery. A user could + call a restricted API or leak internal headers to an unauthorized party. Validate + your user arguments against an allowlist of known URLs, or consider refactoring + so that user-controlled data is not necessary. + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - apollo + - axios + references: + - https://www.cvedetails.com/cve/CVE-2020-28168/ + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf + shortlink: https://sg.run/jkEZ + semgrep.dev: + rule: + r_id: 13021 + rv_id: 1263102 + rule_id: AbUGBR + version_id: K3TKk30 + url: https://semgrep.dev/playground/r/K3TKk30/javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf + origin: community + languages: + - javascript + severity: WARNING + patterns: + - pattern: const $RESPONSE = await axios.request($INNERARG,...) + - pattern-inside: | + Query: { + $METHOD(parent, args, context, info) { + ... + $DATA = args.$DATAVAL + ... + async function $INNERFUNC(...,$INNERARG,...){ + ... + } + ... + return $INNERFUNC(...,$DATA,...) + } + } +- id: javascript.lang.security.audit.code-string-concat.code-string-concat + message: Found data from an Express or Next web request flowing to `eval`. If this + data is user-controllable this can lead to execution of arbitrary system commands + in the context of your application process. Avoid `eval` whenever possible. + options: + interfile: true + metadata: + interfile: true + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval + - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback + - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ + - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html + category: security + technology: + - node.js + - Express + - Next.js + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat + shortlink: https://sg.run/96Yk + semgrep.dev: + rule: + r_id: 13023 + rv_id: 1263192 + rule_id: DbUKEz + version_id: 44TEjYX + url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) + {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + import { ...,$IMPORT,... } from 'next/router' + ... + - pattern-inside: | + import $IMPORT from 'next/router'; + ... + - pattern-either: + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern-either: + - pattern-inside: | + const { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + var { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + let { ...,$PROPS,... } = $ROUTER.query + ... + - focus-metavariable: $PROPS + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern: "$ROUTER.query.$VALUE \n" + - patterns: + - pattern: $IMPORT().query.$VALUE + pattern-sinks: + - patterns: + - pattern: | + eval(...) +- id: yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled + languages: + - yaml + severity: WARNING + message: Do not set FLASK_ENV to "development" since that sets `debug=True` in Flask. + Use "dev" or a similar term instead. + metadata: + owasp: A06:2017 - Security Misconfiguration + cwe: + - 'CWE-489: Active Debug Code' + references: + - https://flask.palletsprojects.com/en/2.0.x/debugging/ + - https://flask.palletsprojects.com/en/2.0.x/config/#ENV + category: security + technology: + - kubernetes + - flask + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled + shortlink: https://sg.run/y6x8 + semgrep.dev: + rule: + r_id: 13024 + rv_id: 947053 + rule_id: WAUP0z + version_id: ZRT3qOw + url: https://semgrep.dev/playground/r/ZRT3qOw/yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled + origin: community + patterns: + - pattern-inside: | + env: [...] + - pattern: | + {name: FLASK_ENV, value: "development"} + fix-regex: + regex: development + replacement: dev +- id: javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli + message: 'Detected string concatenation with a non-literal variable in a `mssql` + JS SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use parameterized statements like + so: `$REQ.input(''USER_ID'', mssql.Int, id);`' + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - mssql + references: + - https://www.npmjs.com/package/mssql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli + shortlink: https://sg.run/lxlB + semgrep.dev: + rule: + r_id: 13157 + rv_id: 1263206 + rule_id: kxU8Pd + version_id: YDTZezY + url: https://semgrep.dev/playground/r/YDTZezY/javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + function ... (...,$FUNC,...) { + ... + } + - focus-metavariable: $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('mssql'); + ... + - pattern-inside: | + import 'mssql'; + ... + - pattern-inside: | + $REQ = $POOL.request(...) + ... + - pattern: | + $REQ.query($QUERY,...) + - focus-metavariable: $QUERY +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `run:` step could allow an attacker to inject their own code into the runner. + This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate + environment variable with `env:` to store the data and use the environment variable + in the `run:` script. Be sure to use double-quotes the environment variable, like + this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + shortlink: https://sg.run/pkzk + semgrep.dev: + rule: + r_id: 13162 + rv_id: 1423395 + rule_id: v8UjQj + version_id: GxTl1DQ + url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `pull_request_target` and checks + out code from the incoming pull request. When using `pull_request_target`, the + Action runs in the context of the target repository, which includes access to + all repository secrets. Normally, this is safe because the Action only runs code + from the target repository, not the incoming PR. However, by checking out the + incoming PR code, you're now using the incoming code for the rest of the action. + You may be inadvertently executing arbitrary code from the incoming PR with access + to repository secrets, which would let an attacker steal repository secrets. This + normally happens by running build scripts (e.g., `npm build` and `make`) or dependency + installation scripts (e.g., `python setup.py install`). Audit your workflow file + to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + for additional mitigations. + metadata: + category: security + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + shortlink: https://sg.run/jkdn + semgrep.dev: + rule: + r_id: 13365 + rv_id: 1413423 + rule_id: d8Ulkd + version_id: O9TQ2nX + url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + origin: community + patterns: + - pattern-either: + - pattern-inside: | + on: + ... + pull_request_target: ... + ... + ... + - pattern-inside: | + on: [..., pull_request_target, ...] + ... + - pattern-inside: | + on: pull_request_target + ... + - pattern-inside: | + jobs: + ... + $JOBNAME: + ... + steps: + ... + - pattern: | + ... + uses: "$ACTION" + with: + ... + ref: $EXPR + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern-inside: ${{ ... }} + - pattern-either: + - pattern: github.event.pull_request ... + - pattern: github.head_ref ... + severity: ERROR +- id: javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop + message: 'Possibility of prototype polluting function detected. By adding or modifying + attributes of an object prototype, it is possible to create attributes that exist + on every object, or replace critical attributes with malicious ones. This can + be problematic if the software depends on existence or non-existence of certain + attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, + toString or valueOf). Possible mitigations might be: freezing the object prototype, + using an object without prototypes (via Object.create(null) ), blocking modifications + of attributes that resolve to object prototype, using Map instead of object.' + metadata: + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + category: security + references: + - https://github.com/HoLyVieR/prototype-pollution-nsec18/blob/master/paper/JavaScript_prototype_pollution_attack_in_NodeJS.pdf + technology: + - typescript + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop + shortlink: https://sg.run/w1DB + semgrep.dev: + rule: + r_id: 13373 + rv_id: 1263203 + rule_id: QrUpbJ + version_id: K3TKkP7 + url: https://semgrep.dev/playground/r/K3TKkP7/javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop + origin: community + languages: + - typescript + - javascript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $SMTH = $SMTH[$A] + - pattern: | + $SMTH = $SMTH[$A] = ... + - pattern: | + $SMTH = $SMTH[$A] && $Z + - pattern: | + $SMTH = $SMTH[$A] || $Z + - pattern-either: + - pattern-inside: | + for(...) { + ... + } + - pattern-inside: | + while(...) { + ... + } + - pattern-inside: | + $X.forEach(function $NAME(...) { + ... + }) + - pattern-not-inside: | + for(var $A = $S; ...; ...) {...} + - pattern-not-inside: | + for($A = $S; ...; ...) {...} + - pattern-not-inside: | + $X.forEach(function $NAME($OBJ, $A,...) {...}) + - metavariable-pattern: + patterns: + - pattern-not: '"..."' + - pattern-not: | + `...${...}...` + - pattern-not: | + ($A: float) + metavariable: $A +- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + languages: + - yaml + severity: WARNING + message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this + workflow permissions to use the `set-env` and `add-path` commands. There is a + vulnerability in these commands that could result in environment variables being + modified by an attacker. Depending on the use of the environment variable, this + could enable an attacker to, at worst, modify the system path to run a different + command than intended, resulting in arbitrary code execution. This could result + in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, + use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + for more information. + metadata: + cwe: + - 'CWE-749: Exposed Dangerous Method or Function' + owasp: A06:2017 - Security Misconfiguration + references: + - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ + - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w + - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + category: security + technology: + - github-actions + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + shortlink: https://sg.run/qq78 + semgrep.dev: + rule: + r_id: 13412 + rv_id: 947039 + rule_id: EwUQ9x + version_id: jQTzq34 + url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + origin: community + patterns: + - pattern-either: + - patterns: + - pattern-inside: '{env: ...}' + - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' +- id: json.aws.security.public-s3-bucket.public-s3-bucket + languages: + - json + message: Detected public S3 bucket. This policy allows anyone to have some kind + of access to the bucket. The exact level of access and types of actions allowed + will depend on the configuration of bucket policy and ACLs. Please review the + bucket configuration to make sure they are set with intended values. + metadata: + category: security + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html + technology: + - aws + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket + shortlink: https://sg.run/lxv5 + semgrep.dev: + rule: + r_id: 13413 + rv_id: 1263254 + rule_id: 7KUpLy + version_id: RGT0Ld0 + url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket + origin: community + patterns: + - pattern-inside: | + $BUCKETNAME: { + "Type": "AWS::S3::Bucket", + "Properties": { + ..., + }, + ..., + } + - pattern-either: + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "RestrictPublicBuckets": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "IgnorePublicAcls": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "BlockPublicAcls": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "BlockPublicPolicy": false, + ..., + }, + severity: WARNING +- id: javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization + message: '`$STR.replace` method will only replace the first occurrence when used + with a string argument ($CHAR). If this method is used for escaping of dangerous + data then there is a possibility for a bypass. Try to use sanitization library + instead or use a Regex with a global flag.' + metadata: + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + category: security + technology: + - javascript + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Encoding + source: https://semgrep.dev/r/javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization + shortlink: https://sg.run/1GbQ + semgrep.dev: + rule: + r_id: 13466 + rv_id: 1263199 + rule_id: d8UlRq + version_id: BjTkZQD + url: https://semgrep.dev/playground/r/BjTkZQD/javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern: | + $STR.replace(($CHAR: string), ...) + - metavariable-regex: + metavariable: $CHAR + regex: ^[\"\']([\'\"\<\>\*\|\{\}\[\]\%\$]{1}|\\n|\\r|\\t|\\&)[\"\']$ +- id: terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges + pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - patterns: + - pattern: | + {..., Action = "*", ...} + - pattern: | + {..., Resource = "*", ...} + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - patterns: + - pattern: | + {..., resources = ["*"], ...} + - pattern: | + {..., actions = ["*"], ...} + message: IAM policies that allow full "*-*" admin privileges violates the principle + of least privilege. This allows an attacker to take full control over all AWS + account resources. Instead, give each user more fine-grained control with only + the privileges they need. $TYPE + metadata: + references: + - https://github.com/bridgecrewio/checkov/blob/master/checkov/terraform/checks/data/aws/AdminPolicyDocument.py + category: security + cwe: + - 'CWE-269: Improper Privilege Management' + technology: + - terraform + - aws + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges + shortlink: https://sg.run/oY0N + semgrep.dev: + rule: + r_id: 13560 + rv_id: 1263889 + rule_id: NbUNDX + version_id: d6Tyxxd + url: https://semgrep.dev/playground/r/d6Tyxxd/terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: | + Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = [..., $ACTION, ...] + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - pattern: | + "chime:CreateApiKey" + - pattern: | + "codepipeline:PollForJobs" + - pattern: | + "cognito-identity:GetOpenIdToken" + - pattern: | + "cognito-identity:GetOpenIdTokenForDeveloperEdentity" + - pattern: | + "cognito-identity:GetCredentialsForIdentity" + - pattern: | + "connect:GetFederationToken" + - pattern: | + "connect:GetFederationTokens" + - pattern: | + "ec2:GetPasswordData" + - pattern: | + "ecr:GetAuthorizationToken" + - pattern: | + "gamelift:RequestUploadCredentials" + - pattern: | + "iam:CreateAccessKey" + - pattern: | + "iam:CreateLoginProfile" + - pattern: | + "iam:CreateServiceSpecificCredential" + - pattern: | + "iam:ResetServiceSpecificCredential" + - pattern: | + "iam:UpdateAccessKey" + - pattern: | + "lightsail:GetInstanceAccessDetails" + - pattern: | + "lightsail:GetRelationalDatabaseMasterUserPassword" + - pattern: | + "rds-db:Connect" + - pattern: | + "redshift:GetClusterCredentials" + - pattern: | + "sso:GetRoleCredentials" + - pattern: | + "mediapackage:RotateChannelCredentials" + - pattern: | + "mediapackage:RotateIngestEndpointCredentials" + - pattern: | + "sts:AssumeRole" + - pattern: | + "sts:AssumeRoleWithSaml" + - pattern: | + "sts:AssumeRoleWithWebIdentity" + - pattern: | + "sts:GetFederationToken" + - pattern: | + "sts:GetSessionToken" + - pattern: | + "ec2:*" + - pattern: | + "codepipeline:*" + - pattern: | + "rds-db:*" + - pattern: | + "connect:*" + - pattern: | + "iam:*" + - pattern: | + "ecr:*" + - pattern: | + "sts:*" + - pattern: | + "chime:*" + - pattern: | + "mediapackage:*" + - pattern: | + "redshift:*" + - pattern: | + "gamelift:*" + - pattern: | + "cognito-identity:*" + - pattern: | + "lightsail:*" + - pattern: | + "sso:*" + message: Ensure IAM policies don't allow credentials exposure. Credentials exposure + actions return credentials as part of the API response, and can possibly lead + to leaking important credentials. Instead, use another action that doesn't return + sensitive data as part of the API response. + metadata: + references: + - https://cloudsplaining.readthedocs.io/en/latest/glossary/credentials-exposure/ + - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMCredentialsExposure.py + category: security + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure + shortlink: https://sg.run/zxY1 + semgrep.dev: + rule: + r_id: 13561 + rv_id: 1263890 + rule_id: kxUwK2 + version_id: ZRTKAAP + url: https://semgrep.dev/playground/r/ZRTKAAP/terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Resource = "*" ...}, + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: | + Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + resources = ["*"] + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = [..., $ACTION, ...] + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - pattern: | + "s3:GetObject" + - pattern: | + "ssm:GetParameter*" + - pattern: | + "secretsmanager:GetSecretValue" + - pattern: | + "rds:CopyDBSnapshot" + - pattern: | + "rds:CreateDBSnapshot" + - pattern: | + "ssm:*" + - pattern: | + "s3:*" + - pattern: | + "rds:*" + - pattern: | + "rn: secretsmanager:*" + message: Ensure that IAM policies don't allow data exfiltration actions that are + not resource-constrained. This can allow the user to read sensitive data they + don't need to read. Instead, make sure that the user granted these privileges + are given these permissions on specific resources. + metadata: + references: + - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMDataExfiltration.py + - https://cloudsplaining.readthedocs.io/en/latest/glossary/data-exfiltration/ + category: security + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration + shortlink: https://sg.run/pYrN + semgrep.dev: + rule: + r_id: 13562 + rv_id: 1263891 + rule_id: wdUj1k + version_id: nWT2LLN + url: https://semgrep.dev/playground/r/nWT2LLN/terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = [..., $ACTION, ...] + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - pattern: | + "iam:AddUserToGroup" + - pattern: | + "iam:CreatePolicyVersion" + - pattern: | + "iam:SetDefaultPolicyVersion" + - pattern: | + "iam:AttachUserPolicy" + - pattern: | + "iam:AttachGroupPolicy" + - pattern: | + "iam:AttachRolePolicy" + - pattern: | + "iam:PutUserPolicy" + - pattern: | + "iam:PutGroupPolicy" + - pattern: | + "iam:PutRolePolicy" + - pattern: | + "glue:UpdateDevEndpoint" + - pattern: | + "iam:*" + - pattern: | + "glue:*" + message: Ensure that actions that can result in privilege escalation are not used. + These actions could potentially result in an attacker gaining full administrator + access of an AWS account. Try not to use these actions. + metadata: + references: + - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ + - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ + category: security + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + technology: + - terraform + - aws + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs + shortlink: https://sg.run/28y5 + semgrep.dev: + rule: + r_id: 13563 + rv_id: 946990 + rule_id: x8UxLq + version_id: o5TZzrP + url: https://semgrep.dev/playground/r/o5TZzrP/terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Resource = $RESOURCE ...}, + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: | + Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + resources = $RESOURCE + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = [..., $ACTION, ...] + - metavariable-pattern: + metavariable: $RESOURCE + pattern-either: + - pattern-regex: .*\*.* + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - pattern: | + "iam:CreateAccessKey" + - pattern: | + "iam:CreateLoginProfile" + - pattern: | + "iam:UpdateLoginProfile" + - pattern: | + "iam:*" + message: Ensure that IAM policies with permissions on other users don't allow for + privilege escalation. This can lead to an attacker gaining full administrator + access of AWS accounts. Instead, specify which user the permission should be used + on or do not use the listed actions. $RESOURCE + metadata: + references: + - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ + - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMPrivilegeEscalation.py + category: security + cwe: + - 'CWE-269: Improper Privilege Management' + technology: + - terraform + - aws + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users + shortlink: https://sg.run/XOeA + semgrep.dev: + rule: + r_id: 13564 + rv_id: 1263892 + rule_id: OrU6jO + version_id: ExTExxx + url: https://semgrep.dev/playground/r/ExTExxx/terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: | + Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = $ACTION + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - patterns: + - pattern: | + [..., "sts:AssumeRole", ...] + - pattern: | + [..., "iam:UpdateAssumeRolePolicy", ...] + - patterns: + - pattern: | + [..., "iam:PassRole", ...] + - pattern: | + [..., "lambda:CreateFunction", ...] + - pattern: | + [..., "lambda:InvokeFunction", ...] + - patterns: + - pattern: | + [..., "iam:PassRole", ...] + - pattern: | + [..., "lambda:CreateFunction", ...] + - pattern: | + [..., "lambda:CreateEventSourceMapping", ...] + - pattern: | + "lambda:UpdateFunctionCode" + - patterns: + - pattern: | + [..., "iam:PassRole", ...] + - pattern: | + [..., "glue:CreateDevEndpoint", ...] + - patterns: + - pattern: | + [..., "iam:PassRole", ...] + - pattern: | + [..., "cloudformation:CreateStack", ...] + - patterns: + - pattern: | + [..., "iam:PassRole", ...] + - pattern: | + [..., "datapipeline:CreatePipeline", ...] + - pattern: | + [..., "datapipeline:PutPipelineDefinition", ...] + message: Ensure that groups of actions that include iam:PassRole and could result + in privilege escalation are not all allowed for the same user. These actions could + result in an attacker gaining full admin access of an AWS account. Try not to + use these actions in conjuction. + metadata: + references: + - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ + - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ + category: security + cwe: + - 'CWE-269: Improper Privilege Management' + technology: + - terraform + - aws + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles + shortlink: https://sg.run/jwrA + semgrep.dev: + rule: + r_id: 13565 + rv_id: 1263893 + rule_id: eqUzR3 + version_id: 7ZTE33y + url: https://semgrep.dev/playground/r/7ZTE33y/terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern: | + Action = $ACTION + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = [..., $ACTION, ...] + - metavariable-pattern: + metavariable: $ACTION + pattern-either: + - pattern: | + "acm-pca:CreatePermission" + - pattern: | + "acm-pca:DeletePermission" + - pattern: | + "acm-pca:DeletePolicy" + - pattern: | + "acm-pca:PutPolicy" + - pattern: | + "apigateway:UpdateRestApiPolicy" + - pattern: | + "backup:DeleteBackupVaultAccessPolicy" + - pattern: | + "backup:PutBackupVaultAccessPolicy" + - pattern: | + "chime:DeleteVoiceConnectorTerminationCredentials" + - pattern: | + "chime:PutVoiceConnectorTerminationCredentials" + - pattern: | + "cloudformation:SetStackPolicy" + - pattern: | + "cloudsearch:UpdateServiceAccessPolicies" + - pattern: | + "codeartifact:DeleteDomainPermissionsPolicy" + - pattern: | + "codeartifact:DeleteRepositoryPermissionsPolicy" + - pattern: | + "codebuild:DeleteResourcePolicy" + - pattern: | + "codebuild:DeleteSourceCredentials" + - pattern: | + "codebuild:ImportSourceCredentials" + - pattern: | + "codebuild:PutResourcePolicy" + - pattern: | + "codeguru-profiler:PutPermission" + - pattern: | + "codeguru-profiler:RemovePermission" + - pattern: | + "codestar:AssociateTeamMember" + - pattern: | + "codestar:CreateProject" + - pattern: | + "codestar:DeleteProject" + - pattern: | + "codestar:DisassociateTeamMember" + - pattern: | + "codestar:UpdateTeamMember" + - pattern: | + "cognito-identity:CreateIdentityPool" + - pattern: | + "cognito-identity:DeleteIdentities" + - pattern: | + "cognito-identity:DeleteIdentityPool" + - pattern: | + "cognito-identity:GetId" + - pattern: | + "cognito-identity:MergeDeveloperIdentities" + - pattern: | + "cognito-identity:SetIdentityPoolRoles" + - pattern: | + "cognito-identity:UnlinkDeveloperIdentity" + - pattern: | + "cognito-identity:UnlinkIdentity" + - pattern: | + "cognito-identity:UpdateIdentityPool" + - pattern: | + "deeplens:AssociateServiceRoleToAccount" + - pattern: | + "ds:CreateConditionalForwarder" + - pattern: | + "ds:CreateDirectory" + - pattern: | + "ds:CreateMicrosoftAD" + - pattern: | + "ds:CreateTrust" + - pattern: | + "ds:ShareDirectory" + - pattern: | + "ec2:CreateNetworkInterfacePermission" + - pattern: | + "ec2:DeleteNetworkInterfacePermission" + - pattern: | + "ec2:ModifySnapshotAttribute" + - pattern: | + "ec2:ModifyVpcEndpointServicePermissions" + - pattern: | + "ec2:ResetSnapshotAttribute" + - pattern: | + "ecr:DeleteRepositoryPolicy" + - pattern: | + "ecr:SetRepositoryPolicy" + - pattern: | + "elasticfilesystem:DeleteFileSystemPolicy" + - pattern: | + "elasticfilesystem:PutFileSystemPolicy" + - pattern: | + "elasticmapreduce:PutBlockPublicAccessConfiguration" + - pattern: | + "es:CreateElasticsearchDomain" + - pattern: | + "es:UpdateElasticsearchDomainConfig" + - pattern: | + "glacier:AbortVaultLock" + - pattern: | + "glacier:CompleteVaultLock" + - pattern: | + "glacier:DeleteVaultAccessPolicy" + - pattern: | + "glacier:InitiateVaultLock" + - pattern: | + "glacier:SetDataRetrievalPolicy" + - pattern: | + "glacier:SetVaultAccessPolicy" + - pattern: | + "glue:DeleteResourcePolicy" + - pattern: | + "glue:PutResourcePolicy" + - pattern: | + "greengrass:AssociateServiceRoleToAccount" + - pattern: | + "health:DisableHealthServiceAccessForOrganization" + - pattern: | + "health:EnableHealthServiceAccessForOrganization" + - pattern: | + "iam:AddClientIDToOpenIDConnectProvider" + - pattern: | + "iam:AddRoleToInstanceProfile" + - pattern: | + "iam:AddUserToGroup" + - pattern: | + "iam:AttachGroupPolicy" + - pattern: | + "iam:AttachRolePolicy" + - pattern: | + "iam:AttachUserPolicy" + - pattern: | + "iam:ChangePassword" + - pattern: | + "iam:CreateAccessKey" + - pattern: | + "iam:CreateAccountAlias" + - pattern: | + "iam:CreateGroup" + - pattern: | + "iam:CreateInstanceProfile" + - pattern: | + "iam:CreateLoginProfile" + - pattern: | + "iam:CreateOpenIDConnectProvider" + - pattern: | + "iam:CreatePolicy" + - pattern: | + "iam:CreatePolicyVersion" + - pattern: | + "iam:CreateRole" + - pattern: | + "iam:CreateSAMLProvider" + - pattern: | + "iam:CreateServiceLinkedRole" + - pattern: | + "iam:CreateServiceSpecificCredential" + - pattern: | + "iam:CreateUser" + - pattern: | + "iam:CreateVirtualMFADevice" + - pattern: | + "iam:DeactivateMFADevice" + - pattern: | + "iam:DeleteAccessKey" + - pattern: | + "iam:DeleteAccountAlias" + - pattern: | + "iam:DeleteAccountPasswordPolicy" + - pattern: | + "iam:DeleteGroup" + - pattern: | + "iam:DeleteGroupPolicy" + - pattern: | + "iam:DeleteInstanceProfile" + - pattern: | + "iam:DeleteLoginProfile" + - pattern: | + "iam:DeleteOpenIDConnectProvider" + - pattern: | + "iam:DeletePolicy" + - pattern: | + "iam:DeletePolicyVersion" + - pattern: | + "iam:DeleteRole" + - pattern: | + "iam:DeleteRolePermissionsBoundary" + - pattern: | + "iam:DeleteRolePolicy" + - pattern: | + "iam:DeleteSAMLProvider" + - pattern: | + "iam:DeleteSSHPublicKey" + - pattern: | + "iam:DeleteServerCertificate" + - pattern: | + "iam:DeleteServiceLinkedRole" + - pattern: | + "iam:DeleteServiceSpecificCredential" + - pattern: | + "iam:DeleteSigningCertificate" + - pattern: | + "iam:DeleteUser" + - pattern: | + "iam:DeleteUserPermissionsBoundary" + - pattern: | + "iam:DeleteUserPolicy" + - pattern: | + "iam:DeleteVirtualMFADevice" + - pattern: | + "iam:DetachGroupPolicy" + - pattern: | + "iam:DetachRolePolicy" + - pattern: | + "iam:DetachUserPolicy" + - pattern: | + "iam:EnableMFADevice" + - pattern: | + "iam:PassRole" + - pattern: | + "iam:PutGroupPolicy" + - pattern: | + "iam:PutRolePermissionsBoundary" + - pattern: | + "iam:PutRolePolicy" + - pattern: | + "iam:PutUserPermissionsBoundary" + - pattern: | + "iam:PutUserPolicy" + - pattern: | + "iam:RemoveClientIDFromOpenIDConnectProvider" + - pattern: | + "iam:RemoveRoleFromInstanceProfile" + - pattern: | + "iam:RemoveUserFromGroup" + - pattern: | + "iam:ResetServiceSpecificCredential" + - pattern: | + "iam:ResyncMFADevice" + - pattern: | + "iam:SetDefaultPolicyVersion" + - pattern: | + "iam:SetSecurityTokenServicePreferences" + - pattern: | + "iam:UpdateAccessKey" + - pattern: | + "iam:UpdateAccountPasswordPolicy" + - pattern: | + "iam:UpdateAssumeRolePolicy" + - pattern: | + "iam:UpdateGroup" + - pattern: | + "iam:UpdateLoginProfile" + - pattern: | + "iam:UpdateOpenIDConnectProviderThumbprint" + - pattern: | + "iam:UpdateRole" + - pattern: | + "iam:UpdateRoleDescription" + - pattern: | + "iam:UpdateSAMLProvider" + - pattern: | + "iam:UpdateSSHPublicKey" + - pattern: | + "iam:UpdateServerCertificate" + - pattern: | + "iam:UpdateServiceSpecificCredential" + - pattern: | + "iam:UpdateSigningCertificate" + - pattern: | + "iam:UpdateUser" + - pattern: | + "iam:UploadSSHPublicKey" + - pattern: | + "iam:UploadServerCertificate" + - pattern: | + "iam:UploadSigningCertificate" + - pattern: | + "imagebuilder:PutComponentPolicy" + - pattern: | + "imagebuilder:PutImagePolicy" + - pattern: | + "imagebuilder:PutImageRecipePolicy" + - pattern: | + "iot:AttachPolicy" + - pattern: | + "iot:AttachPrincipalPolicy" + - pattern: | + "iot:DetachPolicy" + - pattern: | + "iot:DetachPrincipalPolicy" + - pattern: | + "iot:SetDefaultAuthorizer" + - pattern: | + "iot:SetDefaultPolicyVersion" + - pattern: | + "iotsitewise:CreateAccessPolicy" + - pattern: | + "iotsitewise:DeleteAccessPolicy" + - pattern: | + "iotsitewise:UpdateAccessPolicy" + - pattern: | + "kms:CreateGrant" + - pattern: | + "kms:PutKeyPolicy" + - pattern: | + "kms:RetireGrant" + - pattern: | + "kms:RevokeGrant" + - pattern: | + "lakeformation:BatchGrantPermissions" + - pattern: | + "lakeformation:BatchRevokePermissions" + - pattern: | + "lakeformation:GrantPermissions" + - pattern: | + "lakeformation:PutDataLakeSettings" + - pattern: | + "lakeformation:RevokePermissions" + - pattern: | + "lambda:AddLayerVersionPermission" + - pattern: | + "lambda:AddPermission" + - pattern: | + "lambda:DisableReplication" + - pattern: | + "lambda:EnableReplication" + - pattern: | + "lambda:RemoveLayerVersionPermission" + - pattern: | + "lambda:RemovePermission" + - pattern: | + "license-manager:UpdateServiceSettings" + - pattern: | + "lightsail:GetRelationalDatabaseMasterUserPassword" + - pattern: | + "logs:DeleteResourcePolicy" + - pattern: | + "logs:PutResourcePolicy" + - pattern: | + "mediapackage:RotateIngestEndpointCredentials" + - pattern: | + "mediastore:DeleteContainerPolicy" + - pattern: | + "mediastore:PutContainerPolicy" + - pattern: | + "opsworks:SetPermission" + - pattern: | + "opsworks:UpdateUserProfile" + - pattern: | + "quicksight:CreateAdmin" + - pattern: | + "quicksight:CreateGroup" + - pattern: | + "quicksight:CreateGroupMembership" + - pattern: | + "quicksight:CreateIAMPolicyAssignment" + - pattern: | + "quicksight:CreateUser" + - pattern: | + "quicksight:DeleteGroup" + - pattern: | + "quicksight:DeleteGroupMembership" + - pattern: | + "quicksight:DeleteIAMPolicyAssignment" + - pattern: | + "quicksight:DeleteUser" + - pattern: | + "quicksight:DeleteUserByPrincipalId" + - pattern: | + "quicksight:RegisterUser" + - pattern: | + "quicksight:UpdateDashboardPermissions" + - pattern: | + "quicksight:UpdateGroup" + - pattern: | + "quicksight:UpdateIAMPolicyAssignment" + - pattern: | + "quicksight:UpdateTemplatePermissions" + - pattern: | + "quicksight:UpdateUser" + - pattern: | + "ram:AcceptResourceShareInvitation" + - pattern: | + "ram:AssociateResourceShare" + - pattern: | + "ram:CreateResourceShare" + - pattern: | + "ram:DeleteResourceShare" + - pattern: | + "ram:DisassociateResourceShare" + - pattern: | + "ram:EnableSharingWithAwsOrganization" + - pattern: | + "ram:RejectResourceShareInvitation" + - pattern: | + "ram:UpdateResourceShare" + - pattern: | + "rds:AuthorizeDBSecurityGroupIngress" + - pattern: | + "rds-db:connect" + - pattern: | + "redshift:AuthorizeSnapshotAccess" + - pattern: | + "redshift:CreateClusterUser" + - pattern: | + "redshift:CreateSnapshotCopyGrant" + - pattern: | + "redshift:JoinGroup" + - pattern: | + "redshift:ModifyClusterIamRoles" + - pattern: | + "redshift:RevokeSnapshotAccess" + - pattern: | + "route53resolver:PutResolverRulePolicy" + - pattern: | + "s3:BypassGovernanceRetention" + - pattern: | + "s3:DeleteAccessPointPolicy" + - pattern: | + "s3:DeleteBucketPolicy" + - pattern: | + "s3:ObjectOwnerOverrideToBucketOwner" + - pattern: | + "s3:PutAccessPointPolicy" + - pattern: | + "s3:PutAccountPublicAccessBlock" + - pattern: | + "s3:PutBucketAcl" + - pattern: | + "s3:PutBucketPolicy" + - pattern: | + "s3:PutBucketPublicAccessBlock" + - pattern: | + "s3:PutObjectAcl" + - pattern: | + "s3:PutObjectVersionAcl" + - pattern: | + "secretsmanager:DeleteResourcePolicy" + - pattern: | + "secretsmanager:PutResourcePolicy" + - pattern: | + "secretsmanager:ValidateResourcePolicy" + - pattern: | + "servicecatalog:CreatePortfolioShare" + - pattern: | + "servicecatalog:DeletePortfolioShare" + - pattern: | + "sns:AddPermission" + - pattern: | + "sns:CreateTopic" + - pattern: | + "sns:RemovePermission" + - pattern: | + "sns:SetTopicAttributes" + - pattern: | + "sqs:AddPermission" + - pattern: | + "sqs:CreateQueue" + - pattern: | + "sqs:RemovePermission" + - pattern: | + "sqs:SetQueueAttributes" + - pattern: | + "ssm:ModifyDocumentPermission" + - pattern: | + "sso:AssociateDirectory" + - pattern: | + "sso:AssociateProfile" + - pattern: | + "sso:CreateApplicationInstance" + - pattern: | + "sso:CreateApplicationInstanceCertificate" + - pattern: | + "sso:CreatePermissionSet" + - pattern: | + "sso:CreateProfile" + - pattern: | + "sso:CreateTrust" + - pattern: | + "sso:DeleteApplicationInstance" + - pattern: | + "sso:DeleteApplicationInstanceCertificate" + - pattern: | + "sso:DeletePermissionSet" + - pattern: | + "sso:DeletePermissionsPolicy" + - pattern: | + "sso:DeleteProfile" + - pattern: | + "sso:DisassociateDirectory" + - pattern: | + "sso:DisassociateProfile" + - pattern: | + "sso:ImportApplicationInstanceServiceProviderMetadata" + - pattern: | + "sso:PutPermissionsPolicy" + - pattern: | + "sso:StartSSO" + - pattern: | + "sso:UpdateApplicationInstanceActiveCertificate" + - pattern: | + "sso:UpdateApplicationInstanceDisplayData" + - pattern: | + "sso:UpdateApplicationInstanceResponseConfiguration" + - pattern: | + "sso:UpdateApplicationInstanceResponseSchemaConfiguration" + - pattern: | + "sso:UpdateApplicationInstanceSecurityConfiguration" + - pattern: | + "sso:UpdateApplicationInstanceServiceProviderConfiguration" + - pattern: | + "sso:UpdateApplicationInstanceStatus" + - pattern: | + "sso:UpdateDirectoryAssociation" + - pattern: | + "sso:UpdatePermissionSet" + - pattern: | + "sso:UpdateProfile" + - pattern: | + "sso:UpdateSSOConfiguration" + - pattern: | + "sso:UpdateTrust" + - pattern: | + "sso-directory:AddMemberToGroup" + - pattern: | + "sso-directory:CreateAlias" + - pattern: | + "sso-directory:CreateGroup" + - pattern: | + "sso-directory:CreateUser" + - pattern: | + "sso-directory:DeleteGroup" + - pattern: | + "sso-directory:DeleteUser" + - pattern: | + "sso-directory:DisableUser" + - pattern: | + "sso-directory:EnableUser" + - pattern: | + "sso-directory:RemoveMemberFromGroup" + - pattern: | + "sso-directory:UpdateGroup" + - pattern: | + "sso-directory:UpdatePassword" + - pattern: | + "sso-directory:UpdateUser" + - pattern: | + "sso-directory:VerifyEmail" + - pattern: | + "storagegateway:DeleteChapCredentials" + - pattern: | + "storagegateway:SetLocalConsolePassword" + - pattern: | + "storagegateway:SetSMBGuestPassword" + - pattern: | + "storagegateway:UpdateChapCredentials" + - pattern: | + "waf:DeletePermissionPolicy" + - pattern: | + "waf:PutPermissionPolicy" + - pattern: | + "waf-regional:DeletePermissionPolicy" + - pattern: | + "waf-regional:PutPermissionPolicy" + - pattern: | + "wafv2:CreateWebACL" + - pattern: | + "wafv2:DeletePermissionPolicy" + - pattern: | + "wafv2:DeleteWebACL" + - pattern: | + "wafv2:PutPermissionPolicy" + - pattern: | + "wafv2:UpdateWebACL" + - pattern: | + "worklink:UpdateDevicePolicyConfiguration" + - pattern: | + "workmail:ResetPassword" + - pattern: | + "workmail:ResetUserPassword" + - pattern: | + "xray:PutEncryptionConfig" + - pattern: | + "worklink:*" + - pattern: | + "route53resolver:*" + - pattern: | + "es:*" + - pattern: | + "greengrass:*" + - pattern: | + "redshift:*" + - pattern: | + "license-manager:*" + - pattern: | + "rds:*" + - pattern: | + "lambda:*" + - pattern: | + "elasticfilesystem:*" + - pattern: | + "logs:*" + - pattern: | + "sso:*" + - pattern: | + "waf:*" + - pattern: | + "mediastore:*" + - pattern: | + "acm-pca:*" + - pattern: | + "sso-directory:*" + - pattern: | + "imagebuilder:*" + - pattern: | + "sqs:*" + - pattern: | + "codeguru-profiler:*" + - pattern: | + "wafv2:*" + - pattern: | + "cloudformation:*" + - pattern: | + "xray:*" + - pattern: | + "codeartifact:*" + - pattern: | + "iotsitewise:*" + - pattern: | + "workmail:*" + - pattern: | + "glue:*" + - pattern: | + "deeplens:*" + - pattern: | + "chime:*" + - pattern: | + "mediapackage:*" + - pattern: | + "opsworks:*" + - pattern: | + "ds:*" + - pattern: | + "ram:*" + - pattern: | + "iam:*" + - pattern: | + "waf-regional:*" + - pattern: | + "glacier:*" + - pattern: | + "cloudsearch:*" + - pattern: | + "lakeformation:*" + - pattern: | + "elasticmapreduce:*" + - pattern: | + "quicksight:*" + - pattern: | + "sns:*" + - pattern: | + "ec2:*" + - pattern: | + "health:*" + - pattern: | + "lightsail:*" + - pattern: | + "codestar:*" + - pattern: | + "kms:*" + - pattern: | + "codebuild:*" + - pattern: | + "s3:*" + - pattern: | + "cognito-identity:*" + - pattern: | + "apigateway:*" + - pattern: | + "rds-db:*" + - pattern: | + "iot:*" + - pattern: | + "backup:*" + - pattern: | + "secretsmanager:*" + - pattern: | + "servicecatalog:*" + - pattern: | + "ssm:*" + - pattern: | + "storagegateway:*" + - pattern: | + "ecr:*" + message: Ensure IAM policies don't allow resource exposure. These actions can expose + AWS resources to the public. For example `ecr:SetRepositoryPolicy` could let an + attacker retrieve container images. Instead, use another action that doesn't expose + AWS resources. + metadata: + references: + - https://cloudsplaining.readthedocs.io/en/latest/glossary/resource-exposure/ + - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMPermissionsManagement.py + category: security + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure + shortlink: https://sg.run/18rD + semgrep.dev: + rule: + r_id: 13566 + rv_id: 1263894 + rule_id: v8U9r0 + version_id: LjTkggK + url: https://semgrep.dev/playground/r/LjTkggK/terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ... + ] + ... + }) + ... + } + - pattern-not-inside: | + resource $TYPE "..." { + ... + policy = jsonencode({ + ... + Statement = [ + ..., + {... Effect = "Deny" ...}, + ... + ] + ... + }) + ... + } + - pattern-either: + - pattern: Action = "*" + - pattern: Action = ["*"] + - metavariable-pattern: + metavariable: $TYPE + pattern-either: + - pattern: | + "aws_iam_role_policy" + - pattern: | + "aws_iam_policy" + - pattern: | + "aws_iam_user_policy" + - pattern: | + "aws_iam_group_policy" + - patterns: + - pattern-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + } + ... + } + - pattern-not-inside: | + data aws_iam_policy_document "..." { + ... + statement { + ... + effect = "Deny" + ... + } + ... + } + - pattern: | + actions = ["*"] + message: Ensure that no IAM policies allow "*" as a statement's actions. This allows + all actions to be performed on the specified resources, and is a violation of + the principle of least privilege. Instead, specify the actions that a certain + user or policy is allowed to take. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy + - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/StarActionPolicyDocument.py + category: security + cwe: + - 'CWE-269: Improper Privilege Management' + technology: + - terraform + - aws + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions + shortlink: https://sg.run/9rZ4 + semgrep.dev: + rule: + r_id: 13567 + rv_id: 1263895 + rule_id: d8Uew3 + version_id: 8KT5rrp + url: https://semgrep.dev/playground/r/8KT5rrp/terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions + origin: community + languages: + - hcl + severity: WARNING +- id: javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true + message: 'By setting `allErrors: true` in `Ajv` library, all error objects will + be allocated without limit. This allows the attacker to produce a huge number + of errors which can lead to denial of service. Do not use `allErrors: true` in + production.' + metadata: + cwe: + - 'CWE-400: Uncontrolled Resource Consumption' + category: security + technology: + - ajv + references: + - https://ajv.js.org/options.html#allerrors + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true + shortlink: https://sg.run/d2jY + semgrep.dev: + rule: + r_id: 13578 + rv_id: 945749 + rule_id: PeUo5X + version_id: 44TZkJ6 + url: https://semgrep.dev/playground/r/44TZkJ6/javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern-either: + - pattern: | + new Ajv({...,allErrors: true,...},...) + - patterns: + - pattern: | + new Ajv($SETTINGS,...) + - pattern-inside: | + $SETTINGS = {...,allErrors: true,...} + ... +- id: javascript.express.security.audit.remote-property-injection.remote-property-injection + message: Bracket object notation with user input is present, this might allow an + attacker to access all properties of the object and even it's prototype. Use literal + values for object properties. + metadata: + confidence: LOW + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + category: security + technology: + - express + references: + - https://github.com/nodesecurity/eslint-plugin-security/blob/3c7522ca1be800353513282867a1034c795d9eb4/docs/the-dangers-of-square-bracket-notation.md + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.remote-property-injection.remote-property-injection + shortlink: https://sg.run/Z4gn + semgrep.dev: + rule: + r_id: 13579 + rv_id: 1263148 + rule_id: JDUL1B + version_id: 44TEjGX + url: https://semgrep.dev/playground/r/44TEjGX/javascript.express.security.audit.remote-property-injection.remote-property-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: $OBJ[...] = ... + - pattern-not-inside: $OBJ["..."] = ... + - pattern-not-inside: $OBJ[...] = "..." + - pattern: $INDEX + - pattern-not: | + "..." + $INDEX + - pattern-not: | + $INDEX + "..." + pattern-sanitizers: + - patterns: + - pattern: var $X = ... + - pattern-not: var $X = $REQ.$ANY +- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration + message: By letting user input control CORS parameters, there is a risk that software + does not properly verify that the source of data or communication is valid. Use + literal values for CORS settings. + metadata: + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-346: Origin Validation Error' + category: security + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS + technology: + - express + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration + shortlink: https://sg.run/nKXO + semgrep.dev: + rule: + r_id: 13580 + rv_id: 1263162 + rule_id: 5rULJQ + version_id: YDTZe8Y + url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, $X) + - pattern: $RES.header($HEADER, $X) + - pattern: $RES.setHeader($HEADER, $X) + - pattern: | + $RES.set({$HEADER: $X}, ...) + - pattern: | + $RES.writeHead($STATUS, {$HEADER: $X}, ...) + - focus-metavariable: $X + - metavariable-regex: + metavariable: $HEADER + regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* +- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + message: By letting user input control `X-Frame-Options` header, there is a risk + that software does not properly verify whether or not a browser should be allowed + to render a page in an `iframe`. + metadata: + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' + category: security + technology: + - express + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + shortlink: https://sg.run/EvjA + semgrep.dev: + rule: + r_id: 13581 + rv_id: 1263178 + rule_id: GdUrLy + version_id: xyTjz3D + url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, ...) + - pattern: $RES.header($HEADER, ...) + - pattern: $RES.setHeader($HEADER, ...) + - pattern: | + $RES.set({$HEADER: ...}, ...) + - pattern: | + $RES.writeHead($STATUS, {$HEADER: ...}, ...) + - metavariable-regex: + metavariable: $HEADER + regex: .*(X-Frame-Options|x-frame-options).* +- id: javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring + message: Detected string concatenation with a non-literal variable in a util.format + / console.log function. If an attacker injects a format specifier in the string, + it will forge the log message. Try to use constant values for the format string. + metadata: + cwe: + - 'CWE-134: Use of Externally-Controlled Format String' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - javascript + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + confidence: LOW + references: + - https://cwe.mitre.org/data/definitions/134.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring + shortlink: https://sg.run/7Y5R + semgrep.dev: + rule: + r_id: 13582 + rv_id: 1263211 + rule_id: ReU3OJ + version_id: A8Tgdyq + url: https://semgrep.dev/playground/r/A8Tgdyq/javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring + origin: community + languages: + - javascript + - typescript + severity: INFO + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $X + $Y + - pattern: $X.concat($Y) + - pattern: | + `...${...}...` + - pattern-not: | + "..." + "..." + - pattern-not: | + $X.concat("...") + pattern-sinks: + - patterns: + - focus-metavariable: $STR + - pattern-either: + - pattern: | + console.$LOG($STR,$PARAM,...) + - patterns: + - pattern-inside: | + $UTIL = require('util') + ... + - pattern: | + $UTIL.format($STR,$PARAM,...) +- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + metadata: + shortDescription: Allowing an attacker to manipulate the session may lead to unintended + behavior. + tags: + - security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + references: + - https://brakemanscanner.org/docs/warning_types/session_manipulation/ + category: security + technology: + - rails + help: | + ## Remediation + Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior. + + ## References + [Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/) + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + shortlink: https://sg.run/86q7 + semgrep.dev: + rule: + r_id: 13584 + rv_id: 1263621 + rule_id: BYUdW6 + version_id: qkTR76G + url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + origin: community + message: This gets data from session using user inputs. A malicious user may be + able to retrieve information from your session that you didn't intend them to. + Do not use user input as a session key. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern: session[...] +- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + shortlink: https://sg.run/gYln + semgrep.dev: + rule: + r_id: 13585 + rv_id: 1263622 + rule_id: DbU1dr + version_id: l4TJRkk + url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - pattern: Dir.$X(...) + - pattern: File.$X(...) + - pattern: IO.$X(...) + - pattern: Kernel.$X(...) + - pattern: PStore.$X(...) + - pattern: Pathname.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + shortlink: https://sg.run/Q9gP + semgrep.dev: + rule: + r_id: 13586 + rv_id: 1263623 + rule_id: WAUyzp + version_id: YDTZeWL + url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - pattern: Net::FTP.$X(...) + - patterns: + - pattern-inside: | + $FTP = Net::FTP.$OPEN(...) + ... + $FTP.$METHOD(...) + - pattern: $FTP.$METHOD(...) +- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + shortlink: https://sg.run/3rLb + semgrep.dev: + rule: + r_id: 13587 + rv_id: 1263624 + rule_id: 0oU2x3 + version_id: 6xT29nN + url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - patterns: + - pattern: Net::HTTP::$METHOD.new(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: Copy + - pattern: Delete + - pattern: Get + - pattern: Head + - pattern: Lock + - pattern: Mkcol + - pattern: Move + - pattern: Options + - pattern: Patch + - pattern: Post + - pattern: Propfind + - pattern: Proppatch + - pattern: Put + - pattern: Trace + - pattern: Unlock + - patterns: + - pattern: Net::HTTP.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: get + - pattern: get2 + - pattern: head + - pattern: head2 + - pattern: options + - pattern: patch + - pattern: post + - pattern: post2 + - pattern: post_form + - pattern: put + - pattern: request + - pattern: request_get + - pattern: request_head + - pattern: request_post + - pattern: send_request + - pattern: trace + - pattern: get_print + - pattern: get_response + - pattern: start +- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + shortlink: https://sg.run/4e8E + semgrep.dev: + rule: + r_id: 13588 + rv_id: 1263625 + rule_id: KxU72k + version_id: o5TbDq8 + url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - pattern: params[...] + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: Kernel.$X(...) + - patterns: + - pattern-either: + - pattern: Shell.$X(...) + - patterns: + - pattern-inside: | + $SHELL = Shell.$ANY(...) + ... + $SHELL.$X(...) + - pattern: $SHELL.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: cat + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: exec + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: system + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/default_routes/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes + shortlink: https://sg.run/Pbrq + semgrep.dev: + rule: + r_id: 13589 + rv_id: 1263630 + rule_id: qNUXYy + version_id: jQTn5dx + url: https://semgrep.dev/playground/r/jQTn5dx/ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes + origin: community + message: Default routes are enabled in this routes file. This means any public method + on a controller can be called as an action. It is very easy to accidentally expose + a method you didn't mean to. Instead, remove this line and explicitly include + all routes you intend external users to follow. + languages: + - ruby + severity: WARNING + patterns: + - pattern-either: + - pattern: map.connect ":controller/:action/:id" + - pattern: match ':controller(/:action(/:id(.:format)))' + paths: + include: + - '*routes.rb' +- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://brakemanscanner.org/docs/warning_types/link_to/ + - https://brakemanscanner.org/docs/warning_types/link_to_href/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + shortlink: https://sg.run/JxXQ + semgrep.dev: + rule: + r_id: 13590 + rv_id: 1263632 + rule_id: lBU8Qj + version_id: 9lT4brj + url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + origin: community + message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` + is not escaped. This means that user input which reaches the body will be executed + when the HTML is rendered. Even in other versions, values starting with `javascript:` + or `data:` are not escaped. It is better to create and use a safer function which + checks the body argument. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern-either: + - pattern: $MODEL.url(...) + - pattern: $MODEL.uri(...) + - pattern: $MODEL.link(...) + - pattern: $MODEL.page(...) + - pattern: $MODEL.site(...) + pattern-sinks: + - pattern: link_to(...) + pattern-sanitizers: + - patterns: + - pattern: | + "...#{...}..." + - pattern-not: | + "#{...}..." +- id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + references: + - https://brakemanscanner.org/docs/warning_types/redirect/ + category: security + technology: + - rails + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + shortlink: https://sg.run/5DY3 + semgrep.dev: + rule: + r_id: 13591 + rv_id: 1263634 + rule_id: YGUDqJ + version_id: rxTAKdY + url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + origin: community + message: When a redirect uses user input, a malicious user can spoof a website under + a trusted URL or access restricted parts of a site. When using user-supplied values, + sanitize the value before using it for the redirect. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - patterns: + - pattern: $MODEL.$X(...) + - pattern-not: $MODEL.$X("...") + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: all + - pattern: create + - pattern: create! + - pattern: find + - pattern: find_by_sql + - pattern: first + - pattern: last + - pattern: new + - pattern: from + - pattern: group + - pattern: having + - pattern: joins + - pattern: lock + - pattern: order + - pattern: reorder + - pattern: select + - pattern: where + - pattern: find_by + - pattern: find_by! + - pattern: take + pattern-sinks: + - pattern: redirect_to(...) + pattern-sanitizers: + - pattern: params.merge(:only_path => true) + - pattern: params.merge(:host => ...) +- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + shortlink: https://sg.run/GO2n + semgrep.dev: + rule: + r_id: 13592 + rv_id: 1263635 + rule_id: 6JU1bL + version_id: bZT53p0 + url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + origin: community + message: Avoid rendering user input. It may be possible for a malicious user to + input a path that lets them access a template they shouldn't. To prevent this, + check dynamic template paths against a predefined allowlist to make sure it's + an allowed template. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-inside: render($X => $INPUT, ...) + - pattern: $INPUT + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: action + - pattern: template + - pattern: partial + - pattern: file +- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + languages: + - python + severity: WARNING + metadata: + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + technology: + - python + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + shortlink: https://sg.run/AXY4 + semgrep.dev: + rule: + r_id: 13594 + rv_id: 1263482 + rule_id: zdUYqR + version_id: O9Tpxqr + url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + origin: community + message: These permissions `$BITS` are widely permissive and grant access to more + people than may be necessary. A good default is `0o644` which gives read and write + access to yourself and read access to everyone else. + patterns: + - pattern-inside: os.$METHOD(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: chmod + - pattern: lchmod + - pattern: fchmod + - pattern-either: + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o650 and $BITS < 0o100000 + - patterns: + - pattern: os.$METHOD($FILE, $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o100650 + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-pattern: + metavariable: $BITS + patterns: + - pattern-either: + - pattern: <... stat.S_IWGRP ...> + - pattern: <... stat.S_IXGRP ...> + - pattern: <... stat.S_IWOTH ...> + - pattern: <... stat.S_IXOTH ...> + - pattern: <... stat.S_IRWXO ...> + - pattern: <... stat.S_IRWXG ...> + - patterns: + - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) + - metavariable-comparison: + metavariable: $MOD + comparison: $MOD == 0o111 +- id: csharp.lang.security.ssrf.http-client.ssrf + severity: ERROR + languages: + - csharp + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/csharp.lang.security.ssrf.http-client.ssrf + shortlink: https://sg.run/4eB9 + semgrep.dev: + rule: + r_id: 13700 + rv_id: 1262649 + rule_id: 10UdbE + version_id: A8Tgde1 + url: https://semgrep.dev/playground/r/A8Tgde1/csharp.lang.security.ssrf.http-client.ssrf + origin: community + message: SSRF is an attack vector that abuses an application to interact with the + internal/external network or the machine itself. + patterns: + - pattern-inside: | + using System.Net.Http; + ... + - pattern-either: + - pattern: | + $T $F(..., $X, ...) + { + ... + HttpClient $Y = new HttpClient(); + ... + ... $Y.GetAsync(<... $X ...>, ...); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + HttpClient $Y = new HttpClient(); + ... + ... $Y.GetAsync($B, ...); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + HttpClient $Y = new HttpClient(); + ... + ... $Y.GetStringAsync(<... $X ...>); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + HttpClient $Y = new HttpClient(); + ... + ... $Y.GetStringAsync($B); + } +- id: csharp.lang.security.ssrf.rest-client.ssrf + severity: ERROR + languages: + - csharp + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/csharp.lang.security.ssrf.rest-client.ssrf + shortlink: https://sg.run/Pb9v + semgrep.dev: + rule: + r_id: 13701 + rv_id: 1262650 + rule_id: 9AURoq + version_id: BjTkZzn + url: https://semgrep.dev/playground/r/BjTkZzn/csharp.lang.security.ssrf.rest-client.ssrf + origin: community + message: SSRF is an attack vector that abuses an application to interact with the + internal/external network or the machine itself. + patterns: + - pattern-inside: | + using RestSharp; + ... + - pattern-either: + - pattern: | + $T $F(..., $X, ...) + { + ... + ... new RestClient(<... $X ...>); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + ... new RestClient($B); + } +- id: csharp.lang.security.ssrf.web-client.ssrf + severity: ERROR + languages: + - csharp + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/csharp.lang.security.ssrf.web-client.ssrf + shortlink: https://sg.run/JxqP + semgrep.dev: + rule: + r_id: 13702 + rv_id: 1262651 + rule_id: yyUPBe + version_id: DkTRbxP + url: https://semgrep.dev/playground/r/DkTRbxP/csharp.lang.security.ssrf.web-client.ssrf + origin: community + message: SSRF is an attack vector that abuses an application to interact with the + internal/external network or the machine itself. + patterns: + - pattern-inside: | + using System.Net; + ... + - pattern-either: + - pattern: | + $T $F(..., $X, ...) + { + ... + WebClient $Y = new WebClient(); + ... + ... $Y.OpenRead(<... $X ...>); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + WebClient $Y = new WebClient(); + ... + ... $Y.OpenRead($B); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + WebClient $Y = new WebClient(); + ... + ... $Y.OpenReadAsync(<... $X ...>, ...); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + WebClient $Y = new WebClient(); + ... + ... $Y.OpenReadAsync($B, ...); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + WebClient $Y = new WebClient(); + ... + ... $Y.DownloadString(<... $X ...>); + } + - pattern: | + $T $F(..., $X, ...) + { + ... + $A $B = <... $X ...>; + ... + WebClient $Y = new WebClient(); + ... + ... $Y.DownloadString($B); + } +- id: csharp.lang.security.ssrf.web-request.ssrf + severity: ERROR + languages: + - csharp + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cwe.mitre.org/data/definitions/918.html + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/csharp.lang.security.ssrf.web-request.ssrf + shortlink: https://sg.run/5DWj + semgrep.dev: + rule: + r_id: 13703 + rv_id: 1262652 + rule_id: r6UwoG + version_id: WrTqKND + url: https://semgrep.dev/playground/r/WrTqKND/csharp.lang.security.ssrf.web-request.ssrf + origin: community + message: The web server receives a URL or similar request from an upstream component + and retrieves the contents of this URL, but it does not sufficiently ensure that + the request is being sent to the expected destination. Many different options + exist to fix this issue depending the use case (Application can send request only + to identified and trusted applications, Application can send requests to ANY external + IP address or domain name). + patterns: + - pattern-inside: | + using System.Net; + ... + - pattern-either: + - pattern: | + $T $F(..., $X, ...) + { + ... + ... WebRequest.Create(<... $X ...>); + } + - pattern: | + $T $F($X) + { + ... + $A $B = <... $X ...>; + ... + ... WebRequest.Create($B); + } + - pattern: | + $T $F($X) + { + ... + $A $B = <... $X ...>; + ... + $C $D = <... $B ...>; + ... + ... WebRequest.Create($D); + } +- id: html.security.audit.missing-integrity.missing-integrity + metadata: + category: security + technology: + - html + cwe: + - 'CWE-353: Missing Support for Integrity Check' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + confidence: LOW + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity + shortlink: https://sg.run/krXA + semgrep.dev: + rule: + r_id: 13728 + rv_id: 1262975 + rule_id: AbUQzj + version_id: w8TRopQ + url: https://semgrep.dev/playground/r/w8TRopQ/html.security.audit.missing-integrity.missing-integrity + origin: community + patterns: + - pattern-either: + - pattern: + - pattern: + - metavariable-pattern: + metavariable: $...A + patterns: + - pattern-either: + - pattern: src='... :// ...' + - pattern: src="... :// ..." + - pattern: href='... :// ...' + - pattern: href="... :// ..." + - pattern: src='//...' + - pattern: src="//..." + - pattern: href='//...' + - pattern: href="//..." + - pattern-not-regex: (?is).*integrity=.* + - pattern-not-regex: (google-analytics\.com|fonts\.googleapis\.com|fonts\.gstatic\.com|googletagmanager\.com) + - pattern-not-regex: .*rel\s*=\s*['"]?preconnect.* + paths: + include: + - '*.html' + message: "This tag is missing an 'integrity' subresource integrity attribute. The + 'integrity' attribute allows for the browser to verify that externally hosted + files (for example from a CDN) are delivered without unexpected manipulation. + Without this attribute, if an attacker can modify the externally hosted resource, + this could lead to XSS and other types of attacks. To prevent this, include the + base64-encoded cryptographic hash of the resource (file) you\u2019re telling the + browser to fetch in the 'integrity' attribute for all externally hosted files." + severity: WARNING + languages: + - generic +- id: php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query + languages: + - php + message: Detected string concatenation with a non-literal variable in a Doctrine + DBAL query method. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/security.html + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + technology: + - doctrine + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query + shortlink: https://sg.run/KXWn + semgrep.dev: + rule: + r_id: 13799 + rv_id: 1263270 + rule_id: X5UdZj + version_id: jQTn5pd + url: https://semgrep.dev/playground/r/jQTn5pd/php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query + origin: community + patterns: + - pattern-either: + - pattern: $CONNECTION->prepare($QUERY,...) + - pattern: $CONNECTION->createQuery($QUERY,...) + - pattern: $CONNECTION->executeQuery($QUERY,...) + - pattern-either: + - pattern-inside: | + use Doctrine\DBAL\Connection; + ... + - pattern-inside: | + $CONNECTION = $SMTH->getConnection(...); + ... + - pattern-not: $CONNECTION->prepare("...",...) + - pattern-not: $CONNECTION->createQuery("...",...) + - pattern-not: $CONNECTION->executeQuery("...",...) + severity: WARNING +- id: php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect + patterns: + - pattern: $this->redirect(...) + - pattern-not: $this->redirect("...") + - pattern-not: $this->redirect() + message: The `redirect()` method does not check its destination in any way. If you + redirect to a URL provided by end-users, your application may be open to the unvalidated + redirects security vulnerability. Consider using literal values or an allowlist + to validate URLs. + languages: + - php + metadata: + references: + - https://symfony.com/doc/current/controller.html#redirecting + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + category: security + technology: + - symfony + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect + shortlink: https://sg.run/4ey5 + semgrep.dev: + rule: + r_id: 13800 + rv_id: 1263316 + rule_id: j2U3q8 + version_id: 0bTKz0j + url: https://semgrep.dev/playground/r/0bTKz0j/php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect + origin: community + severity: WARNING +- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + languages: + - php + message: '`$QUERY` Detected string concatenation with a non-literal variable in + a Doctrine QueryBuilder method. This could lead to SQL injection if the variable + is user-controlled and not properly sanitized. In order to prevent SQL injection, + use parameterized queries or prepared statements instead.' + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + technology: + - doctrine + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + shortlink: https://sg.run/jwDJ + semgrep.dev: + rule: + r_id: 13965 + rv_id: 1263271 + rule_id: kxUw23 + version_id: 1QTypnG + url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + origin: community + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $QUERY->add(...,$SINK,...) + - pattern: $QUERY->select(...,$SINK,...) + - pattern: $QUERY->addSelect(...,$SINK,...) + - pattern: $QUERY->delete(...,$SINK,...) + - pattern: $QUERY->update(...,$SINK,...) + - pattern: $QUERY->insert(...,$SINK,...) + - pattern: $QUERY->from(...,$SINK,...) + - pattern: $QUERY->join(...,$SINK,...) + - pattern: $QUERY->innerJoin(...,$SINK,...) + - pattern: $QUERY->leftJoin(...,$SINK,...) + - pattern: $QUERY->rightJoin(...,$SINK,...) + - pattern: $QUERY->where(...,$SINK,...) + - pattern: $QUERY->andWhere(...,$SINK,...) + - pattern: $QUERY->orWhere(...,$SINK,...) + - pattern: $QUERY->groupBy(...,$SINK,...) + - pattern: $QUERY->addGroupBy(...,$SINK,...) + - pattern: $QUERY->having(...,$SINK,...) + - pattern: $QUERY->andHaving(...,$SINK,...) + - pattern: $QUERY->orHaving(...,$SINK,...) + - pattern: $QUERY->orderBy(...,$SINK,...) + - pattern: $QUERY->addOrderBy(...,$SINK,...) + - pattern: $QUERY->set($SINK,...) + - pattern: $QUERY->setValue($SINK,...) + - pattern-either: + - pattern-inside: | + $Q = $X->createQueryBuilder(); + ... + - pattern-inside: | + $Q = new QueryBuilder(...); + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: sprintf(...) + - pattern: | + "...".$SMTH + severity: WARNING +- id: php.lang.security.ldap-bind-without-password.ldap-bind-without-password + patterns: + - pattern-either: + - pattern: ldap_bind($LDAP, $DN, NULL) + - pattern: ldap_bind($LDAP, $DN, '') + - patterns: + - pattern: ldap_bind(...) + - pattern-not: ldap_bind($LDAP, $DN, $PASSWORD) + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. + metadata: + references: + - https://www.php.net/manual/en/function.ldap-bind.php + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/php.lang.security.ldap-bind-without-password.ldap-bind-without-password + shortlink: https://sg.run/18Rv + semgrep.dev: + rule: + r_id: 13966 + rv_id: 1263292 + rule_id: wdUjA5 + version_id: 3ZT4X56 + url: https://semgrep.dev/playground/r/3ZT4X56/php.lang.security.ldap-bind-without-password.ldap-bind-without-password + origin: community + languages: + - php + severity: WARNING +- id: php.lang.security.php-permissive-cors.php-permissive-cors + patterns: + - pattern: header($VALUE,...) + - pattern-either: + - pattern: header("...",...) + - pattern-inside: | + $VALUE = "..."; + ... + - metavariable-regex: + metavariable: $VALUE + regex: (\'|\")\s*(Access-Control-Allow-Origin|access-control-allow-origin)\s*:\s*(\*)\s*(\'|\") + message: Access-Control-Allow-Origin response header is set to "*". This will disable + CORS Same Origin Policy restrictions. + metadata: + references: + - https://developer.mozilla.org/ru/docs/Web/HTTP/Headers/Access-Control-Allow-Origin + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-346: Origin Validation Error' + category: security + technology: + - php + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/php.lang.security.php-permissive-cors.php-permissive-cors + shortlink: https://sg.run/y1XR + semgrep.dev: + rule: + r_id: 13968 + rv_id: 1263296 + rule_id: OrU6JZ + version_id: 5PTo1KA + url: https://semgrep.dev/playground/r/5PTo1KA/php.lang.security.php-permissive-cors.php-permissive-cors + origin: community + languages: + - php + severity: WARNING +- id: php.lang.security.unlink-use.unlink-use + patterns: + - pattern: unlink(...) + - pattern-not: unlink("...",...) + message: Using user input when deleting files with `unlink()` is potentially dangerous. + A malicious actor could use this to modify or access files they have no right + to. + metadata: + references: + - https://www.php.net/manual/en/function.unlink + - https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html + category: security + technology: + - php + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use + shortlink: https://sg.run/rYeR + semgrep.dev: + rule: + r_id: 13969 + rv_id: 1263301 + rule_id: eqUzDE + version_id: DkTRbBX + url: https://semgrep.dev/playground/r/DkTRbBX/php.lang.security.unlink-use.unlink-use + origin: community + languages: + - php + severity: WARNING +- id: php.lang.security.unserialize-use.unserialize-use + patterns: + - pattern: unserialize(...) + - pattern-not: unserialize("...",...) + message: Calling `unserialize()` with user input in the pattern can lead to arbitrary + code execution. Consider using JSON or structured data approaches (e.g. Google + Protocol Buffers). + metadata: + references: + - https://www.php.net/manual/en/function.unserialize.php + - https://owasp.org/www-project-top-ten/2017/A8_2017-Insecure_Deserialization.html + category: security + technology: + - php + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/php.lang.security.unserialize-use.unserialize-use + shortlink: https://sg.run/b24E + semgrep.dev: + rule: + r_id: 13970 + rv_id: 1263302 + rule_id: v8U9OJ + version_id: WrTqKeJ + url: https://semgrep.dev/playground/r/WrTqKeJ/php.lang.security.unserialize-use.unserialize-use + origin: community + languages: + - php + severity: WARNING +- id: php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled + patterns: + - pattern-either: + - pattern: $X->createForm($TYPE, $TASK, [..., 'csrf_protection' => false, ...], + ...) + - pattern: $X->prependExtensionConfig('framework', [..., 'csrf_protection' => + false, ...], ...) + - pattern: $X->loadFromExtension('framework', [..., 'csrf_protection' => false, + ...], ...) + - pattern: $X->setDefaults([..., 'csrf_protection' => false, ...], ...) + - patterns: + - pattern-either: + - pattern: $X->createForm($TYPE, $TASK, [..., 'csrf_protection' => $VAL, ...], + ...) + - pattern: $X->prependExtensionConfig('framework', [..., 'csrf_protection' + => $VAL, ...], ...) + - pattern: $X->loadFromExtension('framework', [..., 'csrf_protection' => $VAL, + ...], ...) + - pattern: $X->setDefaults([..., 'csrf_protection' => $VAL, ...], ...) + - pattern-inside: | + $VAL = false; + ... + message: CSRF protection is disabled for this configuration. This is a security + risk. Make sure that it is safe or consider setting `csrf_protection` property + to `true`. + metadata: + references: + - https://symfony.com/doc/current/security/csrf.html + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - symfony + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled + shortlink: https://sg.run/N1gz + semgrep.dev: + rule: + r_id: 13971 + rv_id: 1263315 + rule_id: d8UeKO + version_id: WrTqKeL + url: https://semgrep.dev/playground/r/WrTqKeL/php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled + origin: community + languages: + - php + severity: WARNING +- id: php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors + patterns: + - pattern-inside: | + use Symfony\Component\HttpFoundation\Response; + ... + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + new Symfony\Component\HttpFoundation\Response($X, $Y, $HEADERS, ...) + - pattern: new Response($X, $Y, $HEADERS, ...) + - pattern-either: + - pattern: new $R($X, $Y, [$KEY => $VALUE], ...) + - pattern-inside: | + $HEADERS = [$KEY => $VALUE]; + ... + - patterns: + - pattern: $RES->headers->set($KEY, $VALUE) + - metavariable-regex: + metavariable: $KEY + regex: (\'|\")\s*(Access-Control-Allow-Origin|access-control-allow-origin)\s*(\'|\") + - metavariable-regex: + metavariable: $VALUE + regex: (\'|\")\s*(\*)\s*(\'|\") + message: Access-Control-Allow-Origin response header is set to "*". This will disable + CORS Same Origin Policy restrictions. + metadata: + references: + - https://developer.mozilla.org/ru/docs/Web/HTTP/Headers/Access-Control-Allow-Origin + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-346: Origin Validation Error' + category: security + technology: + - symfony + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors + shortlink: https://sg.run/kr92 + semgrep.dev: + rule: + r_id: 13972 + rv_id: 1263317 + rule_id: ZqUOlR + version_id: K3TKkAW + url: https://semgrep.dev/playground/r/K3TKkAW/php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors + origin: community + languages: + - php + severity: WARNING +- id: trailofbits.go.missing-unlock-before-return.missing-unlock-before-return + message: Missing mutex unlock (`$T` variable) before returning from a function. This + could result in panics resulting from double lock operations + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-667: Improper Locking' + subcategory: + - vuln + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + technology: + - --no-technology-- + description: Missing `mutex` unlock before returning from a function + references: + - https://pkg.go.dev/sync#Mutex + - https://blog.trailofbits.com/2020/06/09/how-to-check-if-a-mutex-is-locked-in-go/ + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.missing-unlock-before-return.missing-unlock-before-return + shortlink: https://sg.run/18Bk + semgrep.dev: + rule: + r_id: 14222 + rv_id: 937959 + rule_id: L1U5Gz + version_id: O9TXj4X + url: https://semgrep.dev/playground/r/O9TXj4X/trailofbits.go.missing-unlock-before-return.missing-unlock-before-return + origin: community + patterns: + - pattern-either: + - pattern: panic(...) + - pattern: return ... + - metavariable-pattern: + metavariable: $T + patterns: + - pattern: | + ($T : sync.Mutex) + - pattern-inside: | + $T.Lock() + ... + - pattern-not-inside: | + $T.Unlock() + ... + - pattern-not-inside: | + defer $T.Unlock() + ... + - pattern-not-inside: | + defer func(...) { + ... + $T.Unlock() + ... + }(...) + ... + - pattern-not-inside: "$FOO(..., ..., func(...) { \n ... \n})\n" + - pattern-not-inside: | + return func(...) { + ... + $T.Unlock() + ... + } +- id: trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex + message: Missing `RUnlock` on an `RWMutex` (`$T` variable) lock before returning + from a function + languages: + - go + severity: ERROR + metadata: + category: security + cwe: 'CWE-667: Improper Locking' + subcategory: + - vuln + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + technology: + - --no-technology-- + description: Missing `RUnlock` on an `RWMutex` lock before returning from a function + references: + - https://pkg.go.dev/sync#RWMutex + - https://blog.trailofbits.com/2020/06/09/how-to-check-if-a-mutex-is-locked-in-go/ + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex + shortlink: https://sg.run/9r40 + semgrep.dev: + rule: + r_id: 14223 + rv_id: 937958 + rule_id: 8GUzNK + version_id: xyTqL9d + url: https://semgrep.dev/playground/r/xyTqL9d/trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex + origin: community + patterns: + - pattern-either: + - pattern: panic(...) + - pattern: return ... + - metavariable-pattern: + metavariable: $T + patterns: + - pattern: | + ($T : sync.RWMutex) + - pattern-inside: | + $T.RLock() + ... + - pattern-not-inside: | + $T.RUnlock() + ... + - pattern-not-inside: | + defer $T.RUnlock() + ... + - pattern-not-inside: | + defer func(...) { + ... + $T.RUnlock() + ... + }(...) + ... + - pattern-not-inside: "$FOO(..., ..., func(...) { \n ... \n})\n" + - pattern-not-inside: | + return func(...) { + ... + $T.RUnlock() + ... + } +- id: python.django.security.injection.raw-html-format.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which + will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render + - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/oYj1 + semgrep.dev: + rule: + r_id: 14360 + rv_id: 1263397 + rule_id: 2ZUPER + version_id: 5PTo100 + url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: django.utils.html.escape(...) + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: python.flask.security.injection.raw-html-concat.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`flask.render_template`) which will + safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format + shortlink: https://sg.run/Pb7e + semgrep.dev: + rule: + r_id: 14389 + rv_id: 1409401 + rule_id: GdUrJv + version_id: RGTEN1l + url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: jinja2.escape(...) + - pattern: flask.escape(...) + - patterns: + - pattern: flask.render_template($TPL, ...) + - metavariable-regex: + metavariable: $TPL + regex: .*\.html + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can + lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing + sensitive data. It is recommend where possible to not allow user-input to craft + the base request, but to be treated as part of the path or query parameter. When + user-input is necessary to craft the request, it is recommended to follow OWASP + best practices to prevent abuse, including using an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/5DjW + semgrep.dev: + rule: + r_id: 14391 + rv_id: 1262970 + rule_id: AbUQLr + version_id: yeTxpOj + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $CLIENT := &http.Client{...} + ... + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: | + http.NewRequest("$METHOD", $URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + severity: WARNING +- id: javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport + message: If user input reaches `HoverProvider` while `supportHml` is set to `true` + it may introduce an XSS vulnerability. Do not produce HTML for hovers with dynamically + generated input. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/microsoft/monaco-editor/issues/801 + category: security + technology: + - monaco + - monaco-editor + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport + shortlink: https://sg.run/Jx7R + semgrep.dev: + rule: + r_id: 14402 + rv_id: 1263221 + rule_id: zdUYQb + version_id: o5TbDWj + url: https://semgrep.dev/playground/r/o5TbDWj/javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport + origin: community + languages: + - typescript + - javascript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + import "monaco-editor" + ... + - pattern-inside: | + require("monaco-editor") + ... + - pattern-either: + - pattern: | + {value: $VAL, supportHtml: true} + - pattern: | + {value: $VAL, isTrusted: true} + - pattern-inside: | + {range: $R, contents: [...]} + - pattern-not: | + {..., value: "...", ...} +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `html/template` package which will + safely render HTML instead, or inspect that the HTML is rendered safely. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/3r1G + semgrep.dev: + rule: + r_id: 14443 + rv_id: 1262968 + rule_id: PeUonQ + version_id: 1QTyp2p + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: ruby.rails.security.injection.raw-html-format.raw-html-format + languages: + - ruby + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `render template` and make template + files which will safely render HTML instead, or inspect that the HTML is absolutely + rendered safely with a function like `sanitize`. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/ + - https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/b2JQ + semgrep.dev: + rule: + r_id: 14470 + rv_id: 1409408 + rule_id: kxUwZX + version_id: qkTvgYY + url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: sanitize(...) + - pattern: strip_tags(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $HTMLSTR + - pattern-regex: <\w+.* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$HTMLSTR", ...) + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR" % $EXPR + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: bash.curl.security.curl-eval.curl-eval + severity: WARNING + languages: + - bash + message: Data is being eval'd from a `curl` command. An attacker with control of + the server in the `curl` command could inject malicious code into the `eval`, + resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If + you must do this, consider checking the SHA sum of the content returned by the + server to verify its integrity. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + category: security + technology: + - bash + - curl + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval + shortlink: https://sg.run/0yqJ + semgrep.dev: + rule: + r_id: 14554 + rv_id: 1262601 + rule_id: KxU7Rq + version_id: JdTzxL2 + url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval + origin: community + mode: taint + pattern-sources: + - pattern: | + $(curl ...) + - pattern: | + `curl ...` + pattern-sinks: + - pattern: eval ... +- id: bash.curl.security.curl-pipe-bash.curl-pipe-bash + languages: + - bash + severity: WARNING + message: Data is being piped into `bash` from a `curl` command. An attacker with + control of the server in the `curl` command could inject malicious code into the + pipe, resulting in a system compromise. Avoid piping untrusted data into `bash` + or any other shell if you can. If you must do this, consider checking the SHA + sum of the content returned by the server to verify its integrity. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + category: security + technology: + - bash + - curl + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/bash.curl.security.curl-pipe-bash.curl-pipe-bash + shortlink: https://sg.run/KXz6 + semgrep.dev: + rule: + r_id: 14555 + rv_id: 1262602 + rule_id: qNUXrw + version_id: 5PTo1Lx + url: https://semgrep.dev/playground/r/5PTo1Lx/bash.curl.security.curl-pipe-bash.curl-pipe-bash + origin: community + patterns: + - pattern-either: + - pattern: curl ... | ... bash ... + - pattern: curl ... | ... /bin/bash ... + - pattern: '... bash <(curl ...)' + - pattern: '... /bin/bash <(curl ...)' + - pattern: '... bash -c "$(curl ...)"' + - pattern: '... /bin/bash -c "$(curl ...)"' +- id: python.flask.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RXpK + semgrep.dev: + rule: + r_id: 14649 + rv_id: 1409403 + rule_id: ReU3Wb + version_id: BjTy42w + url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: | + $URL = "$URLSTR" + ... + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + severity: WARNING +- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - go + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt` + package. + options: + interfile: true + metadata: + category: security + technology: + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://pkg.go.dev/golang.org/x/crypto/bcrypt + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/4eOE + semgrep.dev: + rule: + r_id: 14688 + rv_id: 1262938 + rule_id: 4bU1Wj + version_id: nWT2L9r + url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5.New + - pattern: md5.Sum + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) + or a safe library. + options: + interfile: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/PbEq + semgrep.dev: + rule: + r_id: 14689 + rv_id: 1409388 + rule_id: PeUoqy + version_id: nWTQ5qD + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + severity: ERROR + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern-inside: | + var $SB strings.Builder + ... + - pattern-inside: | + $SB.WriteString("$SQLSTR") + ... + $SB.String(...) + - pattern: | + $SB.WriteString(...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) +- id: java.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - java + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use + `javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")` + or, if using Spring, `org.springframework.security.crypto.bcrypt`. + metadata: + category: security + technology: + - java + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory + - https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/JxEQ + semgrep.dev: + rule: + r_id: 14690 + rv_id: 1263029 + rule_id: JDULAW + version_id: bZT53QB + url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + $TYPE $MD = MessageDigest.getInstance("MD5"); + ... + - pattern: $MD.digest(...); + pattern-sinks: + - patterns: + - pattern: $MODEL.$METHOD(...); + - metavariable-regex: + metavariable: $METHOD + regex: (?i)(.*password.*) +- id: javascript.express.security.injection.raw-html-format.raw-html-format + message: User data flows into the host portion of this manually-constructed HTML. + This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from + user-provided input. Consider using a sanitization library such as DOMPurify to + sanitize the HTML within. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/5DO3 + semgrep.dev: + rule: + r_id: 14691 + rv_id: 1263175 + rule_id: 5rUL0X + version_id: NdTzyQv + url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - label: EXPRESS + patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - label: EXPRESSTS + patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - label: CLEAN + by-side-effect: true + patterns: + - pattern-either: + - pattern: $A($SOURCE) + - pattern: $SANITIZE. ... .$A($SOURCE) + - pattern: $A. ... .$SANITIZE($SOURCE) + - focus-metavariable: $SOURCE + - metavariable-regex: + metavariable: $A + regex: (?i)(.*valid|.*sanitiz) + pattern-sinks: + - requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" + $EXPR' + - pattern: '"$HTMLSTR".concat(...)' + - pattern: util.format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...` + - pattern-regex: | + .*<\w+.* +- id: javascript.lang.security.audit.md5-used-as-password.md5-used-as-password + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as bcrypt. You can use the `bcrypt` + node.js package. + metadata: + category: security + technology: + - crypto + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://www.npmjs.com/package/bcrypt + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/GOEn + semgrep.dev: + rule: + r_id: 14692 + rv_id: 1263200 + rule_id: GdUr5G + version_id: DkTRb3p + url: https://semgrep.dev/playground/r/DkTRb3p/javascript.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + languages: + - javascript + severity: WARNING + mode: taint + pattern-sources: + - pattern: $CRYPTO.createHash("md5") + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...); + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DEFAULT_HTTP_CLIENT + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.3 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + shortlink: https://sg.run/RXEK + semgrep.dev: + rule: + r_id: 14693 + rv_id: 1263262 + rule_id: ReU3Yb + version_id: l4TJRYY + url: https://semgrep.dev/playground/r/l4TJRYY/kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + origin: community + message: DefaultHttpClient is deprecated. Further, it does not support connections + using TLS1.2, which makes using DefaultHttpClient a security hazard. Use SystemDefaultHttpClient + instead, which supports TLS1.2. + severity: WARNING + languages: + - kt + pattern: DefaultHttpClient(...) + fix-regex: + regex: DefaultHttpClient + replacement: SystemDefaultHttpClient +- id: kotlin.lang.security.ecb-cipher.ecb-cipher + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher + shortlink: https://sg.run/DzLj + semgrep.dev: + rule: + r_id: 14696 + rv_id: 1263263 + rule_id: DbU1Zd + version_id: YDTZexg + url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher + origin: community + message: Cipher in ECB mode is detected. ECB mode produces the same output for the + same input each time which allows an attacker to intercept and replay the data. + Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + severity: WARNING + languages: + - kt + patterns: + - pattern-either: + - pattern: | + val $VAR : Cipher = $CIPHER.getInstance($MODE) + - pattern: | + var $VAR : Cipher = $CIPHER.getInstance($MODE) + - pattern: | + val $VAR = $CIPHER.getInstance($MODE) + - pattern: | + var $VAR = $CIPHER.getInstance($MODE) + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* +- id: kotlin.lang.security.gcm-detection.gcm-detection + metadata: + category: security + cwe: + - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' + references: + - https://cwe.mitre.org/data/definitions/323.html + technology: + - kotlin + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.gcm-detection.gcm-detection + shortlink: https://sg.run/WpPA + semgrep.dev: + rule: + r_id: 14697 + rv_id: 1263264 + rule_id: WAUyAW + version_id: 6xT29k7 + url: https://semgrep.dev/playground/r/6xT29k7/kotlin.lang.security.gcm-detection.gcm-detection + origin: community + languages: + - kt + message: GCM detected, please check that IV/nonce is not reused, an Initialization + Vector (IV) is a nonce used to randomize the encryption, so that even if multiple + messages with identical plaintext are encrypted, the generated corresponding ciphertexts + are different.Unlike the Key, the IV usually does not need to be secret, rather + it is important that it is random and unique. Certain encryption schemes the IV + is exchanged in public as part of the ciphertext. Reusing same Initialization + Vector with the same Key to encrypt multiple plaintext blocks allows an attacker + to compare the ciphertexts and then, with some assumptions on the content of the + messages, to gain important information about the data being encrypted. + patterns: + - pattern-either: + - pattern: $METHOD.getInstance("AES/GCM/NoPadding",...) + - pattern: GCMParameterSpec(...) + severity: INFO +- id: kotlin.lang.security.no-null-cipher.no-null-cipher + pattern: NullCipher(...) + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher + shortlink: https://sg.run/0ywb + semgrep.dev: + rule: + r_id: 14698 + rv_id: 1263265 + rule_id: 0oU2Yy + version_id: o5TbDPj + url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - kt + - scala +- id: kotlin.lang.security.unencrypted-socket.unencrypted-socket + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/kotlin.lang.security.unencrypted-socket.unencrypted-socket + shortlink: https://sg.run/KXZd + semgrep.dev: + rule: + r_id: 14699 + rv_id: 1413421 + rule_id: KxU76z + version_id: w8TWBzA + url: https://semgrep.dev/playground/r/w8TWBzA/kotlin.lang.security.unencrypted-socket.unencrypted-socket + origin: community + message: This socket is not encrypted. The traffic could be read by an attacker + intercepting the network traffic. Use an SSLSocket created by 'SSLSocketFactory' + or 'SSLServerSocketFactory' instead + severity: WARNING + languages: + - kt + patterns: + - pattern-either: + - pattern: ServerSocket(...) + - pattern: Socket(...) + - pattern-not-inside: | + fun $FN(...): Int { + ... + val $SS = ServerSocket(0) + ... + $SS.close() + ... + } + - pattern-not-inside: | + fun $FN(...): Int { + ... + val $SS = ServerSocket(0) + ... + $SS.localPort + ... + $SS.close() + ... + } +- id: kotlin.lang.security.use-of-md5.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + languages: + - kt + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5 + shortlink: https://sg.run/4eQx + semgrep.dev: + rule: + r_id: 14700 + rv_id: 1263267 + rule_id: qNUXPj + version_id: pZT03Jd + url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5 + origin: community + pattern-either: + - pattern: | + java.security.MessageDigest.getInstance("MD5") + - pattern: | + org.apache.commons.codec.digest.DigestUtils.getMd5Digest() +- id: python.django.security.injection.tainted-sql-string.tainted-sql-string + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using the Django object-relational mappers (ORM) + instead of raw SQL queries. + metadata: + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + category: security + technology: + - django + subcategory: + - audit + impact: LOW + likelihood: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/python.django.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/PbZp + semgrep.dev: + rule: + r_id: 14701 + rv_id: 1263408 + rule_id: lBU8Ad + version_id: YDTZeje + url: https://semgrep.dev/playground/r/YDTZeje/python.django.security.injection.tainted-sql-string.tainted-sql-string + origin: community + severity: ERROR + languages: + - python + mode: taint + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* +- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as SQLAlchemy which will protect your queries. + metadata: + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column + category: security + technology: + - sqlalchemy + - flask + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/JxZj + semgrep.dev: + rule: + r_id: 14702 + rv_id: 1409402 + rule_id: YGUDKQ + version_id: A8TEvb4 + url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string + origin: community + severity: ERROR + languages: + - python + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* +- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`. + languages: + - python + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt + category: security + technology: + - pycryptodome + - hashlib + - md5 + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/5DwD + semgrep.dev: + rule: + r_id: 14703 + rv_id: 1263504 + rule_id: 6JU1w1 + version_id: WrTqKDz + url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: hashlib.md5 + - pattern: hashlib.new(..., name="MD5", ...) + - pattern: Cryptodome.Hash.MD5 + - pattern: Crypto.Hash.MD5 + - pattern: cryptography.hazmat.primitives.hashes.MD5 + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: ruby.lang.security.md5-used-as-password.md5-used-as-password + languages: + - ruby + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Instead, use a suitable password hashing function such as bcrypt. You can use + the `bcrypt` gem. + metadata: + category: security + technology: + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/GOZy + semgrep.dev: + rule: + r_id: 14704 + rv_id: 1263611 + rule_id: oqU4p2 + version_id: JdTzx0e + url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - pattern: Digest::MD5 + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...); + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host + languages: + - ruby + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction + with `SsrfFilter(...)`, or create an allowlist for approved hosts. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://github.com/arkadiyt/ssrf_filter + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RX3g + semgrep.dev: + rule: + r_id: 14705 + rv_id: 1263668 + rule_id: zdUY0W + version_id: 6xT29BN + url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sanitizers: + - pattern: SsrfFilter + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $URLSTR + - pattern-regex: \w+:\/\/#{.*} + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$URLSTR", ...) + - pattern: | + "$URLSTR" + $EXPR + - pattern: | + "$URLSTR" % $EXPR + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// ... +- id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as ActiveRecord which will protect your queries. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/Y85o + semgrep.dev: + rule: + r_id: 14714 + rv_id: 1263667 + rule_id: bwU8gl + version_id: YDTZeLL + url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sanitizers: + - pattern: | + $PARAMS.slice(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $RECORD.where($X,...) + - pattern: | + $RECORD.find(..., :conditions => $X,...) + - focus-metavariable: $X + - patterns: + - pattern: | + "$SQLVERB#{$EXPR}..." + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $SQLVERB + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", $EXPR) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key + pattern-regex: k2sk_v[0-9]_[0-9a-zA-Z]{24} + languages: + - regex + message: Kolide API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - kolide + confidence: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key + shortlink: https://sg.run/d2YQ + semgrep.dev: + rule: + r_id: 14734 + rv_id: 1262880 + rule_id: JDULYW + version_id: ZRTKApA + url: https://semgrep.dev/playground/r/ZRTKApA/generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key + origin: community +- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - php + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) + VALUES (?, ?)");`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/lZYG + semgrep.dev: + rule: + r_id: 14757 + rv_id: 1263290 + rule_id: qNUXdL + version_id: gETB7vY + url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: mysqli_real_escape_string(...) + - pattern: real_escape_string(...) + - pattern: $MYSQLI->real_escape_string(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($SQLSTR, ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "...$EXPR..." + - metavariable-regex: + metavariable: $EXPR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "$SQLSTR".$EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* +- id: php.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - php + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/Y8no + semgrep.dev: + rule: + r_id: 14758 + rv_id: 1263291 + rule_id: lBU8K1 + version_id: QkTGqRd + url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($URLSTR, ...) + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME://%s + - patterns: + - pattern: | + "...{$EXPR}..." + - pattern-regex: | + .*://\{.* + - patterns: + - pattern: | + "...$EXPR..." + - pattern-regex: | + .*://\$.* + - patterns: + - pattern: | + "...".$EXPR + - pattern-regex: | + .*://["'].* +- id: php.lang.security.md5-used-as-password.md5-used-as-password + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD, + PASSWORD_BCRYPT, $OPTIONS);`. + languages: + - php + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://www.php.net/password_hash + category: security + technology: + - md5 + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/66YL + semgrep.dev: + rule: + r_id: 14759 + rv_id: 1263294 + rule_id: YGUD1O + version_id: PkTR37j + url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5(...) + - pattern: hash('md5', ...) + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: python.django.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + impact: MEDIUM + likelihood: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.django.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/oYz6 + semgrep.dev: + rule: + r_id: 14760 + rv_id: 1263409 + rule_id: 6JU1l0 + version_id: JdTzxAj + url: https://semgrep.dev/playground/r/JdTzxAj/python.django.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: | + $URL = "$URLSTR" + ... + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + severity: WARNING +- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/9rzz + semgrep.dev: + rule: + r_id: 14767 + rv_id: 1409396 + rule_id: 10UdRR + version_id: 44TbKvr + url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + interfile: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$SQLSTR"; + ... + - pattern: String.format($VAR, ...) + - pattern-not-inside: System.out.println(...) + - pattern-not-inside: $LOG.info(...) + - pattern-not-inside: $LOG.warn(...) + - pattern-not-inside: $LOG.warning(...) + - pattern-not-inside: $LOG.debug(...) + - pattern-not-inside: $LOG.debugging(...) + - pattern-not-inside: $LOG.error(...) + - pattern-not-inside: new Exception(...) + - pattern-not-inside: throw ...; + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: bash.lang.security.ifs-tampering.ifs-tampering + languages: + - bash + severity: WARNING + message: The special variable IFS affects how splitting takes place when expanding + unquoted variables. Don't set it globally. Prefer a dedicated utility such as + 'cut' or 'awk' if you need to split input data. If you must use 'read', set IFS + locally using e.g. 'IFS="," read -a my_array'. + pattern: IFS=... + metadata: + cwe: + - 'CWE-20: Improper Input Validation' + category: security + technology: + - bash + confidence: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/bash.lang.security.ifs-tampering.ifs-tampering + shortlink: https://sg.run/Q9pq + semgrep.dev: + rule: + r_id: 14842 + rv_id: 1262603 + rule_id: WAUy9q + version_id: GxTkerb + url: https://semgrep.dev/playground/r/GxTkerb/bash.lang.security.ifs-tampering.ifs-tampering + origin: community +- id: generic.unicode.security.bidi.contains-bidirectional-characters + patterns: + - pattern-either: + - pattern-regex: "\u202A" + - pattern-regex: "\u202B" + - pattern-regex: "\u202D" + - pattern-regex: "\u202E" + - pattern-regex: "\u2066" + - pattern-regex: "\u2067" + - pattern-regex: "\u2068" + - pattern-regex: "\u202C" + - pattern-regex: "\u2069" + message: This code contains bidirectional (bidi) characters. While this is useful + for support of right-to-left languages such as Arabic or Hebrew, it can also be + used to trick language parsers into executing code in a manner that is different + from how it is displayed in code editing and review tools. If this is not what + you were expecting, please review this code in an editor that can reveal hidden + Unicode characters. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - unicode + references: + - https://trojansource.codes/ + confidence: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/generic.unicode.security.bidi.contains-bidirectional-characters + shortlink: https://sg.run/nK4r + semgrep.dev: + rule: + r_id: 14880 + rv_id: 1262904 + rule_id: d8UeX4 + version_id: JdTzxzn + url: https://semgrep.dev/playground/r/JdTzxzn/generic.unicode.security.bidi.contains-bidirectional-characters + origin: community + languages: + - bash + - c + - csharp + - go + - java + - javascript + - json + - kotlin + - lua + - ocaml + - php + - python + - ruby + - rust + - scala + - sh + - typescript + - yaml + severity: WARNING +- id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + patterns: + - pattern-either: + - patterns: + - pattern: ssl_policy = $ANYTHING + - pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+ + - pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+ + - patterns: + - pattern: protocol = "HTTP" + - pattern-not-inside: | + resource $ANYTHING $NAME { + ... + default_action { + ... + redirect { + ... + protocol = "HTTPS" + ... + } + ... + } + ... + } + - pattern-inside: | + resource $RESOURCE $X { + ... + } + - metavariable-pattern: + metavariable: $RESOURCE + patterns: + - pattern-either: + - pattern: | + "aws_lb_listener" + - pattern: | + "aws_alb_listener" + message: Detected an AWS load balancer with an insecure TLS version. TLS versions + less than 1.2 are considered insecure because they can be broken. To fix this, + set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include + a default action to redirect to HTTPS. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.ietf.org/rfc/rfc5246.txt + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + shortlink: https://sg.run/187G + semgrep.dev: + rule: + r_id: 14966 + rv_id: 1263747 + rule_id: 2ZUP9K + version_id: ExTEx0y + url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + origin: community + languages: + - hcl + severity: WARNING +- id: yaml.github-actions.security.curl-eval.curl-eval + languages: + - yaml + message: Data is being eval'd from a `curl` command. An attacker with control of + the server in the `curl` command could inject malicious code into the `eval`, + resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If + you must do this, consider checking the SHA sum of the content returned by the + server to verify its integrity. + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + technology: + - github-actions + - bash + - curl + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.curl-eval.curl-eval + shortlink: https://sg.run/9r7r + semgrep.dev: + rule: + r_id: 14967 + rv_id: 1263926 + rule_id: X5Udrd + version_id: YDTZe7K + url: https://semgrep.dev/playground/r/YDTZe7K/yaml.github-actions.security.curl-eval.curl-eval + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern: | + $DATA=<... curl ...> + ... + eval <... $DATA ...> + severity: ERROR +- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: | + (string $X) + - pattern-not: | + "..." + pattern-propagators: + - pattern: (StringBuilder $B).$ANY(...,(string $X),...) + from: $X + to: $B + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + new $PATTERN($CMD,...) + - focus-metavariable: $CMD + - patterns: + - pattern: | + $CMD.$PATTERN = $VALUE; + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $PATTERN + regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ + pattern-sanitizers: + - pattern-either: + - pattern: | + $CMD.Parameters.Add(...) + - pattern: | + $CMD.Parameters.AddRange(...) + - pattern: | + $CMD.Parameters.AddWithValue(...) + - pattern: | + $CMD.Parameters[$IDX].Value = ... + by-side-effect: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand' + and 'SqlParameter'. + metadata: + category: security + technology: + - csharp + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + shortlink: https://sg.run/d2Xd + semgrep.dev: + rule: + r_id: 15078 + rv_id: 1262648 + rule_id: x8UxeP + version_id: RGT0LqW + url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + origin: community + languages: + - csharp + severity: ERROR +- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + languages: + - scala + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + metadata: + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + shortlink: https://sg.run/Z40o + semgrep.dev: + rule: + r_id: 15079 + rv_id: 1263691 + rule_id: OrU6W1 + version_id: 7ZTE3kr + url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + origin: community + pattern-either: + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC256("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC384("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC512("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + ... + } + ... + } + severity: ERROR +- id: terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered + message: Registering the identity used by an App with AD allows it to interact with + other services without using username and password. Set the `identity` block in + your appservice. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + identity { + type = "..." + identity_ids = "..." + } + ... + } + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + identity { + type = "SystemAssigned" + } + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + metadata: + category: security + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#identity + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered + shortlink: https://sg.run/PbXY + semgrep.dev: + rule: + r_id: 15101 + rv_id: 1263754 + rule_id: WAUynd + version_id: 44TEj04 + url: https://semgrep.dev/playground/r/44TEj04/terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + message: Enabling authentication ensures that all communications in the application + are authenticated. The `auth_settings` block needs to be filled out with the appropriate + auth backend settings + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-287: Improper Authentication' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + shortlink: https://sg.run/JxYw + semgrep.dev: + rule: + r_id: 15102 + rv_id: 1263755 + rule_id: 0oU23p + version_id: PkTR3P8 + url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + message: Use the latest version of HTTP to ensure you are benefiting from security + fixes. Add `http2_enabled = true` to your appservice resource block + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + site_config { + ... + http2_enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + site_config { + ... + http2_enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response + Smuggling'')' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + shortlink: https://sg.run/5DkA + semgrep.dev: + rule: + r_id: 15103 + rv_id: 1263756 + rule_id: KxU7LJ + version_id: JdTzx98 + url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + message: By default, clients can connect to App Service by using both HTTP or HTTPS. + HTTP should be disabled enabling the HTTPS Only setting. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + https_only = true + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + https_only = false + ... + } + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only + - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + shortlink: https://sg.run/GOKp + semgrep.dev: + rule: + r_id: 15104 + rv_id: 1263757 + rule_id: qNUXwx + version_id: 5PTo1gg + url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + message: Detected an AppService that was not configured to use a client certificate. + Add `client_cert_enabled = true` in your resource block. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + client_cert_enabled = true + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + client_cert_enabled = false + ... + } + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + shortlink: https://sg.run/RX1O + semgrep.dev: + rule: + r_id: 15105 + rv_id: 1263758 + rule_id: lBU8D6 + version_id: GxTkedE + url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version + = "1.2"` in your resource block. + patterns: + - pattern: min_tls_version = $ANYTHING + - pattern-inside: | + resource "azurerm_app_service" "$NAME" { + ... + } + - pattern-not-inside: min_tls_version = "1.2" + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + shortlink: https://sg.run/AXRp + semgrep.dev: + rule: + r_id: 15106 + rv_id: 1263759 + rule_id: YGUDbZ + version_id: RGT0L4x + url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled + message: Enabling authentication ensures that all communications in the application + are authenticated. The `auth_settings` block needs to be filled out with the appropriate + auth backend settings + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_function_app" "..." { + ... + auth_settings { + ... + enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_function_app" "..." { + ... + } + - pattern-inside: | + resource "azurerm_function_app" "..." { + ... + auth_settings { + ... + enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-287: Improper Authentication' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/function_app#enabled + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled + shortlink: https://sg.run/B6AW + semgrep.dev: + rule: + r_id: 15107 + rv_id: 1263800 + rule_id: 6JU1X8 + version_id: JdTzxr8 + url: https://semgrep.dev/playground/r/JdTzxr8/terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 + message: Use the latest version of HTTP to ensure you are benefiting from security + fixes. Add `http2_enabled = true` to your function app resource block + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_function_app" "..." { + ... + site_config { + ... + http2_enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_function_app" "..." { + ... + } + - pattern-inside: | + resource "azurerm_function_app" "..." { + ... + site_config { + ... + http2_enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response + Smuggling'')' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/function_app#http2_enabled + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 + shortlink: https://sg.run/DzDY + semgrep.dev: + rule: + r_id: 15108 + rv_id: 1263801 + rule_id: oqU41L + version_id: 5PTo1Dg + url: https://semgrep.dev/playground/r/5PTo1Dg/terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny + message: Detected a Storage that was not configured to deny action by default. Add + `default_action = "Deny"` in your resource block. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_storage_account_network_rules" "..." { + ... + default_action = "Deny" + ... + } + - pattern-inside: | + resource "azurerm_storage_account_network_rules" "..." { + ... + default_action = "Allow" + ... + } + metadata: + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account_network_rules#default_action + - https://docs.microsoft.com/en-us/azure/firewall/rule-processing + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny + shortlink: https://sg.run/WpN4 + semgrep.dev: + rule: + r_id: 15109 + rv_id: 1263804 + rule_id: zdUY3N + version_id: A8Tgd7d + url: https://semgrep.dev/playground/r/A8Tgd7d/terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + message: Detected a Storage that was not configured to deny action by default. Add + `enable_https_traffic_only = true` in your resource block. + patterns: + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + enable_https_traffic_only = true + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + enable_https_traffic_only = false + ... + } + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only + - https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + shortlink: https://sg.run/0y9v + semgrep.dev: + rule: + r_id: 15110 + rv_id: 1263805 + rule_id: pKUpDA + version_id: BjTkZ0A + url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted + patterns: + - pattern-not-inside: | + resource "aws_backup_vault" $BACKUP { + ... + kms_key_arn = ... + ... + } + - pattern: resource "aws_backup_vault" $BACKUP {...} + message: The AWS Backup vault is unencrypted. The AWS KMS encryption key protects + backups in the Backup vault. To create your own, create a aws_kms_key resource + or use the ARN string of a key in your account. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted + shortlink: https://sg.run/18yw + semgrep.dev: + rule: + r_id: 15122 + rv_id: 946662 + rule_id: x8UxrP + version_id: GxTP79j + url: https://semgrep.dev/playground/r/GxTP79j/terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted + origin: community +- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + metadata: + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + shortlink: https://sg.run/rY2n + semgrep.dev: + rule: + r_id: 15125 + rv_id: 1263258 + rule_id: v8U9Q7 + version_id: WrTqKgJ + url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + origin: community + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html + for more information. + severity: WARNING + pattern: | + $ENV.put($CTX.SECURITY_AUTHENTICATION, "none") + ... + $DCTX = InitialDirContext($ENV, ...) + languages: + - kt +- id: kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion + metadata: + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + owasp: A03:2017 - Sensitive Data Exposure + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BAD_HEXA_CONVERSION + category: security + technology: + - kotlin + references: + - https://cwe.mitre.org/data/definitions/704.html + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion + shortlink: https://sg.run/b25p + semgrep.dev: + rule: + r_id: 15126 + rv_id: 945937 + rule_id: d8UegG + version_id: xyTqnDy + url: https://semgrep.dev/playground/r/xyTqnDy/kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion + origin: community + message: '''Integer.toHexString()'' strips leading zeroes from each byte if read + byte-by-byte. This mistake weakens the hash value computed since it introduces + more collisions. Use ''String.format("%02X", ...)'' instead.' + severity: WARNING + languages: + - kt + pattern: |- + fun $METHOD(...) { + ... + val $MD: MessageDigest = ... + ... + $MD.digest(...) + ... + Integer.toHexString(...) + } +- id: kotlin.lang.security.use-of-sha1.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + languages: + - kt + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/N1pp + semgrep.dev: + rule: + r_id: 15127 + rv_id: 1263268 + rule_id: ZqUOdd + version_id: 2KTv2XZ + url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1 + origin: community + pattern-either: + - patterns: + - pattern: | + $VAR = $MD.getInstance("$ALGO") + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: | + $DU.getSha1Digest().digest(...) +- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - kt + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - kotlin + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/krq7 + semgrep.dev: + rule: + r_id: 15128 + rv_id: 1263269 + rule_id: nJUZNL + version_id: X0TzypE + url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + $KEY = $G.getInstance("RSA") + ... + $KEY.initialize($BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 +- id: terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret + message: Key vault Secret should have a content type set + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault_secret" "..." { + ... + content_type = "..." + ... + } + - pattern-inside: | + resource "azurerm_key_vault_secret" "..." { + ... + } + metadata: + category: correctness + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_secret#content_type + - https://docs.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret + shortlink: https://sg.run/eoAb + semgrep.dev: + rule: + r_id: 15132 + rv_id: 946862 + rule_id: 8GUzld + version_id: JdTDP3Y + url: https://semgrep.dev/playground/r/JdTDP3Y/terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires + message: Ensure that the expiration date is set on all keys + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault_key" "..." { + ... + expiration_date = "..." + ... + } + - pattern-inside: | + resource "azurerm_key_vault_key" "..." { + ... + } + metadata: + cwe: + - 'CWE-262: Not Using Password Aging' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_key#expiration_date + - https://docs.microsoft.com/en-us/powershell/module/az.keyvault/update-azkeyvaultkey?view=azps-5.8.0#example-1--modify-a-key-to-enable-it--and-set-the-expiration-date-and-tags + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires + shortlink: https://sg.run/vq9A + semgrep.dev: + rule: + r_id: 15133 + rv_id: 946863 + rule_id: gxUgXq + version_id: 5PT94PR + url: https://semgrep.dev/playground/r/5PT94PR/terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires + message: Ensure that the expiration date is set on all secrets + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault_secret" "..." { + ... + expiration_date = "..." + ... + } + - pattern-not-inside: | + resource "azurerm_key_vault_secret" "..." { + ... + expiration_date = ... + ... + } + - pattern-inside: | + resource "azurerm_key_vault_secret" "..." { + ... + } + metadata: + cwe: + - 'CWE-262: Not Using Password Aging' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_secret#expiration_date + - https://docs.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires + shortlink: https://sg.run/d2RZ + semgrep.dev: + rule: + r_id: 15134 + rv_id: 1028693 + rule_id: QrUdNy + version_id: 0bTl7og + url: https://semgrep.dev/playground/r/0bTl7og/terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled + message: Key vault should have purge protection enabled + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault" "..." { + ... + purge_protection_enabled = true + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_key_vault" "..." { + ... + } + - pattern-inside: | + resource "azurerm_key_vault" "..." { + ... + purge_protection_enabled = false + ... + } + metadata: + cwe: + - 'CWE-693: Protection Mechanism Failure' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault#purge_protection_enabled + - https://docs.microsoft.com/en-us/azure/key-vault/general/soft-delete-overview#purge-protection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled + shortlink: https://sg.run/Z4xD + semgrep.dev: + rule: + r_id: 15135 + rv_id: 946865 + rule_id: 3qUjw9 + version_id: RGTAPQ7 + url: https://semgrep.dev/playground/r/RGTAPQ7/terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl + message: Network ACLs allow you to reduce your exposure to risk by limiting what + can access your key vault. The default action of the Network ACL should be set + to deny for when IPs are not matched. Azure services can be allowed to bypass. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault" "..." { + ... + network_acls { + ... + default_action = "Deny" + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_key_vault" "..." { + ... + } + - pattern-inside: | + resource "azurerm_key_vault" "..." { + ... + network_acls { + ... + default_action = "Allow" + ... + } + ... + } + metadata: + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault#network_acls + - https://docs.microsoft.com/en-us/azure/key-vault/general/network-security + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl + shortlink: https://sg.run/nKgX + semgrep.dev: + rule: + r_id: 15136 + rv_id: 1263802 + rule_id: 4bU1jy + version_id: GxTkeEE + url: https://semgrep.dev/playground/r/GxTkeEE/terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl + origin: community + languages: + - hcl + severity: ERROR +- id: json.aws.security.wildcard-assume-role.wildcard-assume-role + patterns: + - pattern-inside: | + "Statement": [...] + - pattern-inside: | + {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} + - pattern: | + "Principal": {..., "AWS": "*", ...} + message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone + with your AWS account ID and the name of the role can assume the role. Instead, + limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - aws + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role + shortlink: https://sg.run/7YEZ + semgrep.dev: + rule: + r_id: 15138 + rv_id: 1263256 + rule_id: JDULx5 + version_id: BjTkZoy + url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role + origin: community + languages: + - json + severity: ERROR +- id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role + patterns: + - pattern-inside: | + resource "aws_iam_role" $NAME { + ... + } + - pattern: assume_role_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-inside: | + {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} + - pattern: | + "Principal": {..., "AWS": "*", ...} + message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone + with your AWS account ID and the name of the role can assume the role. Instead, + limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - aws + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + shortlink: https://sg.run/LXWr + semgrep.dev: + rule: + r_id: 15139 + rv_id: 1263749 + rule_id: 5rUL1P + version_id: LjTkg8D + url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass + message: Some Microsoft services that interact with storage accounts operate from + networks that can't be granted access through network rules. To help this type + of service work as intended, allow the set of trusted Microsoft services to bypass + the network rules + patterns: + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + network_rules { + ... + bypass = ["...", "AzureServices"] + ... + } + ... + } + - pattern-not-inside: | + resource "azurerm_storage_account_network_rules" "..." { + ... + bypass = ["...", "AzureServices"] + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_storage_account_network_rules" "..." { + ... + bypass = [$ANYTHING] + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + network_rules { + ... + bypass = [$ANYTHING] + ... + } + ... + } + metadata: + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#bypass + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account_network_rules#bypass + - https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security#trusted-microsoft-services + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass + shortlink: https://sg.run/WpX4 + semgrep.dev: + rule: + r_id: 15153 + rv_id: 1263803 + rule_id: GdUreY + version_id: RGT0LGx + url: https://semgrep.dev/playground/r/RGT0LGx/terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging + message: Storage Analytics logs detailed information about successful and failed + requests to a storage service. This information can be used to monitor individual + requests and to diagnose issues with a storage service. Requests are logged on + a best-effort basis. + patterns: + - pattern-either: + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + queue_properties { + ... + } + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + } + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + queue_properties { + ... + logging { + ... + } + ... + } + ... + } + metadata: + cwe: + - 'CWE-778: Insufficient Logging' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#logging + - https://docs.microsoft.com/en-us/azure/storage/common/storage-analytics-logging?tabs=dotnet + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging + shortlink: https://sg.run/0yEv + semgrep.dev: + rule: + r_id: 15154 + rv_id: 1263806 + rule_id: ReU3L9 + version_id: DkTRb05 + url: https://semgrep.dev/playground/r/DkTRb05/terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0, + 1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0 + and TLS 1.1 are still supported for backward compatibility. This check will warn + if the minimum TLS is not set to TLS1_2.' + patterns: + - pattern-either: + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + min_tls_version = "$ANYTHING" + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + } + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + min_tls_version = "TLS1_2" + ... + } + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version + - https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + shortlink: https://sg.run/KXD7 + semgrep.dev: + rule: + r_id: 15155 + rv_id: 1263807 + rule_id: AbUQdL + version_id: WrTqKpv + url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + origin: community + languages: + - hcl + severity: ERROR +- id: python.lang.security.audit.python-reverse-shell.python-reverse-shell + patterns: + - pattern-either: + - pattern: pty.spawn("$BINPATH",...) + - pattern: subprocess.call(["$BINPATH",...],...) + - metavariable-regex: + metavariable: $BINPATH + regex: /bin/.*?sh\b + - pattern-inside: | + import socket + ... + $S = socket.socket(...) + ... + $S.connect(($IP,$PORT),...) + ... + message: Semgrep found a Python reverse shell using $BINPATH to $IP at $PORT + metadata: + cwe: + - 'CWE-553: Command Shell in Externally Accessible Directory' + category: security + technology: + - python + references: + - https://cwe.mitre.org/data/definitions/553.html + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.python-reverse-shell.python-reverse-shell + shortlink: https://sg.run/gYZJ + semgrep.dev: + rule: + r_id: 15185 + rv_id: 946375 + rule_id: nJUZRY + version_id: BjT1NZ4 + url: https://semgrep.dev/playground/r/BjT1NZ4/python.lang.security.audit.python-reverse-shell.python-reverse-shell + origin: community + languages: + - python + severity: WARNING +- id: scala.lang.security.audit.insecure-random.insecure-random + metadata: + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - scala + - cryptography + resources: + - https://find-sec-bugs.github.io/bugs.htm + confidence: LOW + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.lang.security.audit.insecure-random.insecure-random + shortlink: https://sg.run/JxAw + semgrep.dev: + rule: + r_id: 15190 + rv_id: 1263674 + rule_id: gxUgDk + version_id: jQTn5Px + url: https://semgrep.dev/playground/r/jQTn5Px/scala.lang.security.audit.insecure-random.insecure-random + origin: community + message: Flags the use of a predictable random value from `scala.util.Random`. This + can lead to vulnerabilities when used in security contexts, such as in a CSRF + token, password reset token, or any other secret value. To fix this, use java.security.SecureRandom + instead. + severity: WARNING + languages: + - scala + patterns: + - pattern: | + import scala.util.Random +- id: scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - scala + resources: + - https://find-sec-bugs.github.io/bugs.htm + confidence: LOW + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile + shortlink: https://sg.run/5D1A + semgrep.dev: + rule: + r_id: 15191 + rv_id: 1263676 + rule_id: QrUdOZ + version_id: 9lT4bpj + url: https://semgrep.dev/playground/r/9lT4bpj/scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile + origin: community + message: Flags cases of possible path traversal. If an unfiltered parameter is passed + into 'fromFile', file from an arbitrary filesystem location could be read. This + could lead to sensitive data exposure and other provles. Instead, sanitize the + user input instead of performing direct string concatenation. + severity: WARNING + languages: + - scala + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $FILENAME = "..." + $VAR + ... + - pattern-inside: | + $FILENAME = $VAR + "..." + ... + - pattern-inside: | + $FILENAME = $STR.concat($VAR) + ... + - pattern-inside: | + $FILENAME = "...".format(..., $VAR, ...) + ... + - pattern: Source.fromFile($FILENAME, ...) + - patterns: + - pattern-either: + - pattern: Source.fromFile("..." + $VAR, ...) + - pattern: Source.fromFile($VAR + "...", ...) + - pattern: Source.fromFile($STR.concat($VAR), ...) + - pattern: Source.fromFile("...".format(..., $VAR, ...), ...) + - pattern-inside: | + def $FUNC(..., $VAR: $TYPE, ...) = Action { + ... + } +- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set + metadata: + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - scala + - cryptography + resources: + - https://blog.codacy.com/9-scala-security-issues/ + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + shortlink: https://sg.run/GO5p + semgrep.dev: + rule: + r_id: 15192 + rv_id: 1263677 + rule_id: 3qUj1Q + version_id: yeTxpoX + url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + origin: community + message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken + encryption. This could lead to sensitive data exposure. Instead, use RSA with + `OAEPWithMD5AndMGF1Padding` instead. + severity: WARNING + languages: + - scala + patterns: + - pattern: | + $VAR = $CIPHER.getInstance($MODE) + - metavariable-regex: + metavariable: $MODE + regex: .*RSA/.*/NoPadding.* +- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" + to the bucket props for Bucket construct $X' + metadata: + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + shortlink: https://sg.run/eowX + semgrep.dev: + rule: + r_id: 15276 + rv_id: 1263903 + rule_id: bwU8qz + version_id: GxTkeRx + url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + origin: community + languages: + - typescript + severity: ERROR + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3' + ... + - pattern: const $X = new Bucket(...) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...}) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3' + ... + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...}) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...}) +- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + message: Bucket $X is not set to enforce encryption-in-transit, if not explictly + setting this on the bucket policy - the property "enforceSSL" should be set to + true + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + shortlink: https://sg.run/vqBX + semgrep.dev: + rule: + r_id: 15277 + rv_id: 1263904 + rule_id: NbUN8B + version_id: RGT0Llg + url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + origin: community + languages: + - ts + severity: ERROR + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3'; + ... + - pattern: const $X = new Bucket(...) + - pattern-not: | + const $X = new Bucket(..., {enforceSSL: true}, ...) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3'; + ... + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...}) +- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" + or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption + at rest for the queue.' + metadata: + category: security + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + shortlink: https://sg.run/d23P + semgrep.dev: + rule: + r_id: 15278 + rv_id: 1263905 + rule_id: kxUwqO + version_id: A8Tgd2W + url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Queue} from '@aws-cdk/aws-sqs' + ... + - pattern: const $X = new Queue(...) + - pattern-not: | + const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-sqs' + ... + - pattern: const $X = new $Y.Queue(...) + - pattern-not: | + const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...}) +- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + message: Using the GrantPublicAccess method on bucket contruct $X will make the + objects in the bucket world accessible. Verify if this is intentional. + metadata: + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + shortlink: https://sg.run/Z4p7 + semgrep.dev: + rule: + r_id: 15279 + rv_id: 1263906 + rule_id: wdUjZK + version_id: BjTkZA7 + url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new Bucket(...) + ... + $X.grantPublicAccess(...) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new $Y.Bucket(...) + ... + $X.grantPublicAccess(...) +- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + message: CodeBuild Project $X is set to have a public URL. This will make the build + results, logs, artifacts publically accessible, including builds prior to the + project being public. Ensure this is acceptable for the project. + metadata: + category: security + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + shortlink: https://sg.run/nK7G + semgrep.dev: + rule: + r_id: 15280 + rv_id: 1263907 + rule_id: x8UxXZ + version_id: DkTRbj1 + url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Project} from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new Project(..., {..., badge: true, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new $Y.Project(..., {..., badge: true, ...}) +- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + mode: taint + pattern-sinks: + - pattern: | + sqlalchemy.text(...) + pattern-sources: + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $Y + type: string + - patterns: + - pattern: | + f"..." + - patterns: + - pattern: | + $X.format(...) + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X % $Y + - metavariable-type: + metavariable: $X + type: string + message: sqlalchemy.text passes the constructed SQL statement to the database mostly + unchanged. This means that the usual SQL injection protections are not applied + and this function is vulnerable to SQL injection if user input can reach here. + Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct + SQL. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - sqlalchemy + confidence: MEDIUM + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + shortlink: https://sg.run/yP1O + semgrep.dev: + rule: + r_id: 15824 + rv_id: 1263577 + rule_id: r6U2wE + version_id: rxTAKqq + url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + origin: community + languages: + - python + severity: ERROR +- id: terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption + patterns: + - pattern: resource "aws_athena_workgroup" $ANYTHING {...} + - pattern-not-inside: | + resource "aws_athena_workgroup" $ANYTHING { + ... + encryption_configuration {...} + ... + } + message: 'The AWS Athena Workgroup is unencrypted. Encryption protects query results + in your workgroup. To enable, add: `encryption_configuration { encryption_option + = "SSE_KMS" kms_key_arn = aws_kms_key.example.arn }` within `result_configuration + { }` in your resource block, where `encryption_option` is your chosen encryption + method and `kms_key_arn` is your KMS key ARN.' + languages: + - hcl + severity: WARNING + metadata: + technology: + - aws + - terraform + category: security + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption + shortlink: https://sg.run/kzro + semgrep.dev: + rule: + r_id: 15828 + rv_id: 946736 + rule_id: wdUljO + version_id: jQTzqko + url: https://semgrep.dev/playground/r/jQTzqko/terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption + origin: community +- id: terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging + patterns: + - pattern: | + name = ... + - pattern-inside: | + resource "aws_eks_cluster" "..." { + ... + } + - pattern-not-inside: | + resource "aws_eks_cluster" "..." { + ... + enabled_cluster_log_types = [..., "api", ..., "audit", ...] + ... + } + - pattern-not-inside: | + resource "aws_eks_cluster" "..." { + ... + enabled_cluster_log_types = [..., "audit", ..., "api", ...] + ... + } + languages: + - hcl + message: Missing EKS control plane logging. It is recommended to enable at least + Kubernetes API server component logs ("api") and audit logs ("audit") of the EKS + control plane through the enabled_cluster_log_types attribute. + severity: WARNING + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_cluster#enabling-control-plane-logging + - https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html + category: security + cwe: + - 'CWE-778: Insufficient Logging' + technology: + - terraform + - aws + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging + shortlink: https://sg.run/wZ3n + semgrep.dev: + rule: + r_id: 15829 + rv_id: 1263886 + rule_id: x8UGx7 + version_id: O9Tpxxw + url: https://semgrep.dev/playground/r/O9Tpxxw/terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging + origin: community +- id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + pattern-either: + - patterns: + - pattern: password = "..." + - pattern-inside: | + resource "aws_db_instance" "..." { + ... + } + - patterns: + - pattern: master_password = "..." + - pattern-inside: | + resource "aws_rds_cluster" "..." { + ... + } + languages: + - hcl + severity: WARNING + message: RDS instance or cluster with hardcoded credentials in source code. It is + recommended to pass the credentials at runtime, or generate random credentials + using the random_password resource. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password + - https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + category: security + technology: + - terraform + - aws + - secrets + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + shortlink: https://sg.run/x4qA + semgrep.dev: + rule: + r_id: 15830 + rv_id: 1263896 + rule_id: OrUl6W + version_id: gETB77b + url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + origin: community +- id: terraform.lang.security.rds-public-access.rds-public-access + patterns: + - pattern: publicly_accessible = true + - pattern-inside: | + resource "aws_db_instance" "..." { + ... + } + languages: + - hcl + severity: WARNING + message: RDS instance accessible from the Internet detected. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#publicly_accessible + - https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_VPC.WorkingWithRDSInstanceinaVPC.html#USER_VPC.Hiding + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + category: security + technology: + - terraform + - aws + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.lang.security.rds-public-access.rds-public-access + shortlink: https://sg.run/Oye2 + semgrep.dev: + rule: + r_id: 15831 + rv_id: 1263897 + rule_id: eqUrzK + version_id: QkTGqqJ + url: https://semgrep.dev/playground/r/QkTGqqJ/terraform.lang.security.rds-public-access.rds-public-access + origin: community +- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - ci + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell + shortlink: https://sg.run/4l9l + semgrep.dev: + rule: + r_id: 16200 + rv_id: 1262664 + rule_id: gxUJrJ + version_id: jQTn5QE + url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell + origin: community + message: Semgrep found a bash reverse shell + severity: ERROR + languages: + - generic + pattern-either: + - pattern: | + sh -i >& /dev/udp/.../... 0>&1 + - pattern: | + <...>/dev/tcp/.../...; sh <&... >&... 2>& + - pattern: | + <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done + - pattern: | + sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& +- id: ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection + pattern: skip_forgery_protection + message: This call turns off CSRF protection allowing CSRF attacks against the application + languages: + - ruby + severity: WARNING + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + category: security + technology: + - rails + references: + - https://api.rubyonrails.org/classes/ActionController/RequestForgeryProtection/ClassMethods.html#method-i-skip_forgery_protection + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection + shortlink: https://sg.run/PgwY + semgrep.dev: + rule: + r_id: 16201 + rv_id: 1263627 + rule_id: QrUnEk + version_id: pZT03ZD + url: https://semgrep.dev/playground/r/pZT03ZD/ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection + origin: community +- id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + patterns: + - pattern: a + - pattern: b + languages: + - hcl + severity: INFO + message: This rule has been deprecated, as all s3 buckets are encrypted by default + with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration + for more info. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + deprecated: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + shortlink: https://sg.run/Jezw + semgrep.dev: + rule: + r_id: 16202 + rv_id: 1263901 + rule_id: 3qU62L + version_id: JdTzxjN + url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + origin: community +- id: php.lang.security.injection.tainted-filename.tainted-filename + severity: WARNING + message: File name based on user input risks server-side request forgery. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename + shortlink: https://sg.run/Ayqp + semgrep.dev: + rule: + r_id: 16250 + rv_id: 1263287 + rule_id: 5rUpro + version_id: 7ZTE3J1 + url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: basename($PATH, ...) + - pattern-inside: linkinfo($PATH, ...) + - pattern-inside: readlink($PATH, ...) + - pattern-inside: realpath($PATH, ...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: opcache_compile_file($FILENAME, ...) + - pattern-inside: opcache_invalidate($FILENAME, ...) + - pattern-inside: opcache_is_script_cached($FILENAME, ...) + - pattern-inside: runkit7_import($FILENAME, ...) + - pattern-inside: readline_read_history($FILENAME, ...) + - pattern-inside: readline_write_history($FILENAME, ...) + - pattern-inside: rar_open($FILENAME, ...) + - pattern-inside: zip_open($FILENAME, ...) + - pattern-inside: gzfile($FILENAME, ...) + - pattern-inside: gzopen($FILENAME, ...) + - pattern-inside: readgzfile($FILENAME, ...) + - pattern-inside: hash_file($ALGO, $FILENAME, ...) + - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) + - pattern-inside: pg_trace($FILENAME, ...) + - pattern-inside: dio_open($FILENAME, ...) + - pattern-inside: finfo_file($FINFO, $FILENAME, ...) + - pattern-inside: mime_content_type($FILENAME, ...) + - pattern-inside: chgrp($FILENAME, ...) + - pattern-inside: chmod($FILENAME, ...) + - pattern-inside: chown($FILENAME, ...) + - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) + - pattern-inside: file_exists($FILENAME, ...) + - pattern-inside: file_get_contents($FILENAME, ...) + - pattern-inside: file_put_contents($FILENAME, ...) + - pattern-inside: file($FILENAME, ...) + - pattern-inside: fileatime($FILENAME, ...) + - pattern-inside: filectime($FILENAME, ...) + - pattern-inside: filegroup($FILENAME, ...) + - pattern-inside: fileinode($FILENAME, ...) + - pattern-inside: filemtime($FILENAME, ...) + - pattern-inside: fileowner($FILENAME, ...) + - pattern-inside: fileperms($FILENAME, ...) + - pattern-inside: filesize($FILENAME, ...) + - pattern-inside: filetype($FILENAME, ...) + - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) + - pattern-inside: fopen($FILENAME, ...) + - pattern-inside: is_dir($FILENAME, ...) + - pattern-inside: is_executable($FILENAME, ...) + - pattern-inside: is_file($FILENAME, ...) + - pattern-inside: is_link($FILENAME, ...) + - pattern-inside: is_readable($FILENAME, ...) + - pattern-inside: is_uploaded_file($FILENAME, ...) + - pattern-inside: is_writable($FILENAME, ...) + - pattern-inside: lchgrp($FILENAME, ...) + - pattern-inside: lchown($FILENAME, ...) + - pattern-inside: lstat($FILENAME, ...) + - pattern-inside: parse_ini_file($FILENAME, ...) + - pattern-inside: readfile($FILENAME, ...) + - pattern-inside: stat($FILENAME, ...) + - pattern-inside: touch($FILENAME, ...) + - pattern-inside: unlink($FILENAME, ...) + - pattern-inside: xattr_get($FILENAME, ...) + - pattern-inside: xattr_list($FILENAME, ...) + - pattern-inside: xattr_remove($FILENAME, ...) + - pattern-inside: xattr_set($FILENAME, ...) + - pattern-inside: xattr_supported($FILENAME, ...) + - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) + - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_new_personal($FILENAME, ...) + - pattern-inside: exif_imagetype($FILENAME, ...) + - pattern-inside: getimagesize($FILENAME, ...) + - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) + - pattern-inside: imagecreatefromavif($FILENAME, ...) + - pattern-inside: imagecreatefrombmp($FILENAME, ...) + - pattern-inside: imagecreatefromgd2($FILENAME, ...) + - pattern-inside: imagecreatefromgd2part($FILENAME, ...) + - pattern-inside: imagecreatefromgd($FILENAME, ...) + - pattern-inside: imagecreatefromgif($FILENAME, ...) + - pattern-inside: imagecreatefromjpeg($FILENAME, ...) + - pattern-inside: imagecreatefrompng($FILENAME, ...) + - pattern-inside: imagecreatefromtga($FILENAME, ...) + - pattern-inside: imagecreatefromwbmp($FILENAME, ...) + - pattern-inside: imagecreatefromwebp($FILENAME, ...) + - pattern-inside: imagecreatefromxbm($FILENAME, ...) + - pattern-inside: imagecreatefromxpm($FILENAME, ...) + - pattern-inside: imageloadfont($FILENAME, ...) + - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) + - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, + ...) + - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) + - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) + - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) + - pattern-inside: fdf_open($FILENAME, ...) + - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) + - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) + - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) + - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) + - pattern-inside: posix_access($FILENAME, ...) + - pattern-inside: posix_mkfifo($FILENAME, ...) + - pattern-inside: posix_mknod($FILENAME, ...) + - pattern-inside: ftok($FILENAME, ...) + - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) + - pattern-inside: fann_read_train_from_file($FILENAME, ...) + - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) + - pattern-inside: highlight_file($FILENAME, ...) + - pattern-inside: php_strip_whitespace($FILENAME, ...) + - pattern-inside: stream_resolve_include_path($FILENAME, ...) + - pattern-inside: swoole_async_read($FILENAME, ...) + - pattern-inside: swoole_async_readfile($FILENAME, ...) + - pattern-inside: swoole_async_write($FILENAME, ...) + - pattern-inside: swoole_async_writefile($FILENAME, ...) + - pattern-inside: swoole_load_module($FILENAME, ...) + - pattern-inside: tidy_parse_file($FILENAME, ...) + - pattern-inside: tidy_repair_file($FILENAME, ...) + - pattern-inside: get_meta_tags($FILENAME, ...) + - pattern-inside: yaml_emit_file($FILENAME, ...) + - pattern-inside: yaml_parse_file($FILENAME, ...) + - pattern-inside: curl_file_create($FILENAME, ...) + - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) + - pattern-inside: ftp_delete($FTP, $FILENAME, ...) + - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) + - pattern-inside: ftp_size($FTP, $FILENAME, ...) + - pattern-inside: rrd_create($FILENAME, ...) + - pattern-inside: rrd_fetch($FILENAME, ...) + - pattern-inside: rrd_graph($FILENAME, ...) + - pattern-inside: rrd_info($FILENAME, ...) + - pattern-inside: rrd_last($FILENAME, ...) + - pattern-inside: rrd_lastupdate($FILENAME, ...) + - pattern-inside: rrd_tune($FILENAME, ...) + - pattern-inside: rrd_update($FILENAME, ...) + - pattern-inside: snmp_read_mib($FILENAME, ...) + - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) + - pattern-inside: apache_lookup_uri($FILENAME, ...) + - pattern-inside: md5_file($FILENAME, ...) + - pattern-inside: sha1_file($FILENAME, ...) + - pattern-inside: simplexml_load_file($FILENAME, ...) + - pattern: $FILENAME +- id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + languages: + - php + severity: WARNING + message: <- A new object is created where the class name is based on user input. + This could lead to remote code execution, as it allows to instantiate any class + in the application. + metadata: + cwe: + - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe + Reflection'')' + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + shortlink: https://sg.run/7ndw + semgrep.dev: + rule: + r_id: 16438 + rv_id: 1263288 + rule_id: v8U4DA + version_id: LjTkgLy + url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: new $SINK(...) + - pattern: $SINK +- id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + patterns: + - pattern-inside: | + provider "aws" { + ... + secret_key = "$SECRET" + } + - focus-metavariable: $SECRET + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + languages: + - hcl + severity: WARNING + metadata: + technology: + - secrets + - aws + - terraform + category: security + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + shortlink: https://sg.run/L3kn + semgrep.dev: + rule: + r_id: 16439 + rv_id: 1263735 + rule_id: d8U4n0 + version_id: rxTAK76 + url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + origin: community +- id: ruby.rails.security.audit.detailed-exceptions.detailed-exceptions + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_detailed_exceptions.rb + category: security + technology: + - rails + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/ruby.rails.security.audit.detailed-exceptions.detailed-exceptions + shortlink: https://sg.run/Je0d + semgrep.dev: + rule: + r_id: 16546 + rv_id: 1263626 + rule_id: 8GUAo4 + version_id: zyTb2oJ + url: https://semgrep.dev/playground/r/zyTb2oJ/ruby.rails.security.audit.detailed-exceptions.detailed-exceptions + origin: community + message: Found that the setting for providing detailed exception reports in Rails + is set to true. This can lead to information exposure, where sensitive system + or internal information is displayed to the end user. Instead, turn this setting + off. + languages: + - ruby + severity: WARNING + patterns: + - pattern-either: + - patterns: + - pattern: | + config.consider_all_requests_local = true + - patterns: + - pattern-inside: | + class $CONTROLLER < ApplicationController + ... + end + - pattern: | + def show_detailed_exceptions? (...) + ... + return $RETURN + end + - metavariable-pattern: + metavariable: $RETURN + patterns: + - pattern-not: | + false +- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - laravel + references: + - https://laravel.com/docs/8.x/queries + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection + shortlink: https://sg.run/x40p + semgrep.dev: + rule: + r_id: 16830 + rv_id: 1263313 + rule_id: j2UQdp + version_id: BjTkZ45 + url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection + origin: community + severity: WARNING + message: Detected a SQL query based on user input. This could lead to SQL injection, + which could potentially result in sensitive data being exfiltrated by attackers. + Instead, use parameterized queries and prepared statements. + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $SQL + - pattern-either: + - pattern-inside: DB::table(...)->whereRaw($SQL, ...) + - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) + - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) + - pattern-inside: DB::table(...)->havingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) + - patterns: + - pattern: $EXPRESSION + - pattern-either: + - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) + - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) + - patterns: + - pattern: $COLUMNS + - pattern-either: + - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereNull($COLUMN) + - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->find($ID, $COLUMNS) + - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) + - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) + - pattern-inside: DB::table(...)->select($COLUMNS) + - pattern-inside: DB::table(...)->get($COLUMNS) + - pattern-inside: DB::table(...)->count($COLUMNS) + - patterns: + - pattern: $COLUMN + - pattern-either: + - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) + - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->having($COLUMN, ...) + - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) + - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) + - pattern-inside: DB::table(...)->orderByDesc($COLUMN) + - pattern-inside: DB::table(...)->latest($COLUMN) + - pattern-inside: DB::table(...)->oldest($COLUMN) + - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->value($COLUMN) + - pattern-inside: DB::table(...)->pluck($COLUMN, ...) + - pattern-inside: DB::table(...)->implode($COLUMN, ...) + - pattern-inside: DB::table(...)->min($COLUMN) + - pattern-inside: DB::table(...)->max($COLUMN) + - pattern-inside: DB::table(...)->sum($COLUMN) + - pattern-inside: DB::table(...)->avg($COLUMN) + - pattern-inside: DB::table(...)->average($COLUMN) + - pattern-inside: DB::table(...)->increment($COLUMN, ...) + - pattern-inside: DB::table(...)->decrement($COLUMN, ...) + - pattern-inside: DB::table(...)->where($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) + - pattern-inside: DB::table(...)->addSelect($COLUMN) + - patterns: + - pattern: $QUERY + - pattern-inside: DB::unprepared($QUERY) +- id: trailofbits.python.automatic-memory-pinning.automatic-memory-pinning + message: If possible, it is better to rely on automatic pinning in PyTorch to avoid + undefined behavior and for efficiency + languages: + - python + severity: WARNING + metadata: + category: security + cwe: 'CWE-676: Use of Potentially Dangerous Function' + subcategory: + - audit + confidence: HIGH + likelihood: LOW + impact: LOW + technology: + - pytorch + description: '`PyTorch` memory not automatically pinned' + references: + - https://pytorch.org/docs/stable/data.html#memory-pinning + license: AGPL-3.0 license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/trailofbits.python.automatic-memory-pinning.automatic-memory-pinning + shortlink: https://sg.run/jz5N + semgrep.dev: + rule: + r_id: 17165 + rv_id: 833289 + rule_id: WAUN1Z + version_id: gETy20E + url: https://semgrep.dev/playground/r/gETy20E/trailofbits.python.automatic-memory-pinning.automatic-memory-pinning + origin: community + pattern-either: + - patterns: + - pattern: torch.utils.data.DataLoader(...) + - pattern-not: torch.utils.data.DataLoader(..., pin_memory=$VALUE, ...) + - pattern: torch.utils.data.DataLoader(..., pin_memory=False, ...) +- id: trailofbits.python.lxml-in-pandas.lxml-in-pandas + message: Found usage of the `$FLAVOR` library, which is vulnerable to attacks such + as XML external entity (XXE) attacks + languages: + - python + severity: ERROR + metadata: + category: security + cwe: 'CWE-611: Improper Restriction of XML External Entity Reference' + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: MEDIUM + technology: + - pandas + description: Potential XXE attacks from loading `lxml` in pandas + references: + - https://lxml.de/FAQ.html + license: AGPL-3.0 license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/trailofbits.python.lxml-in-pandas.lxml-in-pandas + shortlink: https://sg.run/1z1G + semgrep.dev: + rule: + r_id: 17166 + rv_id: 833290 + rule_id: 0oUrdJ + version_id: QkTkr22 + url: https://semgrep.dev/playground/r/QkTkr22/trailofbits.python.lxml-in-pandas.lxml-in-pandas + origin: community + pattern-either: + - patterns: + - pattern: pandas.read_html($IO) + - pattern-not: pandas.read_html(**$KWARGS) + - patterns: + - metavariable-pattern: + metavariable: $FLAVOR + patterns: + - pattern: '...' + - pattern-not: | + "bs4" + - pattern-not: | + "html5lib" + - pattern-either: + - pattern: pandas.read_html(..., flavor=$FLAVOR, ...) + - patterns: + - pattern-inside: | + $KWARGS = {..., "flavor": $FLAVOR, ...} + ... + - pattern: | + pandas.read_html(**$KWARGS) +- id: trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules + message: Usage of NumPy library inside PyTorch `$MODULE` module was found. Avoid + mixing these libraries for efficiency and proper ONNX loading + languages: + - python + severity: WARNING + metadata: + category: performance + subcategory: + - audit + confidence: MEDIUM + technology: + - pytorch + - numpy + description: Uses of `NumPy` functions inside `PyTorch` modules + references: + - https://tanelp.github.io/posts/a-bug-that-plagues-thousands-of-open-source-ml-projects + license: AGPL-3.0 license + source: https://semgrep.dev/r/trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules + shortlink: https://sg.run/9vxr + semgrep.dev: + rule: + r_id: 17167 + rv_id: 833295 + rule_id: KxU507 + version_id: 5PTyDEK + url: https://semgrep.dev/playground/r/5PTyDEK/trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules + origin: community + patterns: + - pattern-either: + - pattern: numpy.$FN(...) + - pattern: numpy. ... .$FN(...) + - pattern-inside: | + class $MODULE(torch.nn.Module): + ... +- id: trailofbits.python.pickles-in-numpy.pickles-in-numpy + message: Functions reliant on pickle can result in arbitrary code execution. Consider + using fickling or switching to a safer serialization method + languages: + - python + severity: ERROR + metadata: + category: security + cwe: 'CWE-502: Deserialization of Untrusted Data' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + technology: + - numpy + description: Potential arbitrary code execution from `NumPy` functions reliant + on pickling + references: + - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ + license: AGPL-3.0 license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/trailofbits.python.pickles-in-numpy.pickles-in-numpy + shortlink: https://sg.run/ryKe + semgrep.dev: + rule: + r_id: 17169 + rv_id: 833301 + rule_id: lBUWjy + version_id: WrTdpJ9 + url: https://semgrep.dev/playground/r/WrTdpJ9/trailofbits.python.pickles-in-numpy.pickles-in-numpy + origin: community + patterns: + - pattern: numpy.load(..., allow_pickle=$VALUE, ...) + - pattern-not: numpy.load("...", ...) + - pattern-not: numpy.load(..., file="...", ...) + - metavariable-pattern: + metavariable: $VALUE + patterns: + - pattern-not: | + False + - pattern-not: | + [] + - pattern-not: | + None + - pattern-not: | + "" +- id: trailofbits.python.pickles-in-pandas.pickles-in-pandas + message: Functions reliant on pickle can result in arbitrary code execution. Consider + using fickling or switching to a safer serialization method + languages: + - python + severity: ERROR + metadata: + category: security + cwe: 'CWE-502: Deserialization of Untrusted Data' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + technology: + - pandas + description: Potential arbitrary code execution from `Pandas` functions reliant + on pickling + references: + - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ + license: AGPL-3.0 license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/trailofbits.python.pickles-in-pandas.pickles-in-pandas + shortlink: https://sg.run/bXQW + semgrep.dev: + rule: + r_id: 17170 + rv_id: 833302 + rule_id: PeU06j + version_id: 0bTwbqN + url: https://semgrep.dev/playground/r/0bTwbqN/trailofbits.python.pickles-in-pandas.pickles-in-pandas + origin: community + patterns: + - pattern-either: + - pattern: pandas.read_pickle(...) + - pattern: pandas.to_pickle(...) + - patterns: + - pattern-inside: | + import pandas + ... + - pattern: $SMTH.to_pickle(...) + - pattern-not: pandas.read_pickle("...") + - pattern-not: pandas.to_pickle(..., "...") + - pattern-not: $SMTH.to_pickle("...") +- id: trailofbits.python.pickles-in-pytorch.pickles-in-pytorch + message: Functions reliant on pickle can result in arbitrary code execution. Consider + loading from `state_dict`, using fickling, or switching to a safer serialization + method like ONNX + languages: + - python + severity: ERROR + metadata: + category: security + cwe: 'CWE-502: Deserialization of Untrusted Data' + subcategory: + - vuln + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + technology: + - pytorch + description: Potential arbitrary code execution from `PyTorch` functions reliant + on pickling + references: + - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ + license: AGPL-3.0 license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/trailofbits.python.pickles-in-pytorch.pickles-in-pytorch + shortlink: https://sg.run/NwQy + semgrep.dev: + rule: + r_id: 17171 + rv_id: 833304 + rule_id: JDU6WD + version_id: qkTQnJ3 + url: https://semgrep.dev/playground/r/qkTQnJ3/trailofbits.python.pickles-in-pytorch.pickles-in-pytorch + origin: community + patterns: + - pattern-either: + - pattern: torch.save(...) + - pattern: torch.load(...) + - pattern-not: torch.load("...") + - pattern-not: torch.save(..., "...") + - pattern-not: torch.save($M.state_dict(), ...) + - pattern-not-inside: $M.load_state_dict(...) + - pattern-not: + patterns: + - pattern: torch.save($STATE_DICT, ...) + - pattern-inside: | + $STATE_DICT = $M.state_dict() + ... +- id: trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable + message: Variable `$X` is likely modified and later used on error. In some cases + this could result in panics due to a nil dereference + languages: + - go + severity: WARNING + metadata: + category: security + cwe: 'CWE-665: Improper Initialization' + subcategory: + - audit + confidence: HIGH + likelihood: MEDIUM + impact: MEDIUM + technology: + - --no-technology-- + description: Possible unintentional assignment when an error occurs + references: + - https://blog.trailofbits.com/2019/11/07/attacking-go-vr-ttps/ + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable + shortlink: https://sg.run/WWQ2 + semgrep.dev: + rule: + r_id: 17197 + rv_id: 833265 + rule_id: kxU6Xb + version_id: zyTWJNZ + url: https://semgrep.dev/playground/r/zyTWJNZ/trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable + origin: community + patterns: + - pattern: | + ..., $X, ..., $ERR = ... + if $ERR != nil { + ... + <... $X.$Y ...> + } + - pattern-not: | + ..., $X, ..., $ERR = ... + if $ERR != nil { + ... + $X, ... = ... + ... + <... $X.$Y ...> + } + - pattern-not: | + ..., $X, ..., $ERR = ... + if $ERR != nil { + ... + $X = ... + ... + <... $X.$Y ...> + } + - pattern-not: | + ..., $X, ..., $ERR = ... + if $ERR != nil { + ... + if $X != nil { + <... $X.$Y ...> + } + ... + } + - pattern-not: | + ..., $X, ..., $ERR := ... + if $ERR != nil { + ... + if $X != nil && <... $X.$Y ...> { + ... + } + ... + } +- id: trailofbits.go.iterate-over-empty-map.iterate-over-empty-map + message: Iteration over a possibly empty map `$C`. This is likely a bug or redundant + code + languages: + - go + severity: WARNING + metadata: + category: security + cwe: 'CWE-665: Improper Initialization' + subcategory: + - audit + confidence: MEDIUM + likelihood: LOW + impact: LOW + technology: + - --no-technology-- + description: Probably redundant iteration over an empty map + references: + - https://blog.trailofbits.com/2019/11/07/attacking-go-vr-ttps/ + license: AGPL-3.0 license + vulnerability_class: + - Other + source: https://semgrep.dev/r/trailofbits.go.iterate-over-empty-map.iterate-over-empty-map + shortlink: https://sg.run/08jj + semgrep.dev: + rule: + r_id: 17198 + rv_id: 1039527 + rule_id: wdUlww + version_id: ExTNqnL + url: https://semgrep.dev/playground/r/ExTNqnL/trailofbits.go.iterate-over-empty-map.iterate-over-empty-map + origin: community + patterns: + - pattern: | + $C = make(map[$T1] $T2) + ... + for $K := range $C { ... } + - pattern-not: | + $C = make(map[$T1] $T2, ...) + ... + $C[$X] = $V + ... + for $K := range $C { ... } + - pattern-not: | + $C = make(map[$T1] $T2, ...) + ... + $C[$X]++ + ... + for $K := range $C { ... } + - pattern-not: | + $C = make(map[$T1] $T2, ...) + ... + $C[$X]-- + ... + for $K := range $C { ... } + - pattern-not: | + $C = make(map[$T1] $T2, ...) + ... + $CODEC.Unmarshal($BYTES, &$C) + ... + for $K := range $C { ... } +- id: csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug + message: ASP.NET applications built with `debug` set to true in production may leak + debug information to attackers. Debug mode also affects performance and reliability. + Set `debug` to `false` or remove it from `` + severity: WARNING + metadata: + likelihood: LOW + impact: LOW + confidence: LOW + category: security + cwe: + - 'CWE-11: ASP.NET Misconfiguration: Creating Debug Binary' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://web.archive.org/web/20190919105353/https://blogs.msdn.microsoft.com/prashant_upadhyay/2011/07/14/why-debugfalse-in-asp-net-applications-in-production-environment/ + - https://msdn.microsoft.com/en-us/library/e8z01xdh.aspx + subcategory: + - audit + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug + shortlink: https://sg.run/yPWx + semgrep.dev: + rule: + r_id: 17324 + rv_id: 1262620 + rule_id: 0oUrvj + version_id: jQTn53E + url: https://semgrep.dev/playground/r/jQTn53E/csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug + origin: community + languages: + - generic + paths: + include: + - '*web.config*' + patterns: + - pattern: | + + - pattern-inside: | + + ... + +- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::java.security + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + shortlink: https://sg.run/ryJn + semgrep.dev: + rule: + r_id: 17325 + rv_id: 1263013 + rule_id: KxU5lW + version_id: 0bTKzGX + url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + origin: community + patterns: + - pattern: | + java.security.MessageDigest.getInstance($ALGO, ...); + - metavariable-regex: + metavariable: $ALGO + regex: (?i)(.MD5.) + - focus-metavariable: $ALGO + fix: | + "SHA-512" +- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/bXNp + semgrep.dev: + rule: + r_id: 17326 + rv_id: 1263016 + rule_id: qNUWNn + version_id: l4TJRpL + url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + origin: community + pattern-either: + - patterns: + - pattern: | + java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: | + $DU.getSha1Digest().digest(...) +- id: java.lang.security.audit.crypto.weak-random.weak-random + message: Detected use of the functions `Math.random()` or `java.util.Random()`. + These are both not cryptographically strong random number generators (RNGs). If + you are using these RNGs to create passwords or secret tokens, use `java.security.SecureRandom` + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::randomness::java.security + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-random.weak-random + shortlink: https://sg.run/NwBp + semgrep.dev: + rule: + r_id: 17327 + rv_id: 1263018 + rule_id: lBUW5D + version_id: 6xT29RK + url: https://semgrep.dev/playground/r/6xT29RK/java.lang.security.audit.crypto.weak-random.weak-random + origin: community + pattern-either: + - pattern: | + new java.util.Random(...).$FUNC(...) + - pattern: | + java.lang.Math.random(...) +- id: php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate + patterns: + - pattern: openssl_decrypt(...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + if($DECRYPTED_STRING === false){ + ... + } + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + if($DECRYPTED_STRING == false){ + ... + } + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + if(false === $DECRYPTED_STRING){ + ... + } + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + if(false == $DECRYPTED_STRING){ + ... + } + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + assertTrue(false !== $DECRYPTED_STRING,...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + assertTrue($DECRYPTED_STRING !== false,...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + $REFERENCE::assertTrue(false !== $DECRYPTED_STRING,...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + $REFERENCE::assertTrue($DECRYPTED_STRING !== false,...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + assert(false !== $DECRYPTED_STRING,...); + - pattern-not-inside: | + $DECRYPTED_STRING = openssl_decrypt(...); + ... + assert($DECRYPTED_STRING !== false,...); + message: The function `openssl_decrypt` returns either a string of the decrypted + data on success or `false` on failure. If the failure case is not handled, this + could lead to undefined behavior in your application. Please handle the case where + `openssl_decrypt` returns `false`. + languages: + - php + severity: WARNING + metadata: + references: + - https://www.php.net/manual/en/function.openssl-decrypt.php + cwe: + - 'CWE-252: Unchecked Return Value' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + technology: + - php + - openssl + category: security + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate + shortlink: https://sg.run/kzn7 + semgrep.dev: + rule: + r_id: 17328 + rv_id: 1263274 + rule_id: YGUAoe + version_id: rxTAKXz + url: https://semgrep.dev/playground/r/rxTAKXz/php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate + origin: community +- id: scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run + patterns: + - pattern-either: + - pattern: $X.! + - pattern: $X.!! + - pattern: $X.lazyLines + - pattern-inside: | + import sys.process + ... + - pattern-not: | + "...".! + - pattern-not: | + "...".!! + - pattern-not: | + "...".lazyLines + - pattern-not: | + Seq(...).! + - pattern-not: | + Seq(...).!! + - pattern-not: | + Seq(...).lazyLines + - pattern-not-inside: | + val $X = "..." + ... + - pattern-not-inside: | + val $X = Seq(...) + ... + message: Found dynamic content used for the external process. This is dangerous + if arbitrary data can reach this function call because it allows a malicious actor + to execute commands. Use `Seq(...)` for dynamically generated commands. + languages: + - scala + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run + shortlink: https://sg.run/wZBY + semgrep.dev: + rule: + r_id: 17329 + rv_id: 1263679 + rule_id: 6JUEeo + version_id: bZT53y0 + url: https://semgrep.dev/playground/r/bZT53y0/scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run + origin: community +- id: terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted + patterns: + - pattern: | + resource "aws_athena_workgroup" $ANYTHING { + ... + configuration { + ... + result_configuration { + ... + } + ... + } + ... + } + - pattern-not-inside: | + resource "aws_athena_workgroup" $ANYTHING { + ... + configuration { + ... + result_configuration { + ... + encryption_configuration { + ... + } + ... + } + ... + } + ... + } + message: The AWS Athena Work Group is unencrypted. The AWS KMS encryption key protects + backups in the work group. To create your own, create a aws_kms_key resource or + use the ARN string of a key in your account. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted + shortlink: https://sg.run/gX7J + semgrep.dev: + rule: + r_id: 17341 + rv_id: 1263699 + rule_id: NbUXOA + version_id: JdTzx8e + url: https://semgrep.dev/playground/r/JdTzx8e/terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted + origin: community +- id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + patterns: + - pattern: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2018" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2019" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2021" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2025" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.3_2025" + ... + } + ... + } + message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS + versions less than 1.2 are considered insecure because they can be broken. To + fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019", + "TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + shortlink: https://sg.run/Q6o4 + semgrep.dev: + rule: + r_id: 17342 + rv_id: 1263700 + rule_id: kxU6A8 + version_id: 5PTo1bY + url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_cloudtrail" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_cloudtrail" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure CloudTrail logs are encrypted at rest using KMS CMKs. CMKs gives + you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk + shortlink: https://sg.run/38kr + semgrep.dev: + rule: + r_id: 17343 + rv_id: 946664 + rule_id: wdUl2j + version_id: A8TJzbz + url: https://semgrep.dev/playground/r/A8TJzbz/terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + patterns: + - pattern: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + retention_in_days = ... + ... + } + message: The AWS CloudWatch Log Group has no retention. Missing retention in log + groups can cause losing important event information. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + shortlink: https://sg.run/4lwl + semgrep.dev: + rule: + r_id: 17344 + rv_id: 946665 + rule_id: x8UGBG + version_id: BjT1N2B + url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + origin: community +- id: terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted + patterns: + - pattern: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: By default, AWS CloudWatch Log Group is encrypted using AWS-managed keys. + However, for added security, it's recommended to configure your own AWS KMS encryption + key to protect your log group in CloudWatch. You can either create a new aws_kms_key + resource or use the ARN of an existing key in your AWS account to do so. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + technology: + - aws + - terraform + category: security + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted + shortlink: https://sg.run/Pg6Y + semgrep.dev: + rule: + r_id: 17345 + rv_id: 1263701 + rule_id: OrUl0J + version_id: GxTkep4 + url: https://semgrep.dev/playground/r/GxTkep4/terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted + origin: community +- id: terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted + patterns: + - pattern: | + resource "aws_codebuild_project" $ANYTHING { + ... + artifacts { + ... + encryption_disabled = true + ... + } + ... + } + - pattern-not-inside: | + resource "aws_codebuild_project" $ANYTHING { + ... + artifacts { + type = "NO_ARTIFACTS" + encryption_disabled = true + } + ... + } + - pattern-not-inside: | + resource "aws_codebuild_project" $ANYTHING { + ... + artifacts { + type = "NO_ARTIFACTS" + } + ... + } + message: The AWS CodeBuild Project Artifacts are unencrypted. The AWS KMS encryption + key protects artifacts in the CodeBuild Projects. To create your own, create a + aws_kms_key resource or use the ARN string of a key in your account. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted + shortlink: https://sg.run/JeWw + semgrep.dev: + rule: + r_id: 17346 + rv_id: 946668 + rule_id: eqUrdZ + version_id: 0bT15Wr + url: https://semgrep.dev/playground/r/0bT15Wr/terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted + origin: community +- id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + patterns: + - pattern: | + resource "aws_codebuild_project" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_codebuild_project" $ANYTHING { + ... + encryption_key = ... + ... + } + message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects + projects in the CodeBuild. To create your own, create a aws_kms_key resource or + use the ARN string of a key in your account. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + shortlink: https://sg.run/5yxA + semgrep.dev: + rule: + r_id: 17347 + rv_id: 946669 + rule_id: v8U4kG + version_id: K3TJbNr + url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + origin: community +- id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + patterns: + - pattern: | + resource "aws_db_instance" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_db_instance" $ANYTHING { + ... + enabled_cloudwatch_logs_exports = [$SOMETHING, ...] + ... + } + message: Database instance has no logging. Missing logs can cause missing important + event information. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + shortlink: https://sg.run/GyAp + semgrep.dev: + rule: + r_id: 17348 + rv_id: 1263704 + rule_id: d8U4RA + version_id: BjTkZ6j + url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + origin: community +- id: terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_docdb_cluster" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_docdb_cluster" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure DocDB is encrypted at rest using KMS CMKs. CMKs gives you control + over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk + shortlink: https://sg.run/RyzO + semgrep.dev: + rule: + r_id: 17349 + rv_id: 946672 + rule_id: ZqUGEp + version_id: YDTvRX2 + url: https://semgrep.dev/playground/r/YDTvRX2/terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + patterns: + - pattern: | + resource "aws_dynamodb_table" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_dynamodb_table" $ANYTHING { + ... + server_side_encryption { + enabled = true + kms_key_arn = ... + } + ... + } + message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However, + for added security, it's recommended to configure your own AWS KMS encryption + key to protect your data in the DynamoDB table. You can either create a new aws_kms_key + resource or use the ARN of an existing key in your AWS account to do so. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + shortlink: https://sg.run/Ay4p + semgrep.dev: + rule: + r_id: 17350 + rv_id: 1263707 + rule_id: nJUGe2 + version_id: 0bTKzj8 + url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + origin: community +- id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_ebs_snapshot_copy" $ANYTHING { + ... + encrypted = true + ... + } + - pattern-not-inside: | + resource "aws_ebs_snapshot_copy" $ANYTHING { + ... + encrypted = true + kms_key_id = ... + ... + } + message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you + control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + shortlink: https://sg.run/ByPW + semgrep.dev: + rule: + r_id: 17351 + rv_id: 946677 + rule_id: EwUqko + version_id: A8TJzb0 + url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + patterns: + - pattern: | + resource "aws_ebs_encryption_by_default" $ANYTHING { + ... + enabled = false + ... + } + message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the + EBS. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + shortlink: https://sg.run/Dy5Y + semgrep.dev: + rule: + r_id: 17352 + rv_id: 946678 + rule_id: 7KUW7K + version_id: BjT1N2v + url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + origin: community +- id: terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_ebs_volume" $ANYTHING { + ... + encrypted = true + ... + } + - pattern-not-inside: | + resource "aws_ebs_volume" $ANYTHING { + ... + encrypted = true + kms_key_id = ... + ... + } + message: Ensure EBS Volume is encrypted at rest using KMS CMKs. CMKs gives you control + over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk + shortlink: https://sg.run/WW14 + semgrep.dev: + rule: + r_id: 17353 + rv_id: 946679 + rule_id: L1UPY9 + version_id: DkTNpzv + url: https://semgrep.dev/playground/r/DkTNpzv/terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + patterns: + - pattern-either: + - pattern: | + resource "aws_instance" $ANYTHING { + ... + associate_public_ip_address = true + ... + } + - pattern: | + resource "aws_launch_template" $ANYTHING { + ... + network_interfaces { + ... + associate_public_ip_address = true + ... + } + ... + } + message: EC2 instances should not have a public IP address attached in order to + block public access to the instances. To fix this, set your `associate_public_ip_address` + to `"false"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + shortlink: https://sg.run/08rv + semgrep.dev: + rule: + r_id: 17354 + rv_id: 1263709 + rule_id: 8GUA2n + version_id: qkTR73G + url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_efs_file_system" $ANYTHING { + ... + encrypted = true + ... + } + - pattern-not-inside: | + resource "aws_efs_file_system" $ANYTHING { + ... + encrypted = true + kms_key_id = ... + ... + } + message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you + control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + shortlink: https://sg.run/Kk07 + semgrep.dev: + rule: + r_id: 17355 + rv_id: 946690 + rule_id: gxUJ4n + version_id: 2KTYbWy + url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + patterns: + - pattern-either: + - pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + node_to_node_encryption { + ... + enabled = false + ... + } + ... + } + - pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + cluster_config { + ... + instance_count = $COUNT + ... + } + } + - pattern-not-inside: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + cluster_config { + ... + instance_count = $COUNT + ... + } + node_to_node_encryption { + ... + enabled = true + ... + } + } + - metavariable-comparison: + metavariable: $COUNT + comparison: $COUNT > 1 + message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t" + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + shortlink: https://sg.run/lp3y + semgrep.dev: + rule: + r_id: 17357 + rv_id: 1263719 + rule_id: 3qU6J7 + version_id: WrTqK0v + url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled + patterns: + - pattern-either: + - pattern: | + resource "aws_lb" $ANYTHING { + ... + } + - pattern: | + resource "aws_alb" $ANYTHING { + ... + } + - pattern-not-inside: | + resource $ANYLB $ANYTHING { + ... + access_logs { + ... + enabled = true + ... + } + ... + } + - pattern-not-inside: "resource $ANYLB $ANYTHING {\n ...\n subnet_mapping {\n + \ ...\n }\n ...\n} \n" + message: ELB has no logging. Missing logs can cause missing important event information. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled + shortlink: https://sg.run/Yrye + semgrep.dev: + rule: + r_id: 17358 + rv_id: 1263720 + rule_id: 4bUg3J + version_id: 0bTKzj4 + url: https://semgrep.dev/playground/r/0bTKzj4/terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled + origin: community +- id: terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk + patterns: + - pattern-inside: | + resource "aws_emr_security_configuration" $ANYTHING { + ... + } + - pattern: configuration = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + "AwsKmsKey": ... + message: Ensure EMR is encrypted at rest using KMS CMKs. CMKs gives you control + over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk + shortlink: https://sg.run/6gOo + semgrep.dev: + rule: + r_id: 17359 + rv_id: 946694 + rule_id: PeU0L7 + version_id: 9lTy1D0 + url: https://semgrep.dev/playground/r/9lTy1D0/terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_fsx_lustre_file_system" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_fsx_lustre_file_system" $ANYTHING { + ... + kms_key_id = ... + ... + } + - pattern-regex: (^aws_kms_key\.(.*)) + message: Ensure FSX Lustre file system is encrypted at rest using KMS CMKs. CMKs + gives you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk + shortlink: https://sg.run/oNG9 + semgrep.dev: + rule: + r_id: 17360 + rv_id: 1263721 + rule_id: JDU6gw + version_id: K3TKk1l + url: https://semgrep.dev/playground/r/K3TKk1l/terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_fsx_lustre_file_system" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_fsx_lustre_file_system" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure FSX Lustre file system is encrypted at rest using KMS CMKs. CMKs + gives you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk + shortlink: https://sg.run/zJ6G + semgrep.dev: + rule: + r_id: 17361 + rv_id: 1263722 + rule_id: 5rUp50 + version_id: qkTR73q + url: https://semgrep.dev/playground/r/qkTR73q/terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_fsx_ontap_file_system" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_fsx_ontap_file_system" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure FSX ONTAP file system is encrypted at rest using KMS CMKs. CMKs + gives you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk + shortlink: https://sg.run/pyRg + semgrep.dev: + rule: + r_id: 17362 + rv_id: 946697 + rule_id: GdUzwK + version_id: bZTXw0d + url: https://semgrep.dev/playground/r/bZTXw0d/terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_fsx_windows_file_system" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_fsx_windows_file_system" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure FSX Windows file system is encrypted at rest using KMS CMKs. CMKs + gives you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk + shortlink: https://sg.run/2pN0 + semgrep.dev: + rule: + r_id: 17363 + rv_id: 946698 + rule_id: ReUqv6 + version_id: NdTqknl + url: https://semgrep.dev/playground/r/NdTqknl/terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + patterns: + - pattern-inside: | + resource "aws_glacier_vault" $ANYTHING { + ... + } + - pattern: access_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-inside: | + {..., "Effect": "Allow", ...} + - pattern-either: + - pattern: | + "Principal": "*" + - pattern: | + "Principal": {..., "AWS": "*", ...} + - pattern-inside: | + "Principal": {..., "AWS": ..., ...} + - pattern-regex: | + (^\"arn:aws:iam::\*:(.*)\"$) + message: 'Detected wildcard access granted to Glacier Vault. This means anyone within + your AWS account ID can perform actions on Glacier resources. Instead, limit to + a specific identity in your account, like this: `arn:aws:iam:::`.' + metadata: + category: security + technology: + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + shortlink: https://sg.run/XN9K + semgrep.dev: + rule: + r_id: 17364 + rv_id: 1263723 + rule_id: AbUeYK + version_id: l4TJRGB + url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + patterns: + - pattern-inside: | + resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING { + ... + } + - pattern: inline_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} + - pattern: | + {..., "Action": "*", "Resource": "*", ...} + - pattern: | + {..., "Action": "*", "Resource": [...], ...} + - pattern: | + {..., "Action": [...], "Resource": "*", ...} + message: Detected admin access granted in your policy. This means anyone with this + policy can perform administrative actions. Instead, limit actions and resources + to what you need according to least privilege. + metadata: + category: security + technology: + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + shortlink: https://sg.run/jzgY + semgrep.dev: + rule: + r_id: 17365 + rv_id: 1263724 + rule_id: BYUzY5 + version_id: YDTZe9q + url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + patterns: + - pattern-inside: | + resource "aws_iam_policy" $ANYTHING { + ... + } + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} + - pattern: | + {..., "Action": "*", "Resource": "*", ...} + - pattern: | + {..., "Action": "*", "Resource": [...], ...} + - pattern: | + {..., "Action": [...], "Resource": "*", ...} + message: Detected admin access granted in your policy. This means anyone with this + policy can perform administrative actions. Instead, limit actions and resources + to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + shortlink: https://sg.run/1zbw + semgrep.dev: + rule: + r_id: 17366 + rv_id: 1263725 + rule_id: DbUx8l + version_id: 6xT29Pv + url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_imagebuilder_component" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_imagebuilder_component" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure ImageBuilder component is encrypted at rest using KMS CMKs. CMKs + gives you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk + shortlink: https://sg.run/9vdY + semgrep.dev: + rule: + r_id: 17367 + rv_id: 946702 + rule_id: WAUNxL + version_id: O9TX3o0 + url: https://semgrep.dev/playground/r/O9TX3o0/terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + patterns: + - pattern: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + parameter { + name = "require_ssl" + value = "true" + } + ... + } + - pattern-not-inside: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + parameter { + name = "require_ssl" + value = true + } + ... + } + message: Detected an AWS Redshift configuration with a SSL disabled. To fix this, + set your `require_ssl` to `"true"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + shortlink: https://sg.run/yPYx + semgrep.dev: + rule: + r_id: 17368 + rv_id: 1263727 + rule_id: 0oUrOj + version_id: zyTb27A + url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_kinesis_stream" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_kinesis_stream" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure Kinesis stream is encrypted at rest using KMS CMKs. CMKs gives you + control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk + shortlink: https://sg.run/ryBn + semgrep.dev: + rule: + r_id: 17369 + rv_id: 946705 + rule_id: KxU5yW + version_id: d6TPzwr + url: https://semgrep.dev/playground/r/d6TPzwr/terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_kinesis_video_stream" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_kinesis_video_stream" $ANYTHING { + ... + kms_key_id = ... + ... + } + message: Ensure Kinesis video stream is encrypted at rest using KMS CMKs. CMKs gives + you control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk + shortlink: https://sg.run/bXvp + semgrep.dev: + rule: + r_id: 17370 + rv_id: 946707 + rule_id: qNUWqn + version_id: nWTpYW8 + url: https://semgrep.dev/playground/r/nWTpYW8/terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + patterns: + - pattern-inside: | + resource "aws_kms_key" $ANYTHING { + ... + } + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...} + message: Detected wildcard access granted in your KMS key. This means anyone with + this policy can perform administrative actions over the keys. Instead, limit principals, + actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + shortlink: https://sg.run/Nwlp + semgrep.dev: + rule: + r_id: 17371 + rv_id: 1263729 + rule_id: lBUWPD + version_id: 2KTv2J4 + url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + patterns: + - pattern-either: + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + enable_key_rotation = false + ... + } + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + customer_master_key_spec = "SYMMETRIC_DEFAULT" + enable_key_rotation = false + ... + } + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_kms_key" $ANYTHING { + ... + enable_key_rotation = true + ... + } + - pattern-not-inside: | + resource "aws_kms_key" $ANYTHING { + ... + customer_master_key_spec = "RSA_2096" + ... + } + message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be + used by attackers. To fix this, set a `enable_key_rotation`. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + shortlink: https://sg.run/kz47 + semgrep.dev: + rule: + r_id: 17372 + rv_id: 1263730 + rule_id: PeU0L3 + version_id: X0Tzy67 + url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + origin: community +- id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials + patterns: + - pattern-inside: | + resource "$ANYTING" $ANYTHING { + ... + environment { + variables = { + ... + } + } + ... + } + - pattern-either: + - pattern-inside: | + AWS_ACCESS_KEY_ID = "$Y" + - pattern-regex: | + (? + - pattern-inside: | + + ... + +- id: csharp.dotnet.security.razor-template-injection.razor-template-injection + message: User-controllable string passed to Razor.Parse. This leads directly to + code execution in the context of the process. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + cwe2022-top25: true + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/ + subcategory: + - vuln + technology: + - .net + - razor + - asp + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection + shortlink: https://sg.run/oyj0 + semgrep.dev: + rule: + r_id: 18216 + rv_id: 1262621 + rule_id: EwUr68 + version_id: 1QTypdj + url: https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public ActionResult $METHOD(..., string $ARG,...){...} + pattern-sinks: + - pattern: | + Razor.Parse(...) + pattern-sanitizers: + - not_conflicting: true + pattern: $F(...) +- id: csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings + message: Cookie Secure flag is explicitly disabled. You should enforce this value + to avoid accidentally presenting sensitive cookie values over plaintext HTTP connections. + severity: WARNING + metadata: + likelihood: LOW + impact: LOW + confidence: LOW + category: security + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://docs.microsoft.com/en-us/aspnet/web-api/overview/advanced/http-cookies + - https://docs.microsoft.com/en-us/dotnet/api/system.web.security.formsauthentication.requiressl?redirectedfrom=MSDN&view=netframework-4.8#System_Web_Security_FormsAuthentication_RequireSSL + - https://docs.microsoft.com/en-us/dotnet/api/system.web.security.roles.cookierequiressl?redirectedfrom=MSDN&view=netframework-4.8#System_Web_Security_Roles_CookieRequireSSL + subcategory: + - audit + technology: + - .net + - asp + - webforms + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings + shortlink: https://sg.run/z1jd + semgrep.dev: + rule: + r_id: 18217 + rv_id: 1262626 + rule_id: 7KUxPg + version_id: NdTzyXg + url: https://semgrep.dev/playground/r/NdTzyXg/csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings + origin: community + languages: + - generic + paths: + include: + - '*web.config' + patterns: + - pattern-either: + - pattern: | + requireSSL="false" + - pattern: | + cookieRequireSSL="false" + - pattern-either: + - pattern-inside: | + + - pattern-inside: | + + - pattern-inside: | + +- id: csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + severity: WARNING + languages: + - csharp + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.issuernameregistry?view=netframework-4.8 + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + shortlink: https://sg.run/XZ6B + semgrep.dev: + rule: + r_id: 18220 + rv_id: 1262629 + rule_id: gxUy01 + version_id: xyTjzGW + url: https://semgrep.dev/playground/r/xyTjzGW/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + origin: community + message: Validating certificates based on subject name is bad practice. Use the + X509Certificate2.Verify() method instead. + patterns: + - pattern-inside: | + using System.IdentityModel.Tokens; + ... + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + X509SecurityToken $TOK = $RHS; + ... + - pattern-inside: | + $T $M(..., X509SecurityToken $TOK, ...) { + ... + } + - metavariable-pattern: + metavariable: $RHS + pattern-either: + - pattern: $T as X509SecurityToken + - pattern: new X509SecurityToken(...) + - patterns: + - pattern-either: + - pattern-inside: | + X509Certificate2 $CERT = new X509Certificate2(...); + ... + - pattern-inside: | + $T $M(..., X509Certificate2 $CERT, ...) { + ... + } + - pattern-inside: | + foreach (X509Certificate2 $CERT in $COLLECTION) { + ... + } + - patterns: + - pattern-either: + - pattern: String.Equals($NAME, "...") + - pattern: String.Equals("...", $NAME) + - pattern: $NAME.Equals("...") + - pattern: $NAME == "..." + - pattern: $NAME != "..." + - pattern: | + "..." == $NAME + - pattern: | + "..." != $NAME + - metavariable-pattern: + metavariable: $NAME + pattern-either: + - pattern: $TOK.Certificate.SubjectName.Name + - pattern: $CERT.SubjectName.Name + - pattern: $CERT.GetNameInfo(...) +- id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + mode: taint + pattern-sources: + - patterns: + - pattern: $A + - pattern-inside: | + Path.Combine(...,$A,...) + - pattern-inside: | + public $TYPE $M(...,$A,...){...} + - pattern-not-inside: | + <... Path.GetFileName($A) != $A ...> + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern: | + File.$METHOD($X,...) + - metavariable-regex: + metavariable: $METHOD + regex: (?i)^(read|write) + pattern-sanitizers: + - pattern: | + Path.GetFileName(...) + - patterns: + - pattern-inside: | + $X = Path.GetFileName(...); + ... + - pattern: $X + - patterns: + - pattern: $X + - pattern-inside: | + if(<... Path.GetFileName($X) != $X ...>){ + ... + throw new $EXCEPTION(...); + } + ... + message: String argument $A is used to read or write data from a file via Path.Combine + without direct sanitization via Path.GetFileName. If the path is user-supplied + data this can lead to path traversal. + languages: + - csharp + severity: WARNING + metadata: + category: security + confidence: MEDIUM + references: + - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ + - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks + technology: + - .net + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + shortlink: https://sg.run/1RvG + semgrep.dev: + rule: + r_id: 18222 + rv_id: 1262632 + rule_id: 3qU3bE + version_id: vdT0644 + url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + origin: community +- id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0 + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + shortlink: https://sg.run/9LJr + semgrep.dev: + rule: + r_id: 18223 + rv_id: 1262633 + rule_id: 4bUQ81 + version_id: d6Tyx4K + url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + origin: community + message: The top level wildcard bindings $PREFIX leaves your application open to + security vulnerabilities and give attackers more control over where traffic is + routed. If you must use wildcards, consider using subdomain wildcard binding. + For example, you can use "*.asdf.gov" if you own all of "asdf.gov". + patterns: + - pattern-inside: | + using System.Net; + ... + - pattern: $LISTENER.Prefixes.Add("$PREFIX") + - metavariable-regex: + metavariable: $PREFIX + regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+ +- id: csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver + shortlink: https://sg.run/yXjP + semgrep.dev: + rule: + r_id: 18224 + rv_id: 1262636 + rule_id: PeUxb0 + version_id: ExTExqN + url: https://semgrep.dev/playground/r/ExTExqN/csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver + origin: community + message: Only use DataContractResolver if you are completely sure of what information + is being serialized. Malicious types can cause unexpected behavior. + patterns: + - pattern: | + class $MYDCR : DataContractResolver { ... } +- id: csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.typefilterlevel?view=net-6.0 + - https://www.synacktiv.com/en/publications/izi-izi-pwn2own-ics-miami.html + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full + shortlink: https://sg.run/rere + semgrep.dev: + rule: + r_id: 18225 + rv_id: 1262639 + rule_id: JDUlKl + version_id: 8KT5rAN + url: https://semgrep.dev/playground/r/8KT5rAN/csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full + origin: community + message: Using a .NET remoting service can lead to RCE, even if you try to configure + TypeFilterLevel. Recommended to switch from .NET Remoting to WCF https://docs.microsoft.com/en-us/dotnet/framework/wcf/migrating-from-net-remoting-to-wcf + pattern-either: + - patterns: + - pattern-either: + - pattern: new BinaryServerFormatterSinkProvider { TypeFilterLevel = $LEVEL + } + - patterns: + - pattern-inside: | + $TYPE $SP = new BinaryServerFormatterSinkProvider(...); + ... + - pattern: | + $SP.TypeFilterLevel = $LEVEL + - metavariable-regex: + metavariable: $LEVEL + regex: (.*)TypeFilterLevel\.(Full|Low) + - patterns: + - pattern-inside: | + $DICT["typeFilterLevel"] = $VAL; + ... + - pattern: new BinaryServerFormatterSinkProvider(..., $DICT, ...) + - metavariable-regex: + metavariable: $VAL + regex: (\"Full\"|\"Low\") +- id: csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-125: Out-of-bounds Read' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.memorymarshal.createspan?view=net-6.0 + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.memorymarshal.createreadonlyspan?view=net-6.0 + category: security + technology: + - .net + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Memory Issues + source: https://semgrep.dev/r/csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span + shortlink: https://sg.run/b4eW + semgrep.dev: + rule: + r_id: 18226 + rv_id: 1262645 + rule_id: 5rUyEN + version_id: JdTzx62 + url: https://semgrep.dev/playground/r/JdTzx62/csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span + origin: community + message: MemoryMarshal.CreateSpan and MemoryMarshal.CreateReadOnlySpan should be + used with caution, as the length argument is not checked. + pattern-either: + - pattern: MemoryMarshal.CreateSpan(...) + - pattern: MemoryMarshal.CreateReadOnlySpan(...) +- id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + owasp: A01:2017 - Injection + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0 + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + shortlink: https://sg.run/NgRy + semgrep.dev: + rule: + r_id: 18227 + rv_id: 945224 + rule_id: GdUDBP + version_id: yeT0nDq + url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + origin: community + message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based + Denial of Service (DoS) attack. Consider setting the timeout to a short amount + of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double + check that your context meets the conditions outlined in the "Notes to Callers" + section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0' + patterns: + - pattern-inside: | + using System.Text.RegularExpressions; + ... + - pattern-either: + - pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout) + - patterns: + - pattern: new Regex(..., TimeSpan.FromSeconds($TIME)) + - metavariable-comparison: + metavariable: $TIME + comparison: $TIME > 5 + - pattern: new Regex(..., TimeSpan.FromMinutes(...)) + - pattern: new Regex(..., TimeSpan.FromHours(...)) +- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $XMLDOCUMENT.$METHOD(...) + - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver + = new XmlUrlResolver(...);\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + shortlink: https://sg.run/k98P + semgrep.dev: + rule: + r_id: 18228 + rv_id: 1262654 + rule_id: ReUK9k + version_id: K3TKk5E + url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + XmlReader $READER = XmlReader.Create(...,$RS,...); + - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing + = DtdProcessing.Parse;\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + shortlink: https://sg.run/wXjA + semgrep.dev: + rule: + r_id: 18229 + rv_id: 1262655 + rule_id: AbU3pX + version_id: qkTR7WD + url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $READER.$METHOD(...) + - pattern-not-inside: | + $READER.DtdProcessing = DtdProcessing.Prohibit; + ... + - pattern-inside: | + XmlTextReader $READER = new XmlTextReader(...); + ... + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + shortlink: https://sg.run/xXjL + semgrep.dev: + rule: + r_id: 18230 + rv_id: 1262656 + rule_id: BYUevk + version_id: l4TJRWG + url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + origin: community +- id: go.aws-lambda.security.database-sqli.database-sqli + languages: + - go + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' + calls. + mode: taint + metadata: + references: + - https://pkg.go.dev/database/sql#DB.Query + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - database + - sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli + shortlink: https://sg.run/e5e8 + semgrep.dev: + rule: + r_id: 18232 + rv_id: 1262909 + rule_id: WAUdJ7 + version_id: BjTkZkQ + url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.Exec($QUERY,...) + - pattern: $DB.ExecContent($QUERY,...) + - pattern: $DB.Query($QUERY,...) + - pattern: $DB.QueryContext($QUERY,...) + - pattern: $DB.QueryRow($QUERY,...) + - pattern: $DB.QueryRowContext($QUERY,...) + - pattern-inside: | + import "database/sql" + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + severity: WARNING +- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - go + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/vX3Y + semgrep.dev: + rule: + r_id: 18233 + rv_id: 1262910 + rule_id: 0oUwqg + version_id: DkTRbRL + url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "$SQLSTR" + ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + - pattern-not-inside: | + log.$PRINT(...) + pattern-sanitizers: + - pattern: strconv.Atoi(...) +- id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + message: '`Clean` is not intended to sanitize against path traversal attacks. This + function is for finding the shortest path name equivalent to the given input. + Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix + this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package + `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + severity: ERROR + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sanitizers: + - pattern-either: + - pattern: | + "/" + ... + fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + options: + interfile: true + metadata: + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - go + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + shortlink: https://sg.run/ZKzw + semgrep.dev: + rule: + r_id: 18235 + rv_id: 1262967 + rule_id: qNUQJe + version_id: jQTn5Bj + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + origin: community +- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + options: + interfile: true + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EBYN + semgrep.dev: + rule: + r_id: 18237 + rv_id: 1262977 + rule_id: YGUl4z + version_id: O9TpxQN + url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - pattern-not-inside: | + System.out.$PRINTLN(...) +- id: java.aws-lambda.security.tainted-sqli.tainted-sqli + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if variables in the SQL statement are not properly sanitized. + Use parameterized SQL queries or properly sanitize user input instead. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) + options: + interfile: true + metadata: + category: security + technology: + - sql + - java + - aws-lambda + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli + shortlink: https://sg.run/7942 + semgrep.dev: + rule: + r_id: 18238 + rv_id: 1262978 + rule_id: 6JUDWk + version_id: e1Tyj4g + url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli + origin: community +- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + message: Detected input from a HTTPServletRequest going into a SQL sink or statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use parameterized SQL queries or properly sanitize user input instead. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://owasp.org/www-community/attacks/SQL_Injection + subcategory: + - vuln + technology: + - sql + - java + - servlets + - spring + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/Lg56 + semgrep.dev: + rule: + r_id: 18239 + rv_id: 1409390 + rule_id: oqUBJG + version_id: 7ZTKJNj + url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + languages: + - java + mode: taint + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + ... + $OUTPUT = $STMT.$FUNC(...); + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - pattern: | + (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) +- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' + or 'exec' command. This could lead to command injection if variables passed into + the exec commands are not properly sanitized. Instead, avoid using these OS commands + with user-supplied input, or, if you must use these commands, use a whitelist + of specific values. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (ProcessBuilder $PB) = ...; + - patterns: + - pattern: | + (Process $P) = ...; + - pattern-not: | + (Process $P) = (java.lang.Runtime $R).exec(...); + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, ...); + - focus-metavariable: $CMD + - patterns: + - pattern-either: + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n...\n$PB.command($ARGLIST);\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process + $P) = ...;\n" + - pattern: | + $ARGLIST.add(...); + metadata: + category: security + technology: + - java + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + shortlink: https://sg.run/8zPN + semgrep.dev: + rule: + r_id: 18240 + rv_id: 1263042 + rule_id: zdUWrg + version_id: LjTkg9J + url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + origin: community +- id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + message: Detected input from a HTTPServletRequest going into an LDAP query. This + could lead to LDAP injection if the input is not properly sanitized, which could + result in attackers modifying objects in the LDAP tree structure. Ensure data + passed to an LDAP query is not controllable or properly sanitize the data. + metadata: + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection + category: security + technology: + - java + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + shortlink: https://sg.run/gRg0 + semgrep.dev: + rule: + r_id: 18241 + rv_id: 1409392 + rule_id: pKUXAv + version_id: 8KT3Pe6 + url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + origin: community + severity: WARNING + languages: + - java + mode: taint + pattern-sources: + - patterns: + - pattern: (HttpServletRequest $REQ) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (javax.naming.directory.InitialDirContext $IDC).search(...) + - pattern: | + (javax.naming.directory.DirContext $CTX).search(...) + - pattern-not: | + (javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...) + - pattern-not: | + (javax.naming.directory.DirContext $CTX).search($Y, "...", ...) +- id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + message: Detected input from a HTTPServletRequest going into a session command, + like `setAttribute`. User input into such a command could lead to an attacker + inputting malicious code into your session parameters, blurring the line between + what's trusted and untrusted, and therefore leading to a trust boundary violation. + This could lead to programmers trusting unvalidated data. Instead, thoroughly + sanitize user input before passing it into such function calls. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: | + (HttpServletRequest $REQ).$FUNC(...) + - pattern-not: | + (HttpServletRequest $REQ).getSession() + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... ); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + - patterns: + - pattern-inside: | + $HEADERS = (HttpServletRequest $REQ).getHeaders(...); + ... + $PARAM = $HEADERS.$FUNC(...); + ... + - pattern: | + java.net.URLDecoder.decode($PARAM, ...) + pattern-sinks: + - patterns: + - pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE); + - metavariable-regex: + metavariable: $FUNC + regex: ^(putValue|setAttribute)$ + - focus-metavariable: $VALUE + options: + interfile: true + metadata: + category: security + technology: + - java + cwe: + - 'CWE-501: Trust Boundary Violation' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + shortlink: https://sg.run/QbDZ + semgrep.dev: + rule: + r_id: 18242 + rv_id: 1409393 + rule_id: 2ZU7Eo + version_id: gETrv9j + url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + origin: community +- id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + message: Detected input from a HTTPServletRequest going into a XPath evaluate or + compile command. This could lead to xpath injection if variables passed into the + evaluate or compile commands are not properly sanitized. Xpath injection could + lead to unauthorized access to sensitive information in XML documents. Instead, + thoroughly sanitize user input or use parameterized xpath queries if you can. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: | + (HttpServletRequest $REQ).$FUNC(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (javax.xml.xpath.XPath $XP).evaluate(...) + - pattern: | + (javax.xml.xpath.XPath $XP).compile(...).evaluate(...) + metadata: + category: security + technology: + - java + cwe: + - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath + Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XPath Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + shortlink: https://sg.run/3BvK + semgrep.dev: + rule: + r_id: 18243 + rv_id: 1409394 + rule_id: X5U5nj + version_id: QkTERKP + url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + origin: community +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + shortlink: https://sg.run/4Dv5 + semgrep.dev: + rule: + r_id: 18244 + rv_id: 1263057 + rule_id: j2UrJ8 + version_id: 0bTKzgX + url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + origin: community + message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external + entity declarations, this is vulnerable to XML external entity attacks. Disable + this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + false); + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/PYBz + semgrep.dev: + rule: + r_id: 18245 + rv_id: 1263058 + rule_id: 10UPQB + version_id: K3TKk80 + url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This + is vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, + allow DOCTYPE declarations and only prohibit external entities declarations. This + can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = DocumentBuilderFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newDocumentBuilder(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newDocumentBuilder(); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + shortlink: https://sg.run/JgPy + semgrep.dev: + rule: + r_id: 18246 + rv_id: 1263059 + rule_id: 9AUJ6r + version_id: qkTR7Lk + url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + false); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + shortlink: https://sg.run/5Lv0 + semgrep.dev: + rule: + r_id: 18247 + rv_id: 1263060 + rule_id: yyUNeo + version_id: l4TJRoL + url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + false); + languages: + - java +- id: javascript.aws-lambda.security.detect-child-process.detect-child-process + message: Allowing spawning arbitrary programs or running shell processes with arbitrary + arguments may end up in a command injection vulnerability. Try to avoid non-literal + values for the command string. If it is not possible, then do not let running + arbitrary commands, use a white list for inputs. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process + shortlink: https://sg.run/Ggoq + semgrep.dev: + rule: + r_id: 18248 + rv_id: 1263105 + rule_id: r6UDNQ + version_id: YDTZe4o + url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: exec($CMD,...) + - pattern: execSync($CMD,...) + - pattern: spawn($CMD,...) + - pattern: spawnSync($CMD,...) + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-either: + - pattern-inside: | + require('child_process') + ... + - pattern-inside: | + import 'child_process' + ... +- id: javascript.aws-lambda.security.knex-sqli.knex-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from + table'', [userinput])`' + metadata: + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli + shortlink: https://sg.run/RgWq + semgrep.dev: + rule: + r_id: 18249 + rv_id: 1263106 + rule_id: bwUBlj + version_id: JdTzxKg + url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $KNEX.fromRaw($QUERY, ...) + - pattern: $KNEX.whereRaw($QUERY, ...) + - pattern: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... +- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://www.npmjs.com/package/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/A502 + semgrep.dev: + rule: + r_id: 18250 + rv_id: 1263107 + rule_id: NbUBJ2 + version_id: 5PTo1En + url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $POOL.query($QUERY, ...) + - pattern: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('mysql') + ... + - pattern-inside: | + require('mysql2') + ... + - pattern-inside: | + require('mysql2/promise') + ... + - pattern-inside: | + import 'mysql' + ... + - pattern-inside: | + import 'mysql2' + ... + - pattern-inside: | + import 'mysql2/promise' + ... +- id: javascript.aws-lambda.security.pg-sqli.pg-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://node-postgres.com/features/queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/BGKA + semgrep.dev: + rule: + r_id: 18251 + rv_id: 1263108 + rule_id: kxU25P + version_id: GxTkeJL + url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('pg') + ... + - pattern-inside: | + import 'pg' + ... +- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `sequelize.query(''SELECT + * FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT + });`' + metadata: + references: + - https://sequelize.org/master/manual/raw-queries.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequelize + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + shortlink: https://sg.run/DAlP + semgrep.dev: + rule: + r_id: 18252 + rv_id: 1263109 + rule_id: wdUA5o + version_id: RGT0LrD + url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('sequelize') + ... + - pattern-inside: | + import 'sequelize' + ... +- id: javascript.aws-lambda.security.tainted-eval.tainted-eval + message: The `eval()` function evaluates JavaScript code represented as a string. + Executing JavaScript from a string is an enormous security risk. It is far too + easy for a bad actor to run arbitrary code when you use `eval()`. Ensure evaluated + content is not definable by external sources. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - javascript + - aws-lambda + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-eval.tainted-eval + shortlink: https://sg.run/WjY2 + semgrep.dev: + rule: + r_id: 18253 + rv_id: 1263110 + rule_id: x8UNw5 + version_id: A8TgdLk + url: https://semgrep.dev/playground/r/A8TgdLk/javascript.aws-lambda.security.tainted-eval.tainted-eval + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $CODE + - pattern-either: + - pattern: eval($CODE) + - pattern: Function(...,$CODE) + - pattern: new Function(...,$CODE) +- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/0Gvj + semgrep.dev: + rule: + r_id: 18254 + rv_id: 1263111 + rule_id: OrUJBY + version_id: BjTkZ8D + url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $BODY + - pattern-inside: | + {..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... } +- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + message: The `vm` module enables compiling and running code within V8 Virtual Machine + contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted + code. If code passed to `vm` functions is controlled by user input it could result + in command injection. Do not let user input in `vm` functions. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + shortlink: https://sg.run/q9w7 + semgrep.dev: + rule: + r_id: 18256 + rv_id: 1263114 + rule_id: v8UOdZ + version_id: 0bTKz9J + url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('vm'); + ... + - pattern-inside: | + import 'vm' + ... + - pattern-either: + - pattern: $VM.runInContext($X,...) + - pattern: $VM.runInNewContext($X,...) + - pattern: $VM.runInThisContext($X,...) + - pattern: $VM.compileFunction($X,...) + - pattern: new $VM.Script($X,...) + - pattern: new $VM.SourceTextModule($X,...) + - pattern: runInContext($X,...) + - pattern: runInNewContext($X,...) + - pattern: runInThisContext($X,...) + - pattern: compileFunction($X,...) + - pattern: new Script($X,...) + - pattern: new SourceTextModule($X,...) +- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT + $1 from table'', [userinput])` can help prevent SQLi.' + metadata: + confidence: MEDIUM + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - express + - nodejs + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + shortlink: https://sg.run/l9eE + semgrep.dev: + rule: + r_id: 18257 + rv_id: 1263205 + rule_id: d8UKLD + version_id: l4TJRey + url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $KNEX.fromRaw($QUERY, ...) + - pattern-inside: $KNEX.whereRaw($QUERY, ...) + - pattern-inside: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) +- id: javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli + message: Detected a `$IMPORT` SQL statement that comes from a function argument. + This could lead to SQL injection if the variable is user-controlled and is not + properly sanitized. In order to prevent SQL injection, it is recommended to use + parameterized queries or prepared statements. + metadata: + references: + - https://www.npmjs.com/package/mysql2 + - https://www.npmjs.com/package/mysql + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + confidence: LOW + technology: + - mysql + - mysql2 + - javascript + - nodejs + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli + shortlink: https://sg.run/Y0oy + semgrep.dev: + rule: + r_id: 18258 + rv_id: 1263207 + rule_id: ZqUlWE + version_id: JdTzx2D + url: https://semgrep.dev/playground/r/JdTzx2D/javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: function ... (..., $Y,...) {...} + - pattern: $Y + - pattern-not-inside: | + function ... (..., $Y: number,...) {...} + - pattern-not-inside: $Y.query + - pattern-not-inside: $Y.body + - pattern-not-inside: $Y.params + - pattern-not-inside: $Y.cookies + - pattern-not-inside: $Y.headers + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $POOL.query($QUERY, ...) + - pattern-inside: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: | + import $S from "$IMPORT" + ... + - pattern-inside: | + import { ... } from "$IMPORT" + ... + - pattern-inside: | + import * as $S from "$IMPORT" + ... + - pattern-inside: | + require("$IMPORT") + ... + - metavariable-regex: + metavariable: $IMPORT + regex: (mysql|mysql2) + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) +- id: php.lang.security.deserialization.extract-user-data + mode: taint + pattern-sources: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_FILES[...] + - pattern: $_POST[...] + pattern-sinks: + - pattern: extract(...) + pattern-sanitizers: + - pattern: extract($VAR, EXTR_SKIP,...) + message: Do not call 'extract()' on user-controllable data. If you must, then you + must also provide the EXTR_SKIP flag to prevent overwriting existing variables. + languages: + - php + metadata: + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + technology: + - php + references: + - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data + shortlink: https://sg.run/6bv1 + semgrep.dev: + rule: + r_id: 18259 + rv_id: 1263278 + rule_id: nJUykq + version_id: w8TRovw + url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data + origin: community + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected 'create_subprocess_exec' function with argument tainted by `event` + object. If this data can be controlled by a malicious actor, it may be an instance + of command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + shortlink: https://sg.run/oyv0 + semgrep.dev: + rule: + r_id: 18260 + rv_id: 1263331 + rule_id: EwUrX8 + version_id: rxTAKgo + url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted + by `event` object. If this data can be controlled by a malicious actor, it may + be an instance of command injection. Audit the use of this call to ensure it is + not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + shortlink: https://sg.run/z14d + semgrep.dev: + rule: + r_id: 18261 + rv_id: 1263332 + rule_id: 7KUxXg + version_id: bZT53Ww + url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern: asyncio.create_subprocess_shell($CMD, ...) + message: Detected asyncio subprocess function with argument tainted by `event` object. + If this data can be controlled by a malicious actor, it may be an instance of + command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + shortlink: https://sg.run/p9vZ + semgrep.dev: + rule: + r_id: 18262 + rv_id: 1263333 + rule_id: L1UEl7 + version_id: NdTzyWA + url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Ensure no external data reaches here. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/2AjL + semgrep.dev: + rule: + r_id: 18263 + rv_id: 1263334 + rule_id: 8GUGBq + version_id: kbTzGv8 + url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - patterns: + - pattern: os.$METHOD($MODE, $CMD, ...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) +- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + message: Detected subprocess function with argument tainted by an `event` object. If + this data can be controlled by a malicious actor, it may be an instance of command + injection. The default option for `shell` is False, and this is secure by default. + Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` + means you have to split the command string into an array of strings for the command + and its arguments. You may consider using 'shlex.split()' for this purpose. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/XZ7B + semgrep.dev: + rule: + r_id: 18264 + rv_id: 1263335 + rule_id: gxUyn1 + version_id: w8TRogj + url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: subprocess.$FUNC(..., shell=True, ...) + pattern-sanitizers: + - pattern: shlex.split(...) + - pattern: pipes.quote(...) + - pattern: shlex.quote(...) +- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/jDvN + semgrep.dev: + rule: + r_id: 18265 + rv_id: 1263336 + rule_id: QrUkg6 + version_id: xyTjzbG + url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: os.system($CMD,...) + - pattern: os.popen($CMD,...) + - pattern: os.popen2($CMD,...) + - pattern: os.popen3($CMD,...) + - pattern: os.popen4($CMD,...) +- id: python.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/1RjG + semgrep.dev: + rule: + r_id: 18266 + rv_id: 1263337 + rule_id: 3qU3eE + version_id: O9TpxLJ + url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern-either: + - pattern-inside: | + import mysql + ... + - pattern-inside: | + import mysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://www.psycopg.org/docs/cursor.html#cursor.execute + - https://www.psycopg.org/docs/cursor.html#cursor.executemany + - https://www.psycopg.org/docs/cursor.html#cursor.mogrify + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - psycopg + - psycopg2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + shortlink: https://sg.run/9L8r + semgrep.dev: + rule: + r_id: 18267 + rv_id: 1263338 + rule_id: 4bUQG1 + version_id: e1TyjPZ + url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern: $CURSOR.mogrify($QUERY,...) + - pattern-inside: | + import psycopg2 + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://pypi.org/project/pymssql/ + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymssql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + shortlink: https://sg.run/yXvP + semgrep.dev: + rule: + r_id: 18268 + rv_id: 1263339 + rule_id: PeUxO0 + version_id: vdT06bG + url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import pymssql + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://pypi.org/project/PyMySQL/#id4 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + shortlink: https://sg.run/reve + semgrep.dev: + rule: + r_id: 18269 + rv_id: 1263340 + rule_id: JDUlel + version_id: d6TyxNA + url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-either: + - pattern-inside: | + import pymysql + ... + - pattern-inside: | + import pymysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = ?'', ''active'')`' + mode: taint + metadata: + references: + - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sqlalchemy + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + shortlink: https://sg.run/b48W + semgrep.dev: + rule: + r_id: 18270 + rv_id: 1263341 + rule_id: 5rUy3N + version_id: ZRTKARp + url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import sqlalchemy + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval($CODE, ...) + - pattern: exec($CODE, ...) + message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate + dynamic content. If this content can be input from outside the program, this may + be a code injection vulnerability. Ensure evaluated content is not definable by + external sources. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + shortlink: https://sg.run/Ng7y + semgrep.dev: + rule: + r_id: 18271 + rv_id: 1263342 + rule_id: GdUDJP + version_id: nWT2LD2 + url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + origin: community + languages: + - python + severity: WARNING +- id: python.aws-lambda.security.tainted-html-response.tainted-html-response + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: $BODY + - pattern-inside: | + {..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... } + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/k9vP + semgrep.dev: + rule: + r_id: 18272 + rv_id: 1263343 + rule_id: ReUKrk + version_id: ExTEx5o + url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - python + severity: WARNING +- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/wXvA + semgrep.dev: + rule: + r_id: 18273 + rv_id: 1263346 + rule_id: AbU3LX + version_id: 8KT5ron + url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= + - pattern-not-inside: | + print(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: ERROR +- id: python.django.security.nan-injection.nan-injection + message: Found user input going directly into typecast for bool(), float(), or complex(). + This allows an attacker to inject Python's not-a-number (NaN) into the typecast. + This results in undefind behavior, particularly when doing comparisons. Either + cast to a different type, or add a guard checking for all capitalizations of the + string 'nan'. + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: float(...) + - pattern: bool(...) + - pattern: complex(...) + - pattern-not-inside: | + if $COND: + ... + ... + pattern-sanitizers: + - pattern: $ANYTHING(...) + not_conflicting: true + metadata: + references: + - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 + - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ + category: security + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + technology: + - django + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.django.security.nan-injection.nan-injection + shortlink: https://sg.run/Og7L + semgrep.dev: + rule: + r_id: 18275 + rv_id: 946193 + rule_id: DbUGvk + version_id: NdTqk7G + url: https://semgrep.dev/playground/r/NdTqk7G/python.django.security.nan-injection.nan-injection + origin: community +- id: python.flask.security.injection.nan-injection.nan-injection + message: Found user input going directly into typecast for bool(), float(), or complex(). + This allows an attacker to inject Python's not-a-number (NaN) into the typecast. + This results in undefind behavior, particularly when doing comparisons. Either + cast to a different type, or add a guard checking for all capitalizations of the + string 'nan'. + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - pattern: flask.request.$SOMETHING.get(...) + - pattern: flask.request.$SOMETHING[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - pattern-either: + - pattern: float(...) + - pattern: bool(...) + - pattern: complex(...) + pattern-sanitizers: + - not_conflicting: true + pattern: $ANYTHING(...) + metadata: + references: + - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 + - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ + category: security + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + technology: + - flask + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.flask.security.injection.nan-injection.nan-injection + shortlink: https://sg.run/e598 + semgrep.dev: + rule: + r_id: 18276 + rv_id: 946222 + rule_id: WAUdj7 + version_id: qkT4j85 + url: https://semgrep.dev/playground/r/qkT4j85/python.flask.security.injection.nan-injection.nan-injection + origin: community +- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT + title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`' + mode: taint + metadata: + references: + - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - active-record + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + shortlink: https://sg.run/vXvY + semgrep.dev: + rule: + r_id: 18277 + rv_id: 1263581 + rule_id: 0oUw9g + version_id: w8TRor7 + url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: ActiveRecord::Base.connection.execute($QUERY,...) + - pattern: $MODEL.find_by_sql($QUERY,...) + - pattern: $MODEL.select_all($QUERY,...) + - pattern-inside: | + require 'active_record' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' + mode: taint + metadata: + references: + - https://github.com/brianmario/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + shortlink: https://sg.run/dJLE + semgrep.dev: + rule: + r_id: 18278 + rv_id: 1263582 + rule_id: KxUrQ3 + version_id: xyTjzOe + url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CLIENT.query($QUERY,...) + - pattern: $CLIENT.prepare($QUERY,...) + - pattern-inside: | + require 'mysql2' + ... + pattern-sanitizers: + - pattern: $CLIENT.escape(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.pg-sqli.pg-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `conn.exec_params(''SELECT + $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`' + mode: taint + metadata: + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/ZKww + semgrep.dev: + rule: + r_id: 18279 + rv_id: 1263583 + rule_id: qNUQee + version_id: O9Tpxz7 + url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CONN.exec($QUERY,...) + - pattern: $CONN.exec_params($QUERY,...) + - pattern: $CONN.exec_prepared($QUERY,...) + - pattern: $CONN.async_exec($QUERY,...) + - pattern: $CONN.async_exec_params($QUERY,...) + - pattern: $CONN.async_exec_prepared($QUERY,...) + - pattern-inside: | + require 'pg' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `DB[''select * from items + where name = ?'', name]`' + mode: taint + metadata: + references: + - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + shortlink: https://sg.run/n9vY + semgrep.dev: + rule: + r_id: 18280 + rv_id: 1263584 + rule_id: lBUy2N + version_id: e1Tyj5j + url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: DB[$QUERY,...] + - pattern: DB.run($QUERY,...) + - pattern-inside: | + require 'sequel' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EB7N + semgrep.dev: + rule: + r_id: 18281 + rv_id: 1263586 + rule_id: PeUxOE + version_id: d6Tyx1Z + url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "...#{...}..." + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", ...) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - pattern-not-inside: | + puts(...) +- id: scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run + patterns: + - pattern: Seq($CMD, ...) + - pattern-not: Seq("...", ...) + - pattern-inside: | + import sys.process + ... + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-either: + - pattern-inside: Seq(...).! + - pattern-inside: Seq(...).!! + - pattern-inside: Seq(...).lazyLines + message: Found dynamic content used for the external process. This is dangerous + if arbitrary data can reach this function call because it allows a malicious actor + to execute commands. Ensure your variables are not controlled by users or sufficiently + sanitized. + languages: + - scala + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run + shortlink: https://sg.run/79b2 + semgrep.dev: + rule: + r_id: 18282 + rv_id: 1263670 + rule_id: JDUle4 + version_id: zyTb2zJ + url: https://semgrep.dev/playground/r/zyTb2zJ/scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run + origin: community +- id: scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run + patterns: + - pattern: Seq($SH, "-c", $CMD, ...) + - pattern-not: Seq($SH, "-c", "...", ...) + - pattern-inside: | + import sys.process + ... + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-either: + - pattern-inside: Seq(...).! + - pattern-inside: Seq(...).!! + - pattern-inside: Seq(...).lazyLines + - metavariable-regex: + metavariable: $SH + regex: '"(sh|bash|ksh|csh|tcsh|zsh)"' + message: Found dynamic content used for the external process. This is dangerous + if arbitrary data can reach this function call because it allows a malicious actor + to execute commands. Ensure your variables are not controlled by users or sufficiently + sanitized. + languages: + - scala + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run + shortlink: https://sg.run/Lg76 + semgrep.dev: + rule: + r_id: 18283 + rv_id: 1263671 + rule_id: 5rUy3K + version_id: pZT03ED + url: https://semgrep.dev/playground/r/pZT03ED/scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run + origin: community +- id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + patterns: + - pattern: secure = false + - pattern-inside: | + session = { + ... + } + message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag + for cookies prevents the client from transmitting the cookie over insecure channels + such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration + file. + languages: + - generic + severity: WARNING + paths: + include: + - '*.conf' + metadata: + category: security + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security + - https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration + technology: + - play + - scala + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + shortlink: https://sg.run/8z8N + semgrep.dev: + rule: + r_id: 18284 + rv_id: 1263685 + rule_id: GdUDJO + version_id: e1TyjJv + url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + origin: community +- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli + mode: taint + metadata: + references: + - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values + - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - slick + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + shortlink: https://sg.run/k9K2 + semgrep.dev: + rule: + r_id: 18328 + rv_id: 1263687 + rule_id: GdUDWO + version_id: d6TyxJe + url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + origin: community + message: Detected a tainted SQL statement. This could lead to SQL injection if variables + in the SQL statement are not properly sanitized. Avoid using using user input + for generating SQL strings. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.overrideSql(...) + - pattern: sql"..." + - pattern-inside: | + import slick.$DEPS + ... + severity: ERROR + languages: + - scala +- id: scala.play.security.webservice-ssrf.webservice-ssrf + patterns: + - pattern: $WS.url($URL) + - pattern-either: + - pattern-inside: | + class $CLASS (..., $WS: WSClient, ...) { + ... + } + - pattern-inside: | + def $FUNC(..., $WS: WSClient, ...) = { + ... + } + - pattern-inside: | + $WS = AhcWSClient(...) + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `WSClient` most likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts hardcode the + correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://www.playframework.com/documentation/2.8.x/ScalaWS + category: security + technology: + - scala + - play + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.play.security.webservice-ssrf.webservice-ssrf + shortlink: https://sg.run/reRR + semgrep.dev: + rule: + r_id: 18369 + rv_id: 1263690 + rule_id: PeUxEE + version_id: ExTExz1 + url: https://semgrep.dev/playground/r/ExTExz1/scala.play.security.webservice-ssrf.webservice-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + patterns: + - pattern-inside: | + import ("github.com/gorilla/websocket") + ... + - patterns: + - pattern-not-inside: | + $UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...} + ... + - pattern-not-inside: | + $UPGRADER.CheckOrigin = $FN2 + ... + - pattern: | + $UPGRADER.Upgrade(...) + message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee + that the connection accepted by the WebSocket is from a trusted origin domain. + Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" + documentation: "A CheckOrigin function should carefully validate the request origin + to prevent cross-site request forgery."' + languages: + - go + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader + technology: + - gorilla + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + shortlink: https://sg.run/xXpz + semgrep.dev: + rule: + r_id: 18430 + rv_id: 1262914 + rule_id: ReUKdz + version_id: qkTR7RP + url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + origin: community +- id: scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf + patterns: + - pattern: Http($URL) + - pattern-inside: | + import scalaj.http.$HTTP + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `Http` can likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode + the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://github.com/scalaj/scalaj-http#simplified-http + category: security + technology: + - scala + - scalaj-http + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf + shortlink: https://sg.run/OgjB + semgrep.dev: + rule: + r_id: 18431 + rv_id: 1263680 + rule_id: AbU3xA + version_id: NdTzy7D + url: https://semgrep.dev/playground/r/NdTzy7D/scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/Lgqr + semgrep.dev: + rule: + r_id: 18483 + rv_id: 1263112 + rule_id: PeUxwW + version_id: DkTRbvp + url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR".concat(...) + - pattern: $UTIL.format($HTMLSTR, ...) + - pattern: format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...${...}...` + - pattern-regex: | + .*<\w+.* + - pattern-not-inside: | + console.$LOG(...) +- id: python.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/8zNy + semgrep.dev: + rule: + r_id: 18484 + rv_id: 1263344 + rule_id: JDUlwy + version_id: 7ZTE36K + url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - pattern-not-inside: | + print(...) +- id: scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf + patterns: + - pattern: url($URL) + - pattern-inside: | + import dispatch._ + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `url` most likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode + the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://dispatchhttp.org/Dispatch.html + category: security + technology: + - scala + - dispatch + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf + shortlink: https://sg.run/gR6J + semgrep.dev: + rule: + r_id: 18485 + rv_id: 1263672 + rule_id: 5rUyl4 + version_id: 2KTv282 + url: https://semgrep.dev/playground/r/2KTv282/scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf + patterns: + - pattern-either: + - pattern: Source.fromURL($URL,...) + - pattern: Source.fromURI($URL,...) + - pattern-inside: | + import scala.io.$SOURCE + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `fromURL` most likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode + the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource + category: security + technology: + - scala + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + shortlink: https://sg.run/Qbz4 + semgrep.dev: + rule: + r_id: 18486 + rv_id: 1263675 + rule_id: GdUDOZ + version_id: 1QTypG9 + url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: scala.lang.security.audit.scalac-debug.scalac-debug + patterns: + - pattern-either: + - pattern: scalacOptions ... "-Vdebug" + - pattern: scalacOptions ... "-Ydebug" + message: Scala applications built with `debug` set to true in production may leak + debug information to attackers. Debug mode also affects performance and reliability. + Remove it from configuration. + languages: + - generic + severity: WARNING + paths: + include: + - '*.sbt*' + metadata: + category: security + cwe: + - 'CWE-489: Active Debug Code' + owasp: A05:2021 - Security Misconfiguration + technology: + - scala + - sbt + references: + - https://docs.scala-lang.org/overviews/compiler-options/index.html + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug + shortlink: https://sg.run/QbGd + semgrep.dev: + rule: + r_id: 18686 + rv_id: 946569 + rule_id: JDUlE0 + version_id: qkT4j0N + url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug + origin: community +- id: scala.play.security.tainted-html-response.tainted-html-response + mode: taint + metadata: + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - play + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/BG96 + semgrep.dev: + rule: + r_id: 18795 + rv_id: 1263686 + rule_id: 0oUwn2 + version_id: vdT06yj + url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response + origin: community + message: Detected a request with potential user-input going into an `Ok()` response. + This bypasses any view or template environments, including HTML escaping, which + may expose this application to cross-site scripting (XSS) vulnerabilities. Consider + using a view technology such as Twirl which automatically escapes HTML views. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sanitizers: + - pattern-either: + - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) + - pattern: org.owasp.encoder.Encode.forHtml(...) + pattern-sinks: + - pattern-either: + - pattern: Html.apply(...) + - pattern: Ok(...).as(HTML) + - pattern: Ok(...).as(ContentTypes.HTML) + - patterns: + - pattern: Ok(...).as($CTYPE) + - metavariable-regex: + metavariable: $CTYPE + regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' + - patterns: + - pattern: Ok(...).as($CTYPE) + - pattern-not: Ok(...).as("...") + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + severity: WARNING + languages: + - scala +- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + patterns: + - pattern-either: + - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); + - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); + - metavariable-comparison: + metavariable: $M + comparison: re.match(".*-CBC",$M) + message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext + attacks against encrypted data. + languages: + - php + severity: ERROR + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + references: + - https://csrc.nist.gov/publications/detail/sp/800-38a/final + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + technology: + - php + - openssl + category: security + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + shortlink: https://sg.run/LgWJ + semgrep.dev: + rule: + r_id: 19039 + rv_id: 1263295 + rule_id: DbUGbE + version_id: JdTzxOD + url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + origin: community +- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + patterns: + - pattern-inside: | + import pdi.jwt.$DEPS + ... + - pattern-either: + - pattern: $JWT.encode($X, "...", ...) + - pattern: $JWT.decode($X, "...", ...) + - pattern: $JWT.decodeRawAll($X, "...", ...) + - pattern: $JWT.decodeRaw($X, "...", ...) + - pattern: $JWT.decodeAll($X, "...", ...) + - pattern: $JWT.validate($X, "...", ...) + - pattern: $JWT.isValid($X, "...", ...) + - pattern: $JWT.decodeJson($X, "...", ...) + - pattern: $JWT.decodeJsonAll($X, "...", ...) + - patterns: + - pattern-either: + - pattern: $JWT.encode($X, $KEY, ...) + - pattern: $JWT.decode($X, $KEY, ...) + - pattern: $JWT.decodeRawAll($X, $KEY, ...) + - pattern: $JWT.decodeRaw($X, $KEY, ...) + - pattern: $JWT.decodeAll($X, $KEY, ...) + - pattern: $JWT.validate($X, $KEY, ...) + - pattern: $JWT.isValid($X, $KEY, ...) + - pattern: $JWT.decodeJson($X, $KEY, ...) + - pattern: $JWT.decodeJsonAll($X, $KEY, ...) + - pattern: $JWT.encode($X, this.$KEY, ...) + - pattern: $JWT.decode($X, this.$KEY, ...) + - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) + - pattern: $JWT.decodeRaw($X, this.$KEY, ...) + - pattern: $JWT.decodeAll($X, this.$KEY, ...) + - pattern: $JWT.validate($X, this.$KEY, ...) + - pattern: $JWT.isValid($X, this.$KEY, ...) + - pattern: $JWT.decodeJson($X, this.$KEY, ...) + - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) + - pattern-either: + - pattern-inside: | + class $CL { + ... + $KEY = "..." + ... + } + - pattern-inside: | + object $CL { + ... + $KEY = "..." + ... + } + - metavariable-pattern: + metavariable: $JWT + patterns: + - pattern-either: + - pattern: Jwt + - pattern: JwtArgonaut + - pattern: JwtCirce + - pattern: JwtJson4s + - pattern: JwtJson + - pattern: JwtUpickle + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + languages: + - scala + severity: WARNING + metadata: + references: + - https://jwt-scala.github.io/jwt-scala/ + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - scala + confidence: HIGH + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + shortlink: https://sg.run/8zE7 + semgrep.dev: + rule: + r_id: 19040 + rv_id: 1263669 + rule_id: WAUdK0 + version_id: o5TbDA8 + url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + origin: community +- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + patterns: + - pattern-either: + - pattern: | + $DF = DocumentBuilderFactory.newInstance(...) + ... + $DB = $DF.newDocumentBuilder(...) + - patterns: + - pattern: $DB = DocumentBuilderFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $DB.newDocumentBuilder(...) + - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: Document Builder being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + shortlink: https://sg.run/gRQn + semgrep.dev: + rule: + r_id: 19041 + rv_id: 1263673 + rule_id: 0oUwzP + version_id: X0TzyRq + url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + origin: community +- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + patterns: + - pattern-either: + - pattern: $SR = new SAXReader(...) + - pattern: | + $SF = SAXParserFactory.newInstance(...) + ... + $SR = $SF.newSAXParser(...) + - patterns: + - pattern: $SR = SAXParserFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $SR.newSAXParser(...) + - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) + - pattern: $SR = new SAXBuilder(...) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: XML processor being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Parsers can result in XML Internal Entity Processing vulnerabilities like + the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + shortlink: https://sg.run/QbYP + semgrep.dev: + rule: + r_id: 19042 + rv_id: 1263678 + rule_id: KxUrkq + version_id: rxTAKWY + url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + origin: community +- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + patterns: + - pattern-not-inside: | + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) + - pattern-either: + - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) + - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) + - pattern: $XMLFACTORY = new XMLInputFactory(...) + message: XMLInputFactory being instantiated without calling the setProperty functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + shortlink: https://sg.run/3BEb + semgrep.dev: + rule: + r_id: 19043 + rv_id: 1263683 + rule_id: qNUQ7w + version_id: xyTjzkA + url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + origin: community +- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + domain_endpoint_options { + ... + enforce_https = true + tls_security_policy = "Policy-Min-TLS-1-0-2019-07" + ... + } + ... + } + message: Detected an AWS Elasticsearch domain using an insecure version of TLS. + To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07". + languages: + - terraform + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - aws + - terraform + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + shortlink: https://sg.run/PYlq + semgrep.dev: + rule: + r_id: 19045 + rv_id: 1263718 + rule_id: YGUle7 + version_id: DkTRbA5 + url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + origin: community +- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + message: User data from `$REQ` is being compiled into the template, which can lead + to a Server Side Template Injection (SSTI) vulnerability. + options: + interfile: true + metadata: + interfile: true + category: security + cwe: + - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + technology: + - javascript + - typescript + - express + - pug + - jade + - dot + - ejs + - nunjucks + - lodash + - handlbars + - mustache + - hogan.js + - eta + - squirrelly + source_rule_url: + - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + shortlink: https://sg.run/b49v + semgrep.dev: + rule: + r_id: 19226 + rv_id: 1263165 + rule_id: EwUr9k + version_id: zyTb2eD + url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-propagators: + - pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) + from: $E + to: $S + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('pug') + ... + - pattern-inside: | + import * as $PUG from 'pug' + ... + - pattern-inside: | + $PUG = require('jade') + ... + - pattern-inside: | + import * as $PUG from 'jade' + ... + - pattern-either: + - pattern: $PUG.compile(...) + - pattern: $PUG.compileClient(...) + - pattern: $PUG.compileClientWithDependenciesTracked(...) + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('dot') + ... + - pattern-inside: | + import * as $PUG from 'dot' + ... + - pattern-either: + - pattern: $PUG.template(...) + - pattern: $PUG.compile(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('ejs') + ... + - pattern-inside: | + import * as $PUG from 'ejs' + ... + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('nunjucks') + ... + - pattern-inside: | + import * as $PUG from 'nunjucks' + ... + - pattern-either: + - pattern: $PUG.renderString(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('lodash') + ... + - pattern-inside: | + import * as $PUG from 'lodash' + ... + - pattern-either: + - pattern: $PUG.template(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('mustache') + ... + - pattern-inside: | + import * as $PUG from 'mustache' + ... + - pattern-inside: | + $PUG = require('eta') + ... + - pattern-inside: | + import * as $PUG from 'eta' + ... + - pattern-inside: | + $PUG = require('squirrelly') + ... + - pattern-inside: | + import * as $PUG from 'squirrelly' + ... + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('hogan.js') + ... + - pattern-inside: | + import * as $PUG from 'hogan.js' + ... + - pattern-inside: | + $PUG = require('handlebars') + ... + - pattern-inside: | + import * as $PUG from 'handlebars' + ... + - pattern-either: + - pattern: $PUG.compile(...) +- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + mode: taint + pattern-sources: + - patterns: + - pattern: params[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + render ..., file: $X + - pattern: | + render ..., inline: $X + - pattern: | + render ..., template: $X + - pattern: | + render ..., action: $X + - pattern: | + render $X, ... + - focus-metavariable: $X + pattern-sanitizers: + - patterns: + - pattern: $MAP[...] + - metavariable-pattern: + metavariable: $MAP + patterns: + - pattern-not-regex: params + - pattern: File.basename(...) + message: Found request parameters in a call to `render`. This can allow end users + to request arbitrary local files which may result in leaking sensitive information + persisted on disk. Where possible, avoid letting users specify template paths + for `render`. If you must allow user input, use an allow-list of known templates + or normalize the user-supplied value with `File.basename(...)`. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + vulnerability_class: + - Path Traversal + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + shortlink: https://sg.run/Jw8Z + semgrep.dev: + rule: + r_id: 20046 + rv_id: 1409407 + rule_id: ReU2pZ + version_id: K3TgANN + url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + origin: community +- id: ruby.rails.security.brakeman.check-send-file.check-send-file + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: | + send_file ... + message: Allowing user input to `send_file` allows a malicious user to potentially + read arbitrary files from the server. Avoid accepting user input in `send_file` + or normalize with `File.basename(...)` + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb + category: security + cwe: + - 'CWE-73: External Control of File Name or Path' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/Path_Traversal + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file + shortlink: https://sg.run/GbY1 + semgrep.dev: + rule: + r_id: 20048 + rv_id: 1263660 + rule_id: BYUKbl + version_id: BjTkZRj + url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file + origin: community +- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/BeW9 + semgrep.dev: + rule: + r_id: 20051 + rv_id: 1263688 + rule_id: 0oUpon + version_id: ZRTKAoG + url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern: s"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) +- id: dockerfile.security.last-user-is-root.last-user-is-root + patterns: + - pattern: USER root + - pattern-not-inside: + patterns: + - pattern: | + USER root + ... + USER $X + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: root + message: The last user in the container is 'root'. This is a security hazard because + if an attacker gains control of the container they will have root access. Switch + back to another user after running commands as 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 + references: + - https://github.com/hadolint/hadolint/wiki/DL3002 + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root + shortlink: https://sg.run/5Z43 + semgrep.dev: + rule: + r_id: 20147 + rv_id: 1262658 + rule_id: ReU2n5 + version_id: 6xT29Eg + url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root + origin: community +- id: dockerfile.security.missing-user.missing-user + patterns: + - pattern: | + CMD $...VARS + - pattern-not-inside: | + USER $USER + ... + - pattern-not-inside: | + HEALTHCHECK ... CMD ... + fix: | + USER non-root + CMD $...VARS + message: By not specifying a USER, a program in the container may run as 'root'. + This is a security hazard. If an attacker can control a process running as root, + they may have control over the container. Ensure that the last USER in a Dockerfile + is a USER other than 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user + shortlink: https://sg.run/Gbvn + semgrep.dev: + rule: + r_id: 20148 + rv_id: 1262660 + rule_id: AbUN06 + version_id: zyTb2n2 + url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user + origin: community +- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends + selecting Argon2id unless you can guarantee an adversary has no direct access + to the computing environment. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + - https://eprint.iacr.org/2016/759.pdf + - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf + - https://datatracker.ietf.org/doc/html/rfc9106#section-4 + category: security + cwe: + - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' + technology: + - argon2 + - cryptography + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + impact: LOW + likelihood: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + shortlink: https://sg.run/ALq4 + semgrep.dev: + rule: + r_id: 20150 + rv_id: 1263103 + rule_id: DbU2X8 + version_id: qkTR7Jk + url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + $ARGON = require('argon2'); + ... + - pattern: | + {type: ...} + pattern-sinks: + - patterns: + - pattern: | + $Y + - pattern-inside: | + $ARGON.hash(...,$Y) + pattern-sanitizers: + - patterns: + - pattern: '{type: $ARGON.argon2id}' +- id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + - patterns: + - pattern: $Y + - pattern-either: + - pattern-inside: | + $RECORD.read_attribute($Y) + - pattern-inside: | + $RECORD[$Y] + - metavariable-regex: + metavariable: $RECORD + regex: '[A-Z][a-z]+' + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $Y + - pattern-inside: | + /...#{...}.../ + - patterns: + - pattern: $Y + - pattern-inside: | + Regexp.new(...) + message: Found a potentially user-controllable argument in the construction of a + regular expressions. This may result in excessive resource consumption when applied + to certain inputs, or when the user is allowed to control the match target. Avoid + allowing users to specify regular expressions processed by the server. If you + must support user-controllable input in a regular expression, use an allow-list + to restrict the expressions users may supply to limit catastrophic backtracking. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb + category: security + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + owasp: + - A03:2017 - Sensitive Data Exposure + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + shortlink: https://sg.run/qZwx + semgrep.dev: + rule: + r_id: 20156 + rv_id: 1409406 + rule_id: YGUY4R + version_id: 0bTG0WO + url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + origin: community +- id: ruby.rails.security.brakeman.check-sql.check-sql + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + :$KEY => $X + - pattern-inside: | + ["...",$X,...] + - pattern: | + params[...].to_i + - pattern: | + params[...].to_f + - patterns: + - pattern: | + params[...] ? $A : $B + - metavariable-pattern: + metavariable: $A + patterns: + - pattern-not: | + params[...] + - metavariable-pattern: + metavariable: $B + patterns: + - pattern-not: | + params[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-not-inside: | + $P.where("...",...) + - pattern-not-inside: | + $P.where(:$KEY => $VAL,...) + - pattern-either: + - pattern-inside: | + $P.$M(...) + - pattern-inside: | + $P.$M("...",...) + - pattern-inside: | + class $P < ActiveRecord::Base + ... + end + - metavariable-regex: + metavariable: $M + regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) + message: Found potential SQL injection due to unsafe SQL query construction via + $X. Where possible, prefer parameterized queries. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/SQL_Injection + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql + shortlink: https://sg.run/vpgb + semgrep.dev: + rule: + r_id: 20533 + rv_id: 1263661 + rule_id: OrUv2z + version_id: DkTRbE4 + url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql + origin: community +- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X. ... .to_proc + - patterns: + - pattern-inside: | + $Y.method($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap{ |$ANY| $Z } + - focus-metavariable: $Z + message: Found user-controllable input to a reflection method. This may allow a + user to alter program behavior and potentially execute arbitrary instructions + in the context of the process. Do not provide arbitrary user input to `tap`, `method`, + or `to_proc` + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + shortlink: https://sg.run/dPYd + semgrep.dev: + rule: + r_id: 20534 + rv_id: 1263662 + rule_id: eqUZ2Q + version_id: WrTqKLA + url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + origin: community +- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + message: Found the use of an hardcoded passphrase for RSA. The passphrase can be + easily discovered, and therefore should not be stored in source-code. It is recommended + to remove the passphrase from source-code, and use system environment variables + or a restricted configuration file. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - secrets + category: security + references: + - https://cwe.mitre.org/data/definitions/522.html + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + shortlink: https://sg.run/xPEe + semgrep.dev: + rule: + r_id: 20730 + rv_id: 1263607 + rule_id: bwULyN + version_id: K3TKkEo + url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') + - patterns: + - pattern-inside: | + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + - pattern-either: + - pattern: | + $OPENSSL.export(...,'...') + - pattern: | + $OPENSSL.to_pem(...,'...') + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + end + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + def $METHOD(...) + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + $ASSIGN = '...' + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) +- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended + to use a key length of 2048 or higher. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + category: security + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/O4Re + semgrep.dev: + rule: + r_id: 20731 + rv_id: 1263608 + rule_id: NbUe4N + version_id: qkTR76v + url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) + - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = $SIZE + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = $SIZE + ... + end + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 +- id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern: url_for(params[...],...,:only_path => false,...) + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $F(...) + - metavariable-pattern: + metavariable: $F + patterns: + - pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to) + - pattern: | + params.merge! :only_path => true + ... + - pattern: | + params.slice(...) + ... + - pattern: | + redirect_to [...] + - patterns: + - pattern: | + $MODEL. ... .$M(...) + ... + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\w+' + - metavariable-regex: + metavariable: $M + regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take) + - patterns: + - pattern: | + params.$UNSAFE_HASH.merge(...,:only_path => true,...) + ... + - metavariable-regex: + metavariable: $UNSAFE_HASH + regex: to_unsafe_h(ash)? + - patterns: + - pattern: params.permit(...,$X,...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not-regex: (host|port|(sub)?domain) + pattern-sinks: + - patterns: + - pattern: $X + - pattern-inside: | + redirect_to $X, ... + - pattern-not-regex: params\.\w+(? true` hash value. + languages: + - ruby + severity: WARNING + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb + category: security + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + technology: + - ruby + - rails + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + shortlink: https://sg.run/eJNX + semgrep.dev: + rule: + r_id: 20732 + rv_id: 1263657 + rule_id: kxUOJ6 + version_id: GxTke14 + url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + origin: community +- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X.constantize + - pattern-inside: | + $X. ... .safe_constantize + - pattern-inside: | + const_get(...) + - pattern-inside: | + qualified_const_get(...) + message: Found user-controllable input to Ruby reflection functionality. This allows + a remote user to influence runtime behavior, up to and including arbitrary remote + code execution. Do not provide user-controllable input to reflection functionality. + Do not call symbol conversion on user-controllable input. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + shortlink: https://sg.run/vpEX + semgrep.dev: + rule: + r_id: 20733 + rv_id: 1263663 + rule_id: wdUkYA + version_id: 0bTKzn8 + url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + origin: community +- id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.find(...) + - pattern: $MODEL.find_by_id(...) + - pattern: $MODEL.find_by_id!(...) + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\S+' + message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord + model being searched against is sensitive, this may lead to Insecure Direct Object + Reference (IDOR) behavior and allow users to read arbitrary records. Scope the + find to the current user, e.g. `current_user.accounts.find(params[:id])`. + languages: + - ruby + severity: WARNING + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb + category: security + cwe: + - 'CWE-639: Authorization Bypass Through User-Controlled Key' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - ruby + - rails + references: + - https://brakemanscanner.org/docs/warning_types/unscoped_find/ + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + shortlink: https://sg.run/dPbP + semgrep.dev: + rule: + r_id: 20734 + rv_id: 1263664 + rule_id: x8Ud6d + version_id: K3TKkxZ + url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + origin: community +- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + message: Detected DynamoDB query params that are tainted by `$EVENT` object. This + could lead to NoSQL injection if the variable is user-controlled and not properly + sanitized. Explicitly assign query params instead of passing data from `$EVENT` + directly to DynamoDB client. + metadata: + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + owasp: + - A01:2017 - Injection + category: security + technology: + - javascript + - aws-lambda + - dynamodb + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + shortlink: https://sg.run/X1e4 + semgrep.dev: + rule: + r_id: 21320 + rv_id: 945766 + rule_id: 0oU1xk + version_id: GxTP7gN + url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern: | + $DC.$METHOD($SINK, ...) + - metavariable-regex: + metavariable: $METHOD + regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) + - pattern-either: + - pattern-inside: | + $DC = new $AWS.DocumentClient(...); + ... + - pattern-inside: | + $DC = new $AWS.DynamoDB(...); + ... + - pattern-inside: | + $DC = new DynamoDBClient(...); + ... + - pattern-inside: | + $DC = DynamoDBDocumentClient.from(...); + ... + pattern-sanitizers: + - patterns: + - pattern: | + {...} +- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + mode: taint + metadata: + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + owasp: + - A01:2017 - Injection + category: security + technology: + - python + - boto3 + - aws-lambda + - dynamodb + references: + - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + shortlink: https://sg.run/jjrl + semgrep.dev: + rule: + r_id: 21321 + rv_id: 946088 + rule_id: KxUJ2B + version_id: 9lTy1rQ + url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + origin: community + message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This + could lead to NoSQL injection if the variable is user-controlled and not properly + sanitized. Explicitly assign query params instead of passing data from `$EVENT` + directly to DynamoDB client. + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sanitizers: + - patterns: + - pattern: | + {...} + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) + - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) + - pattern-either: + - patterns: + - pattern-inside: | + $TABLE = $DB.Table(...) + ... + - pattern-inside: | + $DB = boto3.resource('dynamodb', ...) + ... + - pattern-inside: | + $TABLE = boto3.client('dynamodb', ...) + ... + severity: ERROR + languages: + - python +- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + message: Detected data rendered directly to the end user via 'Response'. This bypasses + Pyramid's built-in cross-site scripting (XSS) defenses and could result in an + XSS vulnerability. Use Pyramid's template engines to safely render HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + shortlink: https://sg.run/DX8G + semgrep.dev: + rule: + r_id: 21452 + rv_id: 1263572 + rule_id: gxUeA8 + version_id: X0TzyEe + url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + origin: community + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + pyramid.request.Response.text($SINK) + - pattern: | + pyramid.request.Response($SINK) + - pattern: | + $REQ.response.body = $SINK + - pattern: | + $REQ.response.text = $SINK + - pattern: | + $REQ.response.ubody = $SINK + - pattern: | + $REQ.response.unicode_body = $SINK + - pattern: $SINK +- id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause + sql injections if the developer inputs raw SQL into the before-mentioned clauses. + This pattern captures relevant cases in which the developer inputs raw SQL into + the distinct, having, group_by, order_by or filter clauses and injects user-input + into the raw SQL with any function besides "bindparams". Use bindParams to securely + bind user-input to SQL statements. + languages: + - python + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data + technology: + - pyramid + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + shortlink: https://sg.run/W7eE + semgrep.dev: + rule: + r_id: 21453 + rv_id: 1263573 + rule_id: QrUZ7l + version_id: jQTn5WA + url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + from pyramid.view import view_config + ... + @view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-inside: | + $QUERY = $REQ.dbsession.query(...) + ... + - pattern-either: + - pattern: | + $QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: | + $QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: $SINK + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + fix-regex: + regex: format + replacement: bindparams +- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + message: Use of angular.element can lead to XSS if user-input is treated as part + of the HTML element within `$SINK`. It is recommended to contextually output encode + user-input, before inserting into `$SINK`. If the HTML needs to be preserved it + is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + confidence: MEDIUM + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angularjs + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + shortlink: https://sg.run/5AQ0 + semgrep.dev: + rule: + r_id: 21503 + rv_id: 1263091 + rule_id: GdUP71 + version_id: 44TEj8L + url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: window.location.search + - pattern: window.document.location.search + - pattern: document.location.search + - pattern: location.search + - pattern: $location.search(...) + - patterns: + - pattern-either: + - pattern: $DECODE(<... location.hash ...>) + - pattern: $DECODE(<... window.location.hash ...>) + - pattern: $DECODE(<... document.location.hash ...>) + - pattern: $DECODE(<... location.href ...>) + - pattern: $DECODE(<... window.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.URL ...>) + - pattern: $DECODE(<... window.document.URL ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... $location.absUrl() ...>) + - pattern: $DECODE(<... $location.url() ...>) + - pattern: $DECODE(<... $location.hash() ...>) + - metavariable-regex: + metavariable: $DECODE + regex: ^(unescape|decodeURI|decodeURIComponent)$ + - patterns: + - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|delete|head|jsonp|post|put|patch) + - pattern: $RES.data + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + angular.element(...). ... .$SINK($QUERY) + - pattern-inside: | + $ANGULAR = angular.element(...) + ... + $ANGULAR. ... .$SINK($QUERY) + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) +- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: pickle.load($SINK,...) + - pattern: pickle.loads($SINK,...) + - pattern: _pickle.load($SINK,...) + - pattern: _pickle.loads($SINK,...) + - pattern: cPickle.load($SINK,...) + - pattern: cPickle.loads($SINK,...) + - pattern: dill.load($SINK,...) + - pattern: dill.loads($SINK,...) + - pattern: shelve.open($SINK,...) + message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. + When unpickling, the serialized data could be manipulated to run arbitrary code. + Instead, consider serializing the relevant data as JSON or a similar text-based + serialization format. + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + shortlink: https://sg.run/JbjW + semgrep.dev: + rule: + r_id: 21602 + rv_id: 1263345 + rule_id: JDUDQg + version_id: LjTkgd9 + url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + origin: community + languages: + - python + severity: WARNING +- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...}) + pattern-sanitizers: + - patterns: + - pattern: | + DB::raw("...",[...]) + pattern-sinks: + - patterns: + - pattern: | + DB::raw(...) + message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL + injection via string concatenation or unsafe interpolation. + languages: + - php + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md + technology: + - php + - laravel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + shortlink: https://sg.run/x94g + semgrep.dev: + rule: + r_id: 21674 + rv_id: 1263305 + rule_id: zdUln0 + version_id: qkTR7A9 + url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + origin: community +- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + mode: taint + pattern-sources: + - patterns: + - pattern: | + public function $F(...,Request $R,...){...} + - focus-metavariable: $R + - patterns: + - pattern-either: + - pattern: | + $this->$PROPERTY + - pattern: | + $this->$PROPERTY->$GET + - metavariable-pattern: + metavariable: $PROPERTY + patterns: + - pattern-either: + - pattern: query + - pattern: request + - pattern: headers + - pattern: cookies + - pattern: cookie + - pattern: files + - pattern: file + - pattern: allFiles + - pattern: input + - pattern: all + - pattern: post + - pattern: json + - pattern-either: + - pattern-inside: | + class $CL extends Illuminate\Http\Request {...} + - pattern-inside: | + class $CL extends Illuminate\Foundation\Http\FormRequest {...} + pattern-sinks: + - patterns: + - pattern: | + Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...) + - focus-metavariable: $IGNORE + message: Found a request argument passed to an `ignore()` definition in a Rule constraint. + This can lead to SQL injection. + languages: + - php + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - php + - laravel + references: + - https://laravel.com/docs/9.x/validation#rule-unique + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + shortlink: https://sg.run/vkeb + semgrep.dev: + rule: + r_id: 21677 + rv_id: 1263314 + rule_id: X5ULgE + version_id: DkTRbBl + url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + origin: community +- id: java.spring.security.injection.tainted-file-path.tainted-file-path + languages: + - java + severity: ERROR + message: Detected user input controlling a file path. An attacker could control + the location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + options: + interfile: true + metadata: + cwe: + - 'CWE-23: Relative Path Traversal' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - java + - spring + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path + shortlink: https://sg.run/x9o0 + semgrep.dev: + rule: + r_id: 22074 + rv_id: 1263084 + rule_id: lBUxok + version_id: ExTEx6Y + url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new File(...) + - pattern: new java.io.File(...) + - pattern: new FileReader(...) + - pattern: new java.io.FileReader(...) + - pattern: new FileInputStream(...) + - pattern: new java.io.FileInputStream(...) + - pattern: (Paths $PATHS).get(...) + - patterns: + - pattern: | + $CLASS.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(getResourceAsStream|getResource)$ + - patterns: + - pattern-either: + - pattern: new ClassPathResource($FILE, ...) + - pattern: ResourceUtils.getFile($FILE, ...) + - pattern: new FileOutputStream($FILE, ...) + - pattern: new java.io.FileOutputStream($FILE, ...) + - pattern: new StreamSource($FILE, ...) + - pattern: new javax.xml.transform.StreamSource($FILE, ...) + - pattern: FileUtils.openOutputStream($FILE, ...) + - focus-metavariable: $FILE + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) +- id: java.spring.security.injection.tainted-html-string.tainted-html-string + languages: + - java + severity: ERROR + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. You can use the OWASP ESAPI encoder if you must render user + data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string + shortlink: https://sg.run/ObdR + semgrep.dev: + rule: + r_id: 22075 + rv_id: 1409395 + rule_id: YGUvkL + version_id: 3ZT2598 + url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + - label: CONCAT + by-side-effect: true + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + ... + - pattern: | + "$HTMLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$HTMLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$HTMLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$HTMLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$HTMLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $HTMLSTR + regex: ^<\w+ + pattern-propagators: + - pattern: (StringBuilder $SB).append($...TAINTED) + from: $...TAINTED + to: $SB + - pattern: $VAR += $...TAINTED + from: $...TAINTED + to: $VAR + pattern-sinks: + - requires: CONCAT + patterns: + - pattern-either: + - pattern: new ResponseEntity<>($PAYLOAD, ...) + - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) + - pattern: ResponseEntity. ... .body($PAYLOAD) + - patterns: + - pattern: | + ResponseEntity.$RESPFUNC($PAYLOAD). ... + - metavariable-regex: + metavariable: $RESPFUNC + regex: ^(ok|of)$ + - focus-metavariable: $PAYLOAD + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) +- id: java.spring.security.injection.tainted-system-command.tainted-system-command + languages: + - java + severity: ERROR + mode: taint + pattern-propagators: + - pattern: (StringBuilder $STRB).append($INPUT) + from: $INPUT + to: $STRB + label: CONCAT + requires: INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $SOURCE + - pattern: $SOURCE + $Y + - pattern: String.format("...", ..., $SOURCE, ...) + - pattern: String.join("...", ..., $SOURCE, ...) + - pattern: (String $STR).concat($SOURCE) + - pattern: $SOURCE.concat(...) + - pattern: $X += $SOURCE + - pattern: $SOURCE += $X + label: CONCAT + requires: INPUT + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (Process $P) = new Process(...); + - pattern: | + (ProcessBuilder $PB).command(...); + - patterns: + - pattern-either: + - pattern: | + (Runtime $R).$EXEC(...); + - pattern: | + Runtime.getRuntime(...).$EXEC(...); + - metavariable-regex: + metavariable: $EXEC + regex: (exec|loadLibrary|load) + - patterns: + - pattern: | + (ProcessBuilder $PB).command(...).$ADD(...); + - metavariable-regex: + metavariable: $ADD + regex: (add|addAll) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $BUILDER = new ProcessBuilder(...); + ... + - pattern: $BUILDER.start(...) + - pattern: | + new ProcessBuilder(...). ... .start(...); + requires: CONCAT + message: 'Detected user input entering a method which executes a system command. + This could result in a command injection vulnerability, which allows an attacker + to inject an arbitrary system command onto the server. The attacker could download + malware onto or steal data from the server. Instead, use ProcessBuilder, separating + the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", + targetDirectory)`. Further, make sure you hardcode or allowlist the actual command + so that attackers can''t run arbitrary commands.' + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - java + - spring + confidence: HIGH + references: + - https://www.stackhawk.com/blog/command-injection-java/ + - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html + - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command + shortlink: https://sg.run/epY0 + semgrep.dev: + rule: + r_id: 22076 + rv_id: 1263087 + rule_id: 6JUxGN + version_id: 8KT5rnP + url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command + origin: community +- id: java.spring.security.injection.tainted-url-host.tainted-url-host + languages: + - java + severity: ERROR + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode + the correct host, or ensure that the user data can only affect the path or parameters. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/vkYn + semgrep.dev: + rule: + r_id: 22077 + rv_id: 1263088 + rule_id: oqUZo8 + version_id: gETB708 + url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - pattern-either: + - pattern: new URL($ONEARG) + - patterns: + - pattern-either: + - pattern: | + "$URLSTR" + ... + - pattern: | + "$URLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$URLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$URLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern: String.format("$URLSTR", ...) + - pattern-not: String.format("$URLSTR", "...", ...) + - patterns: + - pattern-inside: | + String $VAR = "$URLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: http(s?)://%(v|s|q).* +- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + mode: taint + languages: + - ruby + message: Deserialization of a string tainted by `event` object found. Objects in + Ruby can be serialized into strings, then later loaded from strings. However, + uses of `load` can cause remote code execution. Loading user input with MARSHAL, + YAML or CSV can potentially be dangerous. If you need to deserialize untrusted + data, you should use JSON as it is only capable of returning 'primitive' types + such as strings, arrays, hashes, numbers and nil. + metadata: + references: + - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + category: security + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + technology: + - ruby + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + shortlink: https://sg.run/dplX + semgrep.dev: + rule: + r_id: 22078 + rv_id: 1263585 + rule_id: zdUlNJ + version_id: vdT06gR + url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + origin: community + pattern-sinks: + - patterns: + - pattern: $SINK + - pattern-either: + - pattern-inside: | + YAML.load($SINK,...) + - pattern-inside: | + CSV.load($SINK,...) + - pattern-inside: | + Marshal.load($SINK,...) + - pattern-inside: | + Marshal.restore($SINK,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + message: The libxml library processes user-input with the `noent` attribute is set + to `true` which can lead to being vulnerable to XML External Entities (XXE) type + attacks. It is recommended to set `noent` to `false` when using this feature to + ensure you are protected. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + shortlink: https://sg.run/Z75x + semgrep.dev: + rule: + r_id: 22079 + rv_id: 1263138 + rule_id: pKUNeD + version_id: d6TyxpX + url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('$IMPORT') + ... + - pattern-inside: | + import $XML from '$IMPORT' + ... + - pattern-inside: | + import * as $XML from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent + message: Detected use of parseXml() function with the `noent` field set to `true`. + This can lead to an XML External Entities (XXE) attack if untrusted data is passed + into it. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent + shortlink: https://sg.run/n8Ag + semgrep.dev: + rule: + r_id: 22080 + rv_id: 1263139 + rule_id: 2ZUY52 + version_id: ZRTKAXb + url: https://semgrep.dev/playground/r/ZRTKAXb/javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $VM.runInContext("$CMD", ...) + - pattern: $VM.runInNewContext("$CMD", ...) + - pattern: $VM.runInThisContext("$CMD", ...) + - pattern: $VM.compileFunction("$CMD", ...) + - metavariable-pattern: + metavariable: $CMD + language: typescript + pattern-either: + - pattern: | + $LIBXML.parseXml($DATA, {..., noent: true, ...}, ...) + - patterns: + - pattern-inside: | + $OPTS = {..., noent: true, ...} + ... + - pattern: $LIBXML.parseXml( $DATA, $OPTS ) + - pattern: | + $LIBXML.parseXml($DATA, {..., noent: true, ...}, ...) + - patterns: + - pattern-inside: | + $OPTS = {..., noent: true, ...} + ... + - pattern: $LIBXML.parseXml( $DATA, $OPTS ) +- id: javascript.express.security.audit.express-open-redirect.express-open-redirect + message: The application redirects to a URL specified by user-supplied input `$REQ` + that is not validated. This could redirect users to malicious locations. Consider + using an allow-list approach to validate URLs, or warn users they are being redirected + to a third-party website. + metadata: + technology: + - express + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect + shortlink: https://sg.run/EpoP + semgrep.dev: + rule: + r_id: 22081 + rv_id: 1263140 + rule_id: X5ULkq + version_id: nWT2L0v + url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + options: + taint_unify_mvars: true + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $HTTP + regex: ^https?:\/\/$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ. ... .$VALUE) + - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ.$VALUE['...']) + - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) + - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) + - pattern: $REQ.$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ.$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" + - pattern-either: + - pattern: $RES.redirect($ASSIGN) + - pattern: $RES.redirect($ASSIGN + $...FOO) + - pattern: $RES.redirect(`${$ASSIGN}...`) + - focus-metavariable: $ASSIGN +- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile + message: The application processes user-input, this is passed to res.sendFile which + can allow an attacker to arbitrarily read files on the system through path traversal. + It is recommended to perform input validation in addition to canonicalizing the + path. This allows you to validate the path against the intended directory it should + be accessing. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-73: External Control of File Name or Path' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + shortlink: https://sg.run/7DJk + semgrep.dev: + rule: + r_id: 22082 + rv_id: 1263142 + rule_id: j2UzDx + version_id: 7ZTE3X9 + url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + function ... (...,$REQ: $TYPE, ...) {...} + - metavariable-regex: + metavariable: $TYPE + regex: ^(string|String) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.$METH($QUERY,...) + - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) + - metavariable-regex: + metavariable: $METH + regex: ^(sendfile|sendFile)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + shortlink: https://sg.run/LYvG + semgrep.dev: + rule: + r_id: 22083 + rv_id: 1263143 + rule_id: 10Uo39 + version_id: LjTkgle + url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern-inside: | + import $SESSION from 'express-session' + ... + - pattern-inside: | + import {..., $SESSION, ...} from 'express-session' + ... + - pattern-inside: | + import * as $SESSION from 'express-session' + ... + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: | + $SECRET = $VALUE + ... + $APP.use($SESSION($SECRET)) + - pattern: | + secret: '$Y' +- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + message: The following function call $SER.$FUNC accepts user controlled data which + can result in Remote Code Execution (RCE) through Object Deserialization. It is + recommended to use secure data processing alternatives such as JSON.parse() and + Buffer.from(). + options: + interfile: true + metadata: + interfile: true + technology: + - express + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + shortlink: https://sg.run/8W5j + semgrep.dev: + rule: + r_id: 22084 + rv_id: 1263145 + rule_id: 9AUyqj + version_id: gETB7nD + url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $SER = require('$IMPORT') + ... + - pattern-inside: | + import $SER from '$IMPORT' + ... + - pattern-inside: | + import * as $SER from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + message: Detected a sequelize statement that is tainted by user-input. This could + lead to SQL injection if the variable is user-controlled and is not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. + options: + interfile: true + metadata: + interfile: true + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + category: security + technology: + - express + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + shortlink: https://sg.run/gjoe + semgrep.dev: + rule: + r_id: 22085 + rv_id: 1263241 + rule_id: yyU0GX + version_id: nWT2Llx + url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) +- id: javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization + message: Detected a call to `$FUNC()` in an attempt to HTML escape the string `$STR`. + Manually sanitizing input through a manually built list can be circumvented in + many situations, and it's better to use a well known sanitization library such + as `sanitize-html` or `DOMPurify`. + metadata: + category: security + technology: + - javascript + - typescript + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://www.npmjs.com/package/dompurify + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization + shortlink: https://sg.run/AzoB + semgrep.dev: + rule: + r_id: 22550 + rv_id: 1263104 + rule_id: kxUYE9 + version_id: l4TJR1L + url: https://semgrep.dev/playground/r/l4TJR1L/javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization + origin: community + languages: + - javascript + - typescript + severity: INFO + patterns: + - pattern-either: + - pattern: $STR.$FUNC('<', '<') + - pattern: $STR.$FUNC('>', '>') + - pattern: $STR.$FUNC('"', '"') + - pattern: $STR.$FUNC("'", ''') + - pattern: $STR.$FUNC('&', '&') + - metavariable-regex: + metavariable: $FUNC + regex: (replace|replaceAll) +- id: javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage + message: A CSRF middleware was not detected in your express application. Ensure + you are either using one such as `csurf` or `csrf` (see rule references) and/or + you are properly doing CSRF validation in your routes with a token or cookies. + metadata: + category: security + references: + - https://www.npmjs.com/package/csurf + - https://www.npmjs.com/package/csrf + - https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - javascript + - typescript + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage + shortlink: https://sg.run/BxzR + semgrep.dev: + rule: + r_id: 22551 + rv_id: 1263128 + rule_id: wdUKEq + version_id: yeTxp5d + url: https://semgrep.dev/playground/r/yeTxp5d/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage + origin: community + languages: + - javascript + - typescript + severity: INFO + patterns: + - pattern-inside: | + $EXPRESS = require('express') + ... + - pattern-not-inside: | + import {$CSRF} from 'csurf' + ... + - pattern-not-inside: | + require('csurf') + ... + - pattern-not-inside: | + import {$CSRF} from 'csrf' + ... + - pattern-not-inside: | + require('csrf') + ... + - pattern: | + $APP = $EXPRESS() +- id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + message: Directory listing/indexing is enabled, which may lead to disclosure of + sensitive directories and files. It is recommended to disable directory listing + unless it is a public resource. If you need directory listing, ensure that sensitive + files are inaccessible when querying the resource. + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - express + references: + - https://www.npmjs.com/package/serve-index + - https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/ + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + shortlink: https://sg.run/DX2G + semgrep.dev: + rule: + r_id: 22552 + rv_id: 1263129 + rule_id: x8UqEb + version_id: rxTAKGb + url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $APP.use(require('serve-index')(...)) + - patterns: + - pattern-either: + - pattern-inside: | + $SERVEINDEX = require('serve-index') + ... + - pattern-inside: | + import $SERVEINDEX from 'serve-index' + ... + - pattern-inside: | + import * as $SERVEINDEX from 'serve-index' + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $SERVEINDEX(...) + ... + - pattern: | + $VALUE(...) + - pattern: | + $APP.use(..., $SERVEINDEX(...), ...) +- id: javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage + message: Detected usage of the `notevil` package, which is unmaintained and has + vulnerabilities. Using any sort of `eval()` functionality can be very dangerous, + but if you must, the `eval` package is an up to date alternative. Be sure that + only trusted input reaches an `eval()` function. + metadata: + category: security + references: + - https://github.com/mmckegg/notevil + cwe: + - 'CWE-1104: Use of Unmaintained Third Party Components' + owasp: + - A06:2021 - Vulnerable and Outdated Components + - A03:2025 - Software Supply Chain Failures + technology: + - javascript + - typescript + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage + shortlink: https://sg.run/W70E + semgrep.dev: + rule: + r_id: 22553 + rv_id: 1263136 + rule_id: OrUX9K + version_id: e1TyjGl + url: https://semgrep.dev/playground/r/e1TyjGl/javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + import $EVAL from 'notevil' + ... + - pattern-inside: | + import {$EVAL} from 'notevil' + ... + - pattern-inside: | + $EVAL = require('notevil') + ... + - pattern-either: + - patterns: + - pattern: $EVAL(...) + - pattern-not: $EVAL('...') + - patterns: + - pattern-either: + - pattern: $VM.runInContext("$CMD", ...) + - pattern: $VM.runInNewContext("$CMD", ...) + - pattern: $VM.runInThisContext("$CMD", ...) + - pattern: $VM.compileFunction("$CMD", ...) + - metavariable-pattern: + patterns: + - pattern: $EVAL(...) + - pattern-not: $EVAL('...') + metavariable: $CMD + language: typescript +- id: javascript.express.security.audit.express-ssrf.express-ssrf + message: 'The following request $REQUEST.$METHOD() was found to be crafted from + user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities. + It is recommended where possible to not allow user-input to craft the base request, + but to be treated as part of the path or query parameter. When user-input is necessary + to craft the request, it is recommeneded to follow OWASP best practices to prevent + abuse. ' + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + technology: + - express + category: security + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf + shortlink: https://sg.run/0PNw + semgrep.dev: + rule: + r_id: 22554 + rv_id: 1263144 + rule_id: eqU9l2 + version_id: 8KT5rBr + url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + options: + taint_unify_mvars: true + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, ...) {...} + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,...) => + {...} + - pattern-inside: | + ({ $REQ }: $EXPRESS.Request,...) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) + - pattern: $REQ. ... .$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) + - pattern: $REQ.$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = "$HTTP"+ $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A + ... + - pattern-inside: | + $ASSIGN = `$HTTP${$REQ.$VALUE[...]}...` + ... + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQUEST.$METHOD($ASSIGN,...) + - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) + - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) + - patterns: + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) + - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern: $ASSIGN + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ +- id: javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key + message: Detected a hardcoded hmac key. Avoid hardcoding secrets and consider using + an alternate option such as reading the secret from a config file or using an + environment variable. + options: + interfile: true + metadata: + interfile: true + category: security + technology: + - crypto + - hmac + references: + - https://rules.sonarsource.com/javascript/RSPEC-2068 + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#key-management + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key + shortlink: https://sg.run/K9bn + semgrep.dev: + rule: + r_id: 22555 + rv_id: 1263198 + rule_id: v8UGEw + version_id: A8Tgdyk + url: https://semgrep.dev/playground/r/A8Tgdyk/javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern-either: + - pattern: $CRYPTO.createHmac($ALGO, '...') + - patterns: + - pattern-inside: | + const $SECRET = '...' + ... + - pattern: $CRYPTO.createHmac($ALGO, $SECRET) +- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + patterns: + - pattern: $APP.UseDeveloperExceptionPage(...); + - pattern-not-inside: | + if ($ENV.IsDevelopment(...)) { + ... + } + - pattern-not-inside: | + if ($ENV.EnvironmentName == "Development") { + ... + } + message: Stacktrace information is displayed in a non-Development environment. Accidentally + disclosing sensitive stack trace information in a production environment aids + an attacker in reconnaissance and information gathering. + metadata: + category: security + technology: + - csharp + owasp: + - A06:2017 - Security Misconfiguration + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-209: Generation of Error Message Containing Sensitive Information' + references: + - https://cwe.mitre.org/data/definitions/209.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + shortlink: https://sg.run/XvkA + semgrep.dev: + rule: + r_id: 26720 + rv_id: 1262653 + rule_id: lBU6Dv + version_id: 0bTKzrB + url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + origin: community + languages: + - csharp + severity: WARNING +- id: csharp.dotnet.security.audit.mass-assignment.mass-assignment + message: Mass assignment or Autobinding vulnerability in code allows an attacker + to execute over-posting attacks, which could create a new parameter in the binding + request and manipulate the underlying object in the application. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/915.html + - https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment + shortlink: https://sg.run/7B3e + semgrep.dev: + rule: + r_id: 26838 + rv_id: 1262613 + rule_id: x8Up5B + version_id: YDTZeD9 + url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + public IActionResult $METHOD(..., $TYPE $ARG, ...){ + ... + } + - pattern: | + public ActionResult $METHOD(..., $TYPE $ARG, ...){ + ... + } + - pattern-inside: | + using Microsoft.AspNetCore.Mvc; + ... + - pattern-not: | + public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ + ... + } + - pattern-not: | + public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ + ... + } + - focus-metavariable: $ARG + pattern-sinks: + - pattern: View(...) +- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $X = code.InteractiveConsole(...) + ... + - pattern-inside: | + $X = code.InteractiveInterpreter(...) + ... + - pattern-either: + - pattern: | + $X.push($PAYLOAD,...) + - pattern: | + $X.runsource($PAYLOAD,...) + - pattern: | + $X.runcode(code.compile_command($PAYLOAD),...) + - pattern: | + $PL = code.compile_command($PAYLOAD,...) + ... + $X.runcode($PL,...) + - focus-metavariable: $PAYLOAD + - pattern-not: | + $X.push("...",...) + - pattern-not: | + $X.runsource("...",...) + - pattern-not: | + $X.runcode(code.compile_command("..."),...) + - pattern-not: | + $PL = code.compile_command("...",...) + ... + $X.runcode($PL,...) + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter + method. This is dangerous if external data can reach this function call because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + shortlink: https://sg.run/9pRY + semgrep.dev: + rule: + r_id: 27267 + rv_id: 1263521 + rule_id: KxUKzx + version_id: l4TJRgo + url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.dangerous-os-exec.dangerous-os-exec + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + confidence: MEDIUM + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec + shortlink: https://sg.run/yL9x + semgrep.dev: + rule: + r_id: 27268 + rv_id: 1263523 + rule_id: qNUR13 + version_id: 6xT29rz + url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + - patterns: + - pattern-either: + - pattern: os.environ['$ANYTHING'] + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb['$ANYTHING'] + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv[...] + - pattern: sys.orig_argv[...] + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/r8Zn + semgrep.dev: + rule: + r_id: 27269 + rv_id: 1263524 + rule_id: lBUJrn + version_id: o5TbDO5 + url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern: | + _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) + - pattern-not: | + _xxsubinterpreters.run_string($ID, "...", ...) + - focus-metavariable: $PAYLOAD + message: Found user controlled content in `run_string`. This is dangerous because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + shortlink: https://sg.run/bPop + semgrep.dev: + rule: + r_id: 27270 + rv_id: 1263525 + rule_id: PeURWr + version_id: zyTb2OX + url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], + ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), + ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + message: Detected subprocess function '$FUNC' with user controlled data. A malicious + actor could leverage this to perform command injection. You may consider using + 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/NWxp + semgrep.dev: + rule: + r_id: 27271 + rv_id: 1263526 + rule_id: JDUz3R + version_id: pZT038J + url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-system-call.dangerous-system-call + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: getattr(os, "system")(...) + - pattern: __import__("os").system(...) + - pattern: getattr(__import__("os"), "system")(...) + - pattern: | + $X = __import__("os") + ... + $X.system(...) + - pattern: | + $X = __import__("os") + ... + getattr($X, "system")(...) + - pattern: | + $X = getattr(os, "system") + ... + $X(...) + - pattern: | + $X = __import__("os") + ... + $Y = getattr($X, "system") + ... + $Y(...) + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + message: Found user-controlled data used in a system call. This could allow a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/k0W7 + semgrep.dev: + rule: + r_id: 27272 + rv_id: 1263527 + rule_id: 5rUoP1 + version_id: 2KTv2Zn + url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + _testcapi.run_in_subinterp($PAYLOAD, ...) + - pattern: | + test.support.run_in_subinterp($PAYLOAD, ...) + - focus-metavariable: $PAYLOAD + - pattern-not: | + _testcapi.run_in_subinterp("...", ...) + - pattern-not: | + test.support.run_in_subinterp("...", ...) + message: Found user controlled content in `run_in_subinterp`. This is dangerous + because it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + shortlink: https://sg.run/wLpY + semgrep.dev: + rule: + r_id: 27273 + rv_id: 1263528 + rule_id: GdUkxR + version_id: X0Tzy1e + url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + origin: community + severity: WARNING + languages: + - python +- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + patterns: + - pattern-either: + - patterns: + - pattern: $LIFETIME = $FALSE + - pattern-inside: new TokenValidationParameters {...} + - patterns: + - pattern: | + (TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE + - metavariable-regex: + metavariable: $LIFETIME + regex: (RequireExpirationTime|ValidateLifetime) + - metavariable-regex: + metavariable: $FALSE + regex: (false) + - focus-metavariable: $FALSE + fix: | + true + message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the + JWT tokens lifetime is not validated. This can lead to an JWT token being used + after it has expired, which has security implications. It is recommended to validate + the JWT lifetime to ensure only valid tokens are used. + metadata: + category: security + technology: + - csharp + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-613: Insufficient Session Expiration' + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://cwe.mitre.org/data/definitions/613.html + - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + shortlink: https://sg.run/KA0d + semgrep.dev: + rule: + r_id: 28955 + rv_id: 1262628 + rule_id: bwU5kK + version_id: w8TRolJ + url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + origin: community + languages: + - csharp + severity: WARNING +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(..., $REQUEST, ...): + ... + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + shortlink: https://sg.run/49BE + semgrep.dev: + rule: + r_id: 31144 + rv_id: 1263388 + rule_id: EwUepx + version_id: 7ZTE3qK + url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + origin: community +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + shortlink: https://sg.run/5gW3 + semgrep.dev: + rule: + r_id: 31147 + rv_id: 1263433 + rule_id: 8GU3qp + version_id: bZT53gQ + url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + origin: community +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `actions/github-script`''s `script:` step could allow an attacker to inject + their own code into the runner. This would allow them to steal secrets and code. + `github` context data can have arbitrary user input and should be treated as untrusted. + Instead, use an intermediate environment variable with `env:` to store the data + and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + technology: + - github-actions + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + shortlink: https://sg.run/g1G0 + semgrep.dev: + rule: + r_id: 31441 + rv_id: 1423394 + rule_id: OrUQvK + version_id: 5PT7Zyw + url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + uses: $ACTION + ... + - pattern-inside: | + with: + ... + script: ... + ... + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial + stream output. Its use is strongly discouraged. ARC4 does not use mode constructions. + Use a strong symmetric cipher such as EAS instead. With the `cryptography` package + it is recommended to use the `Fernet` which is a secure implementation of AES + in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class + from the hazmat primitives but use the AES algorithm instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + shortlink: https://sg.run/xoZL + semgrep.dev: + rule: + r_id: 33630 + rv_id: 1263348 + rule_id: KxU8gK + version_id: QkTGq3Q + url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) + - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) + - metavariable-regex: + metavariable: $ARC4 + regex: ^(ARC4)$ + - focus-metavariable: $ARC4 + fix: AES +- id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + message: Blowfish is a block cipher developed by Bruce Schneier. It is known to + be susceptible to attacks when using weak keys. The author has recommended that + users of Blowfish move to newer algorithms such as AES. With the `cryptography` + package it is recommended to use `Fernet` which is a secure implementation of + AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class + from the hazmat primitives but use the AES algorithm instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + - https://tools.ietf.org/html/rfc5469 + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + shortlink: https://sg.run/OdzL + semgrep.dev: + rule: + r_id: 33631 + rv_id: 1263349 + rule_id: qNULvO + version_id: 3ZT4XK7 + url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) + - metavariable-regex: + metavariable: $BLOWFISH + regex: ^(Blowfish)$ + - focus-metavariable: $BLOWFISH + fix: AES +- id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B303 + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/eY88 + semgrep.dev: + rule: + r_id: 33632 + rv_id: 1263352 + rule_id: lBUopp + version_id: JdTzxww + url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$MD5() + - metavariable-regex: + metavariable: $MD5 + regex: ^(MD5)$ + - focus-metavariable: $MD5 + fix: SHA256 +- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + shortlink: https://sg.run/dlOE + semgrep.dev: + rule: + r_id: 33634 + rv_id: 1263545 + rule_id: JDUGnK + version_id: ExTExln + url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.Blowfish.new(...) + - pattern: Crypto.Cipher.Blowfish.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + message: Detected DES cipher or Triple DES algorithm which is considered insecure. + This algorithm is not cryptographically secure and can be reversed easily. Use + a secure symmetric cipher from the cryptodome package instead. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + shortlink: https://sg.run/Z5bw + semgrep.dev: + rule: + r_id: 33635 + rv_id: 1263546 + rule_id: 5rUr73 + version_id: 7ZTE3G7 + url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.DES.new(...) + - pattern: Crypto.Cipher.DES.new(...) + - pattern: Cryptodome.Cipher.DES3.new(...) + - pattern: Crypto.Cipher.DES3.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + message: Detected RC2 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + shortlink: https://sg.run/nAbY + semgrep.dev: + rule: + r_id: 33636 + rv_id: 1263547 + rule_id: GdUYlW + version_id: LjTkgn6 + url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC2.new(...) + - pattern: Crypto.Cipher.ARC2.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + shortlink: https://sg.run/Eo6N + semgrep.dev: + rule: + r_id: 33637 + rv_id: 1263548 + rule_id: ReUnEB + version_id: 8KT5rXY + url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC4.new(...) + - pattern: Crypto.Cipher.ARC4.new(...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + shortlink: https://sg.run/7JP2 + semgrep.dev: + rule: + r_id: 33638 + rv_id: 1263550 + rule_id: AbU0Ex + version_id: QkTGqD8 + url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD2.new(...) + - pattern: Cryptodome.Hash.MD2.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + shortlink: https://sg.run/Lve6 + semgrep.dev: + rule: + r_id: 33639 + rv_id: 1263551 + rule_id: BYUJy4 + version_id: 3ZT4Xnp + url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD4.new(...) + - pattern: Cryptodome.Hash.MD4.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/85JN + semgrep.dev: + rule: + r_id: 33640 + rv_id: 1263552 + rule_id: DbUXwo + version_id: 44TEjpk + url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD5.new(...) + - pattern: Cryptodome.Hash.MD5.new (...) +- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `workflow_run` and checks out code + from the incoming pull request. When using `workflow_run`, the Action runs in + the context of the target repository, which includes access to all repository + secrets. Normally, this is safe because the Action only runs code from the target + repository, not the incoming PR. However, by checking out the incoming PR code, + you're now using the incoming code for the rest of the action. You may be inadvertently + executing arbitrary code from the incoming PR with access to repository secrets, + which would let an attacker steal repository secrets. This normally happens by + running build scripts (e.g., `npm build` and `make`) or dependency installation + scripts (e.g., `python setup.py install`). Audit your workflow file to make sure + no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + for additional mitigations. + metadata: + category: security + owasp: A01:2017 - Injection + cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + subcategory: + - vuln + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability + technology: + - github-actions + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + shortlink: https://sg.run/A0p6 + semgrep.dev: + rule: + r_id: 35494 + rv_id: 947046 + rule_id: 4bU8E4 + version_id: kbTYRwl + url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + origin: community + patterns: + - pattern-inside: | + on: + ... + workflow_run: ... + ... + ... + - pattern-inside: | + jobs: + ... + $JOBNAME: + ... + steps: + ... + - pattern: | + ... + uses: "$ACTION" + with: + ... + ref: $EXPR + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern: ${{ github.event.workflow_run ... }} + severity: WARNING +- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode + message: Usage of the insecure ECB mode detected. You should use an authenticated + encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + shortlink: https://sg.run/wj9n + semgrep.dev: + rule: + r_id: 36773 + rv_id: 1262623 + rule_id: 0oUqWP + version_id: yeTxpPw + url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + origin: community + languages: + - csharp + patterns: + - pattern-either: + - pattern: ($KEYTYPE $KEY).EncryptEcb(...); + - pattern: ($KEYTYPE $KEY).DecryptEcb(...); + - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 +- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + message: You are using an insecure random number generator (RNG) to create a cryptographic + key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator + instead. + severity: ERROR + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + shortlink: https://sg.run/xjrA + semgrep.dev: + rule: + r_id: 36774 + rv_id: 1262624 + rule_id: KxU3Nq + version_id: rxTAK2O + url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... + - pattern: $KEY + pattern-sinks: + - pattern-either: + - patterns: + - pattern: ($KEYTYPE $CIPHER).Key = $SINK; + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 + - pattern: new AesGcm(...) + - pattern: new AesCcm(...) + - pattern: new ChaCha20Poly1305(...) +- id: html.security.plaintext-http-link.plaintext-http-link + metadata: + category: security + technology: + - html + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + confidence: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/319.html + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link + shortlink: https://sg.run/RA5q + semgrep.dev: + rule: + r_id: 39193 + rv_id: 1262976 + rule_id: AbUnNo + version_id: xyTjzRL + url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link + origin: community + patterns: + - pattern: ... + - metavariable-regex: + metavariable: $URL + regex: ^(?i)http:// + message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL + if possible. + severity: WARNING + languages: + - html +- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::org.apache.commons + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + shortlink: https://sg.run/AWL2 + semgrep.dev: + rule: + r_id: 39194 + rv_id: 1263012 + rule_id: BYUGK0 + version_id: WrTqK7K + url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + origin: community + patterns: + - pattern: | + $DU.$GET_ALGO().digest(...) + - metavariable-pattern: + metavariable: $GET_ALGO + pattern: getMd5Digest + - metavariable-pattern: + metavariable: $DU + pattern: DigestUtils + - focus-metavariable: $GET_ALGO + fix: | + getSha512Digest +- id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + message: Dangerously accepting invalid TLS information + pattern-either: + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true) + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true) + metadata: + references: + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs + technology: + - reqwest + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + shortlink: https://sg.run/DqrG + semgrep.dev: + rule: + r_id: 40108 + rv_id: 946551 + rule_id: qNUKDg + version_id: 7ZTrQLJ + url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + origin: community + languages: + - rust + severity: WARNING +- id: rust.lang.security.rustls-dangerous.rustls-dangerous + message: Dangerous client config used, ensure SSL verification + pattern-either: + - pattern: rustls::client::DangerousClientConfig + - pattern: $CLIENT.dangerous().set_certificate_verifier(...) + - pattern: | + let $CLIENT = rustls::client::ClientConfig::dangerous(...); + ... + $CLIENT.set_certificate_verifier(...); + metadata: + references: + - https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html + - https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous + technology: + - rustls + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous + shortlink: https://sg.run/01Rw + semgrep.dev: + rule: + r_id: 40110 + rv_id: 946553 + rule_id: YGU8LK + version_id: 8KTKjdO + url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous + origin: community + languages: + - rust + severity: WARNING +- id: rust.lang.security.ssl-verify-none.ssl-verify-none + message: SSL verification disabled, this allows for MitM attacks + pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE) + metadata: + references: + - https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify + technology: + - openssl + category: security + cwe: 'CWE-295: Improper Certificate Validation' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none + shortlink: https://sg.run/K2Pn + semgrep.dev: + rule: + r_id: 40111 + rv_id: 946554 + rule_id: 6JU0Bl + version_id: gETe1bo + url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none + origin: community + languages: + - rust + severity: WARNING +- id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + message: Using input or workflow parameters in here-scripts can lead to command + injection or code injection. Convert the parameters to env variables instead. + languages: + - yaml + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - "A03:2021 \u2013 Injection" + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://github.com/argoproj/argo-workflows/issues/5061 + - https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370 + technology: + - ci + - argo + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + - Command Injection + source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + shortlink: https://sg.run/yqeZ + semgrep.dev: + rule: + r_id: 40768 + rv_id: 1151472 + rule_id: 10U0zW + version_id: xyTp17z + url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + origin: community + severity: ERROR + patterns: + - pattern-inside: | + apiVersion: $VERSION + ... + - metavariable-regex: + metavariable: $VERSION + regex: (argoproj.io.*) + - pattern-either: + - patterns: + - pattern-inside: | + command: + ... + - $LANG + ... + ... + source: + $SCRIPT + - metavariable-regex: + metavariable: $LANG + regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $SCRIPT + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $SCRIPT + - patterns: + - pattern-either: + - pattern-inside: | + container: + ... + command: $LANG + ... + args: $PARAM + - pattern-inside: | + containerSet: + ... + containers: + - ... + command: $LANG + ... + args: $PARAM + - metavariable-regex: + metavariable: $LANG + regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $PARAM + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $PARAM +- id: python.cryptography.security.empty-aes-key.empty-aes-key + message: Potential empty AES encryption key. Using an empty key in AES encryption + can result in weak encryption and may allow attackers to easily decrypt sensitive + data. Ensure that a strong, non-empty key is used for AES encryption. + patterns: + - pattern: AES.new("",...) + languages: + - python + severity: WARNING + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-310: Cryptographic Issues' + references: + - https://cwe.mitre.org/data/definitions/327.html + - https://cwe.mitre.org/data/definitions/310.html + category: security + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + owasp: A6:2017 misconfiguration + functional-categories: + - crypto::search::key-length::pycrypto + - crypto::search::key-length::pycryptodome + technology: + - python + - pycrypto + - pycryptodome + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key + shortlink: https://sg.run/zQ9G + semgrep.dev: + rule: + r_id: 44817 + rv_id: 946105 + rule_id: OrUADK + version_id: 8KTKjRg + url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key + origin: community +- id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + patterns: + - pattern: | + ENTRYPOINT $...VARS + - pattern-not-inside: | + USER $USER + ... + fix: | + USER non-root + ENTRYPOINT $...VARS + message: By not specifying a USER, a program in the container may run as 'root'. + This is a security hazard. If an attacker can control a process running as root, + they may have control over the container. Ensure that the last USER in a Dockerfile + is a USER other than 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + shortlink: https://sg.run/k281 + semgrep.dev: + rule: + r_id: 47272 + rv_id: 1262659 + rule_id: ReUW9E + version_id: o5TbD21 + url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + origin: community +- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + pattern-either: + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + account_aggregation_source { + ... + regions = ... + ... + } + ... + } + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + organization_aggregation_source { + ... + regions = ... + ... + } + ... + } + message: The AWS configuration aggregator does not aggregate all AWS Config region. + This may result in unmonitored configuration in regions that are thought to be + unused. Configure the aggregator with all_regions for the source. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + shortlink: https://sg.run/O6A7 + semgrep.dev: + rule: + r_id: 47275 + rv_id: 1263703 + rule_id: DbUo7v + version_id: A8Tgdwv + url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + origin: community +- id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - $NAME: $CONTAINER + ... + - pattern: | + image: ... + ... + - pattern-not: | + image: ... + ... + securityContext: + ... + - metavariable-regex: + metavariable: $NAME + regex: name + - focus-metavariable: $NAME + fix: | + securityContext: + allowPrivilegeEscalation: false + $NAME + message: In Kubernetes, each pod runs in its own isolated environment with its own + set of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. By adding a `securityContext` to + your Kubernetes pod, you can help to ensure that your containerized applications + are more secure and less vulnerable to privilege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + shortlink: https://sg.run/eleR + semgrep.dev: + rule: + r_id: 47276 + rv_id: 1263931 + rule_id: WAU5J6 + version_id: 2KTv2j8 + url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - name: $CONTAINER + ... + - pattern-inside: | + image: ... + ... + - pattern-inside: | + securityContext: + ... + - pattern: | + allowPrivilegeEscalation: $TRUE + - metavariable-pattern: + metavariable: $TRUE + pattern: | + true + - focus-metavariable: $TRUE + fix: | + false + message: In Kubernetes, each pod runs in its own isolated environment with its own set + of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. In the container `$CONTAINER` + this parameter is set to `true` which makes this container much more vulnerable + to privelege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + shortlink: https://sg.run/vw3W + semgrep.dev: + rule: + r_id: 47277 + rv_id: 1263932 + rule_id: 0oUkqQ + version_id: X0Tzyqr + url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + origin: community + languages: + - yaml + severity: WARNING +- id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + patterns: + - pattern: | + resource "aws_docdb_cluster" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_docdb_cluster" $ANYTHING { + ... + enabled_cloudwatch_logs_exports = [..., "audit", ...] + ... + } + message: Auditing is not enabled for DocumentDB. To ensure that you are able to + accurately audit the usage of your DocumentDB cluster, you should enable auditing + and export logs to CloudWatch. + languages: + - hcl + severity: INFO + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + shortlink: https://sg.run/xJYP + semgrep.dev: + rule: + r_id: 48630 + rv_id: 1263705 + rule_id: AbU1WN + version_id: DkTRbA4 + url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + origin: community +- id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + patterns: + - pattern: | + resource "aws_ecr_repository" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_ecr_repository" $ANYTHING { + ... + image_tag_mutability = "IMMUTABLE" + ... + } + message: The ECR repository allows tag mutability. Image tags could be overwritten + with compromised images. ECR images should be set to IMMUTABLE to prevent code + injection through image mutation. This can be done by setting `image_tag_mutability` + to IMMUTABLE. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + shortlink: https://sg.run/ZEeL + semgrep.dev: + rule: + r_id: 48635 + rv_id: 1263716 + rule_id: KxUB4o + version_id: A8Tgdwd + url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + origin: community +- id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + patterns: + - pattern-inside: | + resource "aws_ecr_repository_policy" $ANYTHING { + ... + } + - pattern-either: + - patterns: + - pattern: policy = "$JSONPOLICY" + - metavariable-pattern: + metavariable: $JSONPOLICY + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, ...} + - patterns: + - pattern-inside: policy = jsonencode(...) + - pattern-not-inside: | + {..., Effect = "Deny", ...} + - pattern-either: + - pattern: | + {..., Principal = "*", ...} + - pattern: | + {..., Principal = [..., "*", ...], ...} + - pattern: | + {..., Principal = { AWS = "*" }, ...} + - pattern: | + {..., Principal = { AWS = [..., "*", ...] }, ...} + message: Detected wildcard access granted in your ECR repository policy principal. + This grants access to all users, including anonymous users (public access). Instead, + limit principals, actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy + - https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html + - https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + shortlink: https://sg.run/nzqb + semgrep.dev: + rule: + r_id: 48636 + rv_id: 1263717 + rule_id: qNUzov + version_id: BjTkZ6A + url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + origin: community + languages: + - hcl + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + pattern: $CIPHER.getInstance("=~/AES/ECB.*/") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + shortlink: https://sg.run/dB2Y + semgrep.dev: + rule: + r_id: 48734 + rv_id: 1263009 + rule_id: WAU2yA + version_id: A8TgdEo + url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + origin: community + message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality + and is not semantically secure so should not be used. Instead, use a strong, + secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + pattern: $CIPHER.getInstance("Blowfish") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + shortlink: https://sg.run/ZE4n + semgrep.dev: + rule: + r_id: 48735 + rv_id: 1263010 + rule_id: 0oUR28 + version_id: BjTkZy0 + url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + origin: community + message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes + it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead, + use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + import javax; + ... + - pattern-either: + - pattern: javax.crypto.Cipher.getInstance("AES") + - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.*; + ... + - pattern-inside: | + import javax.crypto; + ... + - pattern-either: + - pattern: crypto.Cipher.getInstance("AES") + - pattern: (crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.crypto.*; + ... + - pattern-inside: | + import javax.crypto.Cipher; + ... + - pattern-either: + - pattern: Cipher.getInstance("AES") + - pattern: (Cipher $CIPHER).getInstance("AES") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + shortlink: https://sg.run/nzKO + semgrep.dev: + rule: + r_id: 48736 + rv_id: 1263011 + rule_id: KxUB7Z + version_id: DkTRbwy + url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + origin: community + message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses + ECB mode. ECB doesn''t provide message confidentiality and is not semantically + secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + pattern: $CIPHER.getInstance("RC2") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + shortlink: https://sg.run/EEvA + semgrep.dev: + rule: + r_id: 48737 + rv_id: 1263014 + rule_id: qNUzXG + version_id: K3TKkg0 + url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + origin: community + message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and + is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + pattern: $CIPHER.getInstance("RC4") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + shortlink: https://sg.run/7OYR + semgrep.dev: + rule: + r_id: 48738 + rv_id: 1263015 + rule_id: lBUw8k + version_id: qkTR7vk + url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + origin: community + message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including + stream cipher attacks and bit flipping attacks. Instead, use a strong, secure + cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + message: Detected an HTTP request sent via HttpGet. This could lead to sensitive + information being sent over an insecure channel. Instead, it is recommended to + send requests over HTTPS. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: A03:2017 - Sensitive Data Exposure + references: + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection() + subcategory: + - vuln + technology: + - java + vulnerability: Insecure Transport + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + shortlink: https://sg.run/QE2q + semgrep.dev: + rule: + r_id: 48942 + rv_id: 946061 + rule_id: 6JUOJ2 + version_id: WrTEo9G + url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + origin: community + languages: + - java + fix-regex: + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + count: 1 + patterns: + - pattern: | + "=~/[Hh][Tt][Tt][Pp]://.*/" + - pattern-inside: | + $R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/"); + ... + $CLIENT. ... .execute($R, ...); +- id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + patterns: + - pattern: | + resource "aws_ebs_volume" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_ebs_volume" $ANYTHING { + ... + encrypted = true + ... + } + message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived + snapshots could be read if compromised. Volumes should be encrypted to ensure + sensitive data is stored securely. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted + - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + shortlink: https://sg.run/6ZbY + semgrep.dev: + rule: + r_id: 50759 + rv_id: 1263708 + rule_id: YGUKl1 + version_id: K3TKk1Z + url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + origin: community +- id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + patterns: + - pattern: | + resource "aws_launch_template" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_launch_template" $ANYTHING { + ... + metadata_options { + ... + http_endpoint = "disabled" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_launch_template" $ANYTHING { + ... + metadata_options { + ... + http_tokens = "required" + ... + } + ... + } + message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1) + enabled. IMDSv2 introduced session authentication tokens which improve security + when talking to IMDS. You should either disable IMDS or require the use of IMDSv2. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-1390: Weak Authentication' + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + shortlink: https://sg.run/pg9J + semgrep.dev: + rule: + r_id: 50762 + rv_id: 1263712 + rule_id: zdU0Wo + version_id: JdTzx88 + url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + origin: community +- id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + patterns: + - pattern-either: + - pattern: | + resource "aws_subnet" $ANYTHING { + ... + map_public_ip_on_launch = true + ... + } + - pattern: | + resource "aws_default_subnet" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_default_subnet" $ANYTHING { + ... + map_public_ip_on_launch = false + ... + } + message: Resources in the AWS subnet are assigned a public IP address. Resources + should not be exposed on the public internet, but should have access limited to + consumers required for the function of your application. Set `map_public_ip_on_launch` + to false so that resources are not publicly-accessible. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch + - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + shortlink: https://sg.run/XJZw + semgrep.dev: + rule: + r_id: 50764 + rv_id: 1263744 + rule_id: 2ZUo79 + version_id: d6Tyxdb + url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + origin: community +- id: clojure.lang.security.use-of-md5.use-of-md5 + languages: + - clojure + severity: WARNING + message: MD5 hash algorithm detected. This is not collision resistant and leads + to easily-cracked password hashes. Replace with current recommended hashing algorithms. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + author: Gabriel Marquet + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 + shortlink: https://sg.run/BgPx + semgrep.dev: + rule: + r_id: 52195 + rv_id: 1262609 + rule_id: nJU1ep + version_id: 0bTKz2B + url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 + origin: community + pattern-either: + - pattern: (MessageDigest/getInstance "MD5") + - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance "MD5") + - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) +- id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + patterns: + - pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$ + message: Detects potential Google Maps API keys in code + languages: + - generic + severity: WARNING + metadata: + description: Detects potential Google Maps API keys in code + severity: MEDIUM + category: security + confidence: MEDIUM + impact: HIGH + likelihood: MEDIUM + subcategory: + - audit + owasp: + - A3:2017 Sensitive Data Exposure + references: + - https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e + cwe: + - 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File + or Directory' + technology: + - Google Maps + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + shortlink: https://sg.run/DL5d + semgrep.dev: + rule: + r_id: 52196 + rv_id: 945530 + rule_id: EwU3kN + version_id: NdTqkGz + url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + origin: community +- id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + patterns: + - pattern: | + resource "aws_kinesis_stream" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_kinesis_stream" $ANYTHING { + ... + encryption_type = "KMS" + ... + } + message: The AWS Kinesis stream does not encrypt data at rest. The data could be + read if the Kinesis stream storage layer is compromised. Enable Kinesis stream + server-side encryption. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type + - https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + shortlink: https://sg.run/KZ0L + semgrep.dev: + rule: + r_id: 52199 + rv_id: 1263728 + rule_id: 8GU72N + version_id: pZT037O + url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + origin: community +- id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + patterns: + - pattern-either: + - pattern-inside: | + resource "aws_sqs_queue_policy" $ANYTHING { + ... + } + - pattern-inside: | + resource "aws_sqs_queue" $ANYTHING { + ... + } + - pattern-either: + - patterns: + - pattern: policy = "$JSONPOLICY" + - metavariable-pattern: + metavariable: $JSONPOLICY + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, ...} + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n + \ \"aws:PrincipalARN\": ...\n }\n},\n...}\n" + - patterns: + - pattern-inside: policy = jsonencode(...) + - pattern-not-inside: | + {..., Effect = "Deny", ...} + - pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\" + = ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\" + = ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\" + = ...\n }\n}\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\" + = ...\n }\n},\n...}\n" + - pattern-either: + - pattern: | + {..., Principal = "*", ...} + - pattern: | + {..., Principal = [..., "*", ...], ...} + - pattern: | + {..., Principal = { AWS = "*" }, ...} + - pattern: | + {..., Principal = { AWS = [..., "*", ...] }, ...} + message: Wildcard used in your SQS queue policy principal. This grants access to + all users, including anonymous users (public access). Unless you explicitly require + anyone on the internet to be able to read or write to your queue, limit principals, + actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml + in None + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + shortlink: https://sg.run/z3eW + semgrep.dev: + rule: + r_id: 53517 + rv_id: 1263741 + rule_id: PeUl9d + version_id: O9TpxgE + url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + patterns: + - pattern: | + resource "aws_lambda_permission" $ANYTHING { + ... + principal = "$PRINCIPAL" + ... + } + - pattern-not: | + resource "aws_lambda_permission" $ANYTHING { + ... + source_arn = ... + ... + } + - metavariable-regex: + metavariable: $PRINCIPAL + regex: .*[.]amazonaws[.]com$ + message: The AWS Lambda permission has an AWS service principal but does not specify + a source ARN. If you grant permission to a service principal without specifying + the source, other accounts could potentially configure resources in their account + to invoke your Lambda function. Set the source_arn value to the ARN of the AWS + resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule, + API Gateway, or SNS topic. + languages: + - hcl + severity: ERROR + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission + - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + shortlink: https://sg.run/kOP7 + semgrep.dev: + rule: + r_id: 54772 + rv_id: 1263732 + rule_id: OrU9Ox + version_id: 1QTypq5 + url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + origin: community +- id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + patterns: + - pattern: | + resource "aws_lambda_function" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_lambda_function" $ANYTHING { + ... + tracing_config { + ... + mode = "Active" + ... + } + ... + } + message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray + tracing enables end-to-end debugging and analysis of all function activity. This + makes it easier to trace the flow of logs and identify bottlenecks, slow downs + and timeouts. + languages: + - hcl + severity: INFO + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A09:2021 Security Logging and Monitoring Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://cwe.mitre.org/data/definitions/778.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode + - https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + shortlink: https://sg.run/wO2Y + semgrep.dev: + rule: + r_id: 54773 + rv_id: 946713 + rule_id: eqUl1O + version_id: QkTZ6vk + url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + origin: community +- id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + ObjectMapper $OM = new ObjectMapper(...); + ... + - pattern-inside: | + $OM.enableDefaultTyping(); + ... + - pattern: $OM.readValue($JSON, ...); + - patterns: + - pattern-inside: | + class $CLASS { + ... + @JsonTypeInfo(use = Id.CLASS,...) + $TYPE $VAR; + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: (Object|Serializable|Comparable) + - pattern: $OM.readValue($JSON, $CLASS.class); + - patterns: + - pattern-inside: | + class $CLASS { + ... + ObjectMapper $OM; + ... + $INITMETHODTYPE $INITMETHOD(...) { + ... + $OM = new ObjectMapper(); + ... + $OM.enableDefaultTyping(); + ... + } + ... + } + - pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n" + - pattern: $OM.readValue($JSON, ...); + message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling + default typing is dangerous and can lead to RCE. If an attacker can control `$JSON` + it might be possible to provide a malicious JSON which can be used to exploit + unsecure deserialization. In order to prevent this issue, avoid to enable default + typing (globally or by using "Per-class" annotations) and avoid using `Object` + and other dangerous types for member variable declaration which creating classes + for Jackson based deserialization. + languages: + - java + severity: WARNING + metadata: + category: security + subcategory: + - audit + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + confidence: MEDIUM + likelihood: LOW + impact: HIGH + owasp: + - A8:2017 Insecure Deserialization + - A8:2021 Software and Data Integrity Failures + references: + - https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038 + - https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 + - https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/ + technology: + - jackson + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + shortlink: https://sg.run/GDop + semgrep.dev: + rule: + r_id: 56948 + rv_id: 945724 + rule_id: QrUD20 + version_id: 2KTYbA9 + url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + origin: community +- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/Gj32 + semgrep.dev: + rule: + r_id: 59048 + rv_id: 1263061 + rule_id: j2Udpk + version_id: YDTZeko + url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` + and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - + The previous links are not meant to be clicked. They are the literal config key + values that are supposed to be used to disable these features. For more information, + see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = SAXParserFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newSAXParser(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newSAXParser(); + languages: + - java +- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + shortlink: https://sg.run/1wyQ + semgrep.dev: + rule: + r_id: 59622 + rv_id: 1263062 + rule_id: v8UeQ1 + version_id: 6xT29GK + url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + origin: community + message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" + and "accessExternalStylesheet" to "". + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = TransformerFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newTransformer(...); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + $FACTORY.newTransformer(...); + languages: + - java +- id: javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + patterns: + - pattern-either: + - pattern: | + window.intercomSettings = {..., email: $EMAIL, ...}; + - pattern: | + window.intercomSettings = {..., user_id: $USER_ID, ...}; + - pattern: | + Intercom('boot', {..., email: $EMAIL, ...}); + - pattern: | + Intercom('boot', {..., user_id: $USER_ID, ...}); + - pattern: | + $VAR = {..., email: $EMAIL, ...}; + ... + Intercom('boot', $VAR); + - pattern: | + $VAR = {..., user_id: $EMAIL, ...}; + ... + Intercom('boot', $VAR); + - pattern-not: | + window.intercomSettings = {..., user_hash: $USER_HASH, ...}; + - pattern-not: | + Intercom('boot', {..., user_hash: $USER_HASH, ...}); + - pattern-not: | + $VAR = {..., user_hash: $USER_HASH, ...}; + ... + Intercom('boot', $VAR); + message: Found an initialization of the Intercom Messenger that identifies a User, + but does not specify a `user_hash`. This configuration allows users to impersonate + one another. See the Intercom Identity Verification docs for more context https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile + languages: + - js + severity: WARNING + metadata: + category: security + subcategory: + - audit + cwe: + - 'CWE-287: Improper Authentication' + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + technology: + - intercom + references: + - https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + shortlink: https://sg.run/Eb5w + semgrep.dev: + rule: + r_id: 60237 + rv_id: 945842 + rule_id: QrU96W + version_id: nWTpzDk + url: https://semgrep.dev/playground/r/nWTpzDk/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + origin: community +- id: java.android.security.exported_activity.exported_activity + patterns: + - pattern-not-inside: + - pattern-inside: " \n" + - pattern-either: + - pattern: | + + - pattern: | + ... /> + message: The application exports an activity. Any application on the device can + launch the exported activity which may compromise the integrity of your application + or its data. Ensure that any exported activities do not have privileged access + to your application's control plane. + languages: + - generic + severity: WARNING + paths: + exclude: + - sources/ + - classes3.dex + - '*.so' + include: + - '*AndroidManifest.xml' + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-926: Improper Export of Android Application Components' + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + owasp: + - A5:2021 Security Misconfiguration + technology: + - Android + references: + - https://cwe.mitre.org/data/definitions/926.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity + shortlink: https://sg.run/eNGZ + semgrep.dev: + rule: + r_id: 60632 + rv_id: 945629 + rule_id: v8Ul0r + version_id: rxT6rGR + url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity + origin: community +- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + patterns: + - pattern: | + RUN sudo ... + message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can + help reduce the potential impact of configuration errors and security vulnerabilities. + metadata: + category: security + technology: + - dockerfile + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/250.html + - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + shortlink: https://sg.run/80Q7 + semgrep.dev: + rule: + r_id: 66384 + rv_id: 1262661 + rule_id: kxUlx1 + version_id: pZT03zY + url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + origin: community + languages: + - dockerfile + severity: WARNING +- id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + message: Potentially sensitive data was observed to be stored in UserDefaults, which + is not adequate protection of sensitive information. For data of a sensitive nature, + applications should leverage the Keychain. + severity: WARNING + metadata: + likelihood: LOW + impact: HIGH + confidence: MEDIUM + category: security + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + masvs: + - 'MASVS-STORAGE-1: The app securely stores sensitive data' + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html + - https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/ + subcategory: + - vuln + technology: + - ios + - macos + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + shortlink: https://sg.run/qvoO + semgrep.dev: + rule: + r_id: 66512 + rv_id: 1263696 + rule_id: KxUqoZ + version_id: 3ZT4Xy2 + url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + origin: community + languages: + - swift + options: + symbolic_propagation: true + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $KEY +- id: swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + message: Webviews were observed that explictly allow JavaScript in an WKWebview + to open windows automatically. Consider disabling this functionality if not required, + following the principle of least privelege. + severity: WARNING + metadata: + likelihood: LOW + impact: LOW + confidence: HIGH + category: security + cwe: + - 'CWE-272: Least Privilege Violation' + masvs: + - 'MASVS-PLATFORM-2: The app uses WebViews securely' + references: + - https://mas.owasp.org/MASVS/controls/MASVS-PLATFORM-2/ + - https://developer.apple.com/documentation/webkit/wkpreferences/1536573-javascriptcanopenwindowsautomati + subcategory: + - audit + technology: + - ios + - macos + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + shortlink: https://sg.run/YWLd + semgrep.dev: + rule: + r_id: 66514 + rv_id: 946637 + rule_id: lBUOZk + version_id: 9lTy1KE + url: https://semgrep.dev/playground/r/9lTy1KE/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows + origin: community + languages: + - swift + patterns: + - pattern: | + $P = WKPreferences() + ... + - pattern-either: + - patterns: + - pattern-inside: | + $P.JavaScriptCanOpenWindowsAutomatically = $FALSE + ... + $P.JavaScriptCanOpenWindowsAutomatically = $TRUE + - pattern-not-inside: | + ... + $P.JavaScriptCanOpenWindowsAutomatically = $TRUE + ... + $P.JavaScriptCanOpenWindowsAutomatically = $FALSE + - pattern: | + $P.JavaScriptCanOpenWindowsAutomatically = true + - metavariable-regex: + metavariable: $TRUE + regex: ^(true)$ + - metavariable-regex: + metavariable: $TRUE + regex: (.*(?!true)) + - patterns: + - pattern: | + $P.JavaScriptCanOpenWindowsAutomatically = true + - pattern-not-inside: | + ... + $P.JavaScriptCanOpenWindowsAutomatically = ... + ... + $P.JavaScriptCanOpenWindowsAutomatically = ... +- id: solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + message: $VAULT.getPoolTokens() call on a Balancer pool is not protected from the + read-only reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376 + - https://hackmd.io/@sentimentxyz/SJCySo1z2 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + shortlink: https://sg.run/803Q + semgrep.dev: + rule: + r_id: 67640 + rv_id: 946602 + rule_id: kxUl7x + version_id: e1T98xQ + url: https://semgrep.dev/playground/r/e1T98xQ/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens + origin: community + patterns: + - pattern-either: + - pattern: | + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + - metavariable-pattern: + metavariable: $RETURN + pattern-regex: .*uint256\[].* + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $RETURN = $VAULT.getPoolTokens(...); + ... + } + ... + } + - pattern-not: | + function $F(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + - pattern-not: | + function $F(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + - pattern-not-inside: | + contract LinearPool { + ... + } + - pattern-not-inside: | + contract ComposableStablePool { + ... + } + - pattern-not-inside: "contract BalancerQueries {\n ...\n} \n" + - pattern-not-inside: | + contract ManagedPool { + ... + } + - pattern-not-inside: "contract BaseWeightedPool {\n ...\n} \n" + - pattern-not-inside: | + contract ComposableStablePoolStorage { + ... + } + - pattern-not-inside: | + contract RecoveryModeHelper { + ... + } + - focus-metavariable: + - $VAULT + languages: + - solidity + severity: ERROR +- id: solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + message: $VAR.getRate() call on a Balancer pool is not protected from the read-only + reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://forum.balancer.fi/t/reentrancy-vulnerability-scope-expanded/4345 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + shortlink: https://sg.run/g9e5 + semgrep.dev: + rule: + r_id: 67641 + rv_id: 946603 + rule_id: wdUx3D + version_id: vdTGn2l + url: https://semgrep.dev/playground/r/vdTGn2l/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate + origin: community + patterns: + - pattern: | + function $F(...) { + ... + $VAR.getRate(); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + - pattern-not-inside: | + function _updateTokenRateCache(...) { + ... + } + - pattern-not-inside: | + contract PoolRecoveryHelper { + ... + } + - pattern-not-inside: | + contract ComposableStablePoolRates { + ... + } + - pattern-not-inside: | + contract WeightedPoolProtocolFees { + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $VAR.getRate(); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + VaultReentrancyLib.ensureNotInVaultContext(...); + ... + } + ... + function $F(...) { + ... + $VAR.getRate(); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $VAR.getRate(); + ... + $CHECKFUNC(...); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAULT.manageUserBalance(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $VAR.getRate(); + ... + } + ... + } + - focus-metavariable: $VAR + languages: + - solidity + severity: ERROR +- id: solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + message: Function borrowFresh() in Compound performs state update after doTransferOut() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1509431646818234369 + - https://twitter.com/blocksecteam/status/1509466576848064512 + - https://slowmist.medium.com/another-day-another-reentrancy-attack-5cde10bbb2b4 + - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + shortlink: https://sg.run/4A19 + semgrep.dev: + rule: + r_id: 67644 + rv_id: 946606 + rule_id: eqUkx4 + version_id: nWTpz74 + url: https://semgrep.dev/playground/r/nWTpz74/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy + origin: community + patterns: + - pattern-inside: | + function borrowFresh(...) { + ... + } + - pattern-not-inside: | + accountBorrows[borrower].interestIndex = borrowIndex; + ... + - pattern: doTransferOut(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted + message: Function sweepToken is allowed to be called by anyone + metadata: + category: security + technology: + - solidity + cwe: 'CWE-284: Improper Access Control' + confidence: MEDIUM + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://medium.com/chainsecurity/trueusd-compound-vulnerability-bc5b696d29e2 + - https://chainsecurity.com/security-audit/compound-ctoken/ + - https://blog.openzeppelin.com/compound-comprehensive-protocol-audit/ + - https://etherscan.io/address/0xa035b9e130f2b1aedc733eefb1c67ba4c503491f + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted + shortlink: https://sg.run/P4Wv + semgrep.dev: + rule: + r_id: 67645 + rv_id: 946607 + rule_id: v8Uz2o + version_id: ExTg2nW + url: https://semgrep.dev/playground/r/ExTg2nW/solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted + origin: community + patterns: + - pattern-inside: | + function sweepToken(...) { + ... + } + - pattern-not-inside: | + function sweepToken(...) $M { + ... + } + - pattern: token.transfer(...); + - pattern-not-inside: | + require(msg.sender == admin, "..."); + ... + - pattern-not-inside: | + require(_msgSender() == admin, "..."); + ... + languages: + - solidity + severity: WARNING +- id: solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + message: $POOL.get_virtual_price() call on a Curve pool is not protected from the + read-only reentrancy. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://chainsecurity.com/heartbreaks-curve-lp-oracles/ + - https://chainsecurity.com/curve-lp-oracle-manipulation-post-mortem/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + shortlink: https://sg.run/Jk5P + semgrep.dev: + rule: + r_id: 67646 + rv_id: 946608 + rule_id: d8UGDL + version_id: 7ZTrQO3 + url: https://semgrep.dev/playground/r/7ZTrQO3/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy + origin: community + patterns: + - pattern: | + $POOL.get_virtual_price() + - pattern-not-inside: | + function $F(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + - pattern-not-inside: | + function $F(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + ... + function $F(...) { + ... + $CHECKFUNC(...); + ... + $POOL.get_virtual_price(); + ... + } + ... + } + - pattern-not-inside: | + contract $C { + ... + function $CHECKFUNC(...) { + ... + $VAR.withdraw_admin_fees(...); + ... + } + ... + function $F(...) { + ... + $POOL.get_virtual_price(); + ... + $CHECKFUNC(...); + ... + } + ... + } + languages: + - solidity + severity: ERROR +- id: solidity.security.encode-packed-collision.encode-packed-collision + message: abi.encodePacked hash collision with variable length arguments in $F() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-20: Improper Input Validation' + confidence: HIGH + likelihood: MEDIUM + impact: MEDIUM + subcategory: + - vuln + references: + - https://swcregistry.io/docs/SWC-133 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/solidity.security.encode-packed-collision.encode-packed-collision + shortlink: https://sg.run/Gr46 + semgrep.dev: + rule: + r_id: 67648 + rv_id: 946610 + rule_id: nJU47w + version_id: 8KTKjb1 + url: https://semgrep.dev/playground/r/8KTKjb1/solidity.security.encode-packed-collision.encode-packed-collision + origin: community + patterns: + - pattern-either: + - pattern-inside: | + function $F(..., bytes $A, ..., bytes $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., string $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., string $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., bytes $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., address[] $A, ..., address[] $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., uint256[] $A, ..., uint256[] $B, ...) public { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., bytes $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., string $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., bytes $A, ..., string $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., string $A, ..., bytes $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., address[] $A, ..., address[] $B, ...) external { + ... + } + - pattern-inside: | + function $F(..., uint256[] $A, ..., uint256[] $B, ...) external { + ... + } + - pattern-either: + - pattern: | + keccak256(abi.encodePacked(..., $A, $B, ...)) + - pattern: | + $X = abi.encodePacked(..., $A, $B, ...); + ... + keccak256($X); + languages: + - solidity + severity: ERROR +- id: solidity.security.erc677-reentrancy.erc677-reentrancy + message: ERC677 callAfterTransfer() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1509431646818234369 + - https://twitter.com/blocksecteam/status/1509466576848064512 + - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 + - https://explorer.fuse.io/address/0x5De15b5543c178C111915d6B8ae929Af01a8cC58 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc677-reentrancy.erc677-reentrancy + shortlink: https://sg.run/BXnR + semgrep.dev: + rule: + r_id: 67651 + rv_id: 946613 + rule_id: L1Ub0L + version_id: 3ZTOPdd + url: https://semgrep.dev/playground/r/3ZTOPdd/solidity.security.erc677-reentrancy.erc677-reentrancy + origin: community + patterns: + - pattern-inside: | + function transfer(...) { + ... + } + - pattern: callAfterTransfer(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom + message: Custom ERC721 implementation lacks access control checks in _transfer() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-284: Improper Access Control' + confidence: MEDIUM + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/BlockSecAlert/status/1516289618605654024 + - https://etherscan.io/address/0xf3821adaceb6500c0a202971aecf840a033f236b + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom + shortlink: https://sg.run/D17G + semgrep.dev: + rule: + r_id: 67652 + rv_id: 946614 + rule_id: 8GUkbo + version_id: 44TZko3 + url: https://semgrep.dev/playground/r/44TZko3/solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom + origin: community + patterns: + - pattern-inside: | + function _transfer(...) { + ... + } + - pattern-inside: | + require(prevOwnership.addr == $FROM, ...); + ... + - pattern-not-inside: | + (<... _msgSender() == $FROM ...>); + ... + - pattern-not-inside: | + (<... _msgSender() == $PREV.$ADDR ...>); + ... + - pattern-not-inside: | + (<... msg.sender == $FROM ...>); + ... + - pattern-not-inside: | + require(_isApprovedOrOwner(...), ...); + ... + - pattern: _approve(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.erc721-reentrancy.erc721-reentrancy + message: ERC721 onERC721Received() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://blocksecteam.medium.com/when-safemint-becomes-unsafe-lessons-from-the-hypebears-security-incident-2965209bda2a + - https://etherscan.io/address/0x14e0a1f310e2b7e321c91f58847e98b8c802f6ef + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc721-reentrancy.erc721-reentrancy + shortlink: https://sg.run/WBoE + semgrep.dev: + rule: + r_id: 67653 + rv_id: 946615 + rule_id: gxU2qG + version_id: PkTQZYA + url: https://semgrep.dev/playground/r/PkTQZYA/solidity.security.erc721-reentrancy.erc721-reentrancy + origin: community + patterns: + - pattern: _checkOnERC721Received(...) + languages: + - solidity + severity: WARNING +- id: solidity.security.erc777-reentrancy.erc777-reentrancy + message: ERC777 tokensReceived() reentrancy + metadata: + category: security + technology: + - solidity + cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://mirror.xyz/baconcoin.eth/LHaPiX38mnx8eJ2RVKNXHttHfweQMKNGmEnX4KUksk0 + - https://etherscan.io/address/0xf53f00f844b381963a47fde3325011566870b31f + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.erc777-reentrancy.erc777-reentrancy + shortlink: https://sg.run/0Jpw + semgrep.dev: + rule: + r_id: 67654 + rv_id: 946616 + rule_id: QrUrJj + version_id: JdTDyg1 + url: https://semgrep.dev/playground/r/JdTDyg1/solidity.security.erc777-reentrancy.erc777-reentrancy + origin: community + patterns: + - pattern: $X.tokensReceived(...); + languages: + - solidity + severity: WARNING +- id: solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + message: blockhash(block.number) and blockhash(block.number + N) always returns + 0. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-341: Predictable from Observable State' + confidence: HIGH + likelihood: LOW + impact: MEDIUM + subcategory: + - vuln + references: + - https://blog.positive.com/predicting-random-numbers-in-ethereum-smart-contracts-e5358c6b8620 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + shortlink: https://sg.run/qvPO + semgrep.dev: + rule: + r_id: 67656 + rv_id: 946618 + rule_id: 4bUPoB + version_id: GxTP7wj + url: https://semgrep.dev/playground/r/GxTP7wj/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash + origin: community + patterns: + - pattern-either: + - pattern: blockhash(block.number) + - pattern: blockhash(block.number + $N) + - pattern: blockhash(block.number * $N) + - pattern: block.blockhash(block.number) + - pattern: block.blockhash(block.number + $N) + - pattern: block.blockhash(block.number * $N) + severity: ERROR + languages: + - solidity +- id: solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + message: Keep3rV2.current() call has high data freshness, but it has low security, an + exploiter simply needs to manipulate 2 data points to be able to impact the feed. + metadata: + category: security + technology: + - solidity + cwe: 'CWE-682: Incorrect Calculation' + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/peckshield/status/1510232640338608131 + - https://twitter.com/FrankResearcher/status/1510239094777032713 + - https://twitter.com/larry0x/status/1510263618180464644 + - https://andrecronje.medium.com/keep3r-network-on-chain-oracle-price-feeds-3c67ed002a9 + - https://etherscan.io/address/0x210ac53b27f16e20a9aa7d16260f84693390258f + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + shortlink: https://sg.run/lkEo + semgrep.dev: + rule: + r_id: 67657 + rv_id: 946619 + rule_id: PeUrYv + version_id: RGTAgvQ + url: https://semgrep.dev/playground/r/RGTAgvQ/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation + origin: community + patterns: + - pattern: $KEEPER.current($TOKENIN, $AMOUNTIN, $TOKENOUT); + languages: + - solidity + severity: WARNING +- id: solidity.security.no-bidi-characters.no-bidi-characters + message: The code must not contain any of Unicode Direction Control Characters + metadata: + category: security + technology: + - solidity + cwe: 'CWE-837: Improper Enforcement of a Single, Unique Action' + confidence: HIGH + likelihood: LOW + impact: LOW + subcategory: + - audit + references: + - https://entethalliance.org/specs/ethtrust-sl/v1/#req-1-unicode-bdo + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.no-bidi-characters.no-bidi-characters + shortlink: https://sg.run/6DyK + semgrep.dev: + rule: + r_id: 67659 + rv_id: 946622 + rule_id: 5rUD6Z + version_id: DkTNp8K + url: https://semgrep.dev/playground/r/DkTNp8K/solidity.security.no-bidi-characters.no-bidi-characters + origin: community + patterns: + - pattern-either: + - pattern-regex: "\u202A" + - pattern-regex: "\u202B" + - pattern-regex: "\u202D" + - pattern-regex: "\u202E" + - pattern-regex: "\u2066" + - pattern-regex: "\u2067" + - pattern-regex: "\u2068" + - pattern-regex: "\u202C" + - pattern-regex: "\u2069" + languages: + - solidity + severity: WARNING +- id: solidity.security.no-slippage-check.no-slippage-check + message: No slippage check in a Uniswap v2/v3 trade + metadata: + category: security + technology: + - solidity + cwe: 'CWE-682: Incorrect Calculation' + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + subcategory: + - vuln + references: + - https://uniswapv3book.com/docs/milestone_3/slippage-protection/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.no-slippage-check.no-slippage-check + shortlink: https://sg.run/oO8X + semgrep.dev: + rule: + r_id: 67660 + rv_id: 946623 + rule_id: GdUE2p + version_id: WrTEoxy + url: https://semgrep.dev/playground/r/WrTEoxy/solidity.security.no-slippage-check.no-slippage-check + origin: community + patterns: + - pattern-either: + - pattern: $X.swapExactTokensForTokens($A, $LIMIT, $B, $C, $D) + - pattern: $X.swapExactTokensForTokensSupportingFeeOnTransferTokens($A, $LIMIT, + $B, $C, $D) + - pattern: $X.swapExactTokensForETH($A, $LIMIT, $B, $C, $D) + - pattern: $X.swapExactTokensForETHSupportingFeeOnTransferTokens($A, $LIMIT, $B, + $C, $D) + - pattern: $X.swapExactETHForTokens{$VALUE:...}($LIMIT, $A, $B, $C) + - pattern: $X.swapExactETHForTokensSupportingFeeOnTransferTokens{$VALUE:...}($LIMIT, + $A, $B, $C) + - pattern: $X.swapTokensForExactTokens($A, $LIMIT, $B, $C, $D) + - pattern: $X.swapTokensForExactETH($A, $LIMIT, $B, $C, $D) + - pattern: "function $FUNC(...) {\n ...\n $Y = $SWAPROUTER.ExactInputSingleParams({\n + \ tokenIn: $A, \n tokenOut: $B, \n fee: $C, \n recipient: $D, \n + \ deadline: $E, \n amountIn: $F, \n amountOutMinimum: $LIMIT, \n sqrtPriceLimitX96: + 0\n });\n ...\n $X.exactInputSingle($Y);\n ...\n}\n" + - pattern: | + $X.exactInputSingle($SWAPROUTER.ExactInputSingleParams({ + tokenIn: $A, + tokenOut: $B, + fee: $C, + recipient: $D, + deadline: $E, + amountIn: $F, + amountOutMinimum: $LIMIT, + sqrtPriceLimitX96: 0 + })); + - pattern: | + function $FUNC(...) { + ... + $Y = $SWAPROUTER.ExactOutputSingleParams({ + tokenIn: $A, + tokenOut: $B, + fee: $C, + recipient: $D, + deadline: $E, + amountOut: $F, + amountInMaximum: $LIMIT, + sqrtPriceLimitX96: 0 + }); + ... + $X.exactOutputSingle($Y); + ... + } + - pattern: | + $X.exactOutputSingle($SWAPROUTER.ExactOutputSingleParams({ + tokenIn: $A, + tokenOut: $B, + fee: $C, + recipient: $D, + deadline: $E, + amountOut: $F, + amountInMaximum: $LIMIT, + sqrtPriceLimitX96: 0 + })); + - pattern: $X.swap($RECIPIENT, $ZEROFORONE, $AMOUNTIN, $LIMIT, $DATA) + - metavariable-regex: + metavariable: $LIMIT + regex: ^(0)|(0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff)|(type\(uint(256)?\)\.max)|(uint(256)?\(-1)|(115792089237316195423570985008687907853269984665640564039457584007913129639935)|(2\s?\*\*\s?256\s?-\s?1)$ + languages: + - solidity + severity: ERROR +- id: solidity.security.proxy-storage-collision.proxy-storage-collision + message: Proxy declares a state var that may override a storage slot of the implementation + metadata: + category: security + technology: + - solidity + cwe: 'CWE-787: Out-of-bounds Write' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://blog.audius.co/article/audius-governance-takeover-post-mortem-7-23-22 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.proxy-storage-collision.proxy-storage-collision + shortlink: https://sg.run/2GXr + semgrep.dev: + rule: + r_id: 67663 + rv_id: 946626 + rule_id: BYU0EL + version_id: qkT4jqp + url: https://semgrep.dev/playground/r/qkT4jqp/solidity.security.proxy-storage-collision.proxy-storage-collision + origin: community + patterns: + - pattern-either: + - pattern: | + contract $CONTRACT is ..., $PROXY, ... { + ... + $TYPE $VAR; + ... + constructor(...) { + ... + } + ... + } + - pattern: | + contract $CONTRACT is ..., $PROXY, ... { + ... + $TYPE $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE immutable $VAR; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE immutable $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - pattern-not: | + contract $CONTRACT is ..., $PROXY, ... { + $TYPE constant $VAR = ...; + ... + constructor(...) { + ... + } + ... + } + - metavariable-regex: + metavariable: $CONTRACT + regex: ^(?!AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy).*$ + - metavariable-regex: + metavariable: $PROXY + regex: (UpgradeabilityProxy|AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy|TransparentUpgradeableProxy|ERC1967Proxy) + - focus-metavariable: $PROXY + languages: + - solidity + severity: WARNING +- id: solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + message: transferFrom() can steal allowance of other accounts + metadata: + category: security + technology: + - solidity + cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://medium.com/immunefi/redacted-cartel-custom-approval-logic-bugfix-review-9b2d039ca2c5 + - https://etherscan.io/address/0x186E55C0BebD2f69348d94C4A27556d93C5Bd36C + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + shortlink: https://sg.run/XDzj + semgrep.dev: + rule: + r_id: 67664 + rv_id: 946627 + rule_id: DbU0Qb + version_id: l4Tx9Px + url: https://semgrep.dev/playground/r/l4Tx9Px/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug + origin: community + patterns: + - pattern-inside: | + function transferFrom(...) { + ... + } + - pattern: _approve(..., allowance(sender, recipient).sub(amount, ...), ...); + languages: + - solidity + severity: ERROR +- id: solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + message: setMultipleAllowances() is missing onlyOwner modifier + metadata: + category: security + technology: + - solidity + cwe: 'CWE-284: Improper Access Control' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/danielvf/status/1494317265835147272 + - https://etherscan.io/address/0x876b9ebd725d1fa0b879fcee12560a6453b51dc8 + - https://play.secdim.com/game/dapp/challenge/rigoownsol + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + shortlink: https://sg.run/jbZP + semgrep.dev: + rule: + r_id: 67665 + rv_id: 946628 + rule_id: WAUpbw + version_id: YDTvRP2 + url: https://semgrep.dev/playground/r/YDTvRP2/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control + origin: community + patterns: + - pattern: function setMultipleAllowances(...) {...} + - pattern-not: function setMultipleAllowances(...) onlyOwner {...} + languages: + - solidity + severity: ERROR +- id: solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control + message: Oracle update is not restricted in $F() + metadata: + category: security + technology: + - solidity + cwe: 'CWE-284: Improper Access Control' + confidence: MEDIUM + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + author: https://twitter.com/ArbazKiraak + references: + - https://medium.com/immunefi/sense-finance-access-control-issue-bugfix-review-32e0c806b1a0 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control + shortlink: https://sg.run/1521 + semgrep.dev: + rule: + r_id: 67666 + rv_id: 946629 + rule_id: 0oUbvd + version_id: 6xTxjKQ + url: https://semgrep.dev/playground/r/6xTxjKQ/solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control + origin: community + patterns: + - pattern-either: + - pattern-inside: | + function $F(...,$D $REQUEST,...) external { + ... + } + - pattern-inside: | + function $F(...,$D $REQUEST,...) public { + ... + } + - pattern-not-inside: | + function $F(...,$D $REQUEST,...) external onlyVault(...) { + ... + } + - patterns: + - pattern: _updateOracle($LASTBLOCK,...,...) + - pattern-not-inside: | + ... + if (msg.sender == $BALANCER) { ... } + ... + - pattern-not-inside: | + ... + require(msg.sender == address($BALANCER),...); + ... + - pattern-not-inside: | + ... + if (_msgSender() == $BALANCER) { ... } + ... + - pattern-not-inside: | + ... + require(_msgSender() == address($BALANCER),...); + ... + languages: + - solidity + severity: ERROR +- id: solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + message: A specially crafted calldata may be used to impersonate other accounts + metadata: + category: security + technology: + - solidity + cwe: 'CWE-20: Improper Input Validation' + confidence: HIGH + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://rekt.news/superfluid-rekt/ + - https://medium.com/superfluid-blog/08-02-22-exploit-post-mortem-15ff9c97cdd + - https://polygonscan.com/address/0x07711bb6dfbc99a1df1f2d7f57545a67519941e7 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + shortlink: https://sg.run/9KNy + semgrep.dev: + rule: + r_id: 67667 + rv_id: 946630 + rule_id: KxUqld + version_id: o5TZexb + url: https://semgrep.dev/playground/r/o5TZexb/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection + origin: community + patterns: + - pattern: $T.decodeCtx(ctx); + - pattern-not-inside: | + require($T.isCtxValid(...), "..."); + ... + languages: + - solidity + severity: ERROR +- id: solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug + message: Parameter "from" is checked at incorrect position in "_allowances" mapping + metadata: + category: security + technology: + - solidity + cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' + confidence: MEDIUM + likelihood: HIGH + impact: HIGH + subcategory: + - vuln + references: + - https://twitter.com/Mauricio_0218/status/1490082073096462340 + - https://etherscan.io/address/0xe38b72d6595fd3885d1d2f770aa23e94757f91a1 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug + shortlink: https://sg.run/yBWA + semgrep.dev: + rule: + r_id: 67668 + rv_id: 946631 + rule_id: qNUnN0 + version_id: zyTlkRL + url: https://semgrep.dev/playground/r/zyTlkRL/solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug + origin: community + patterns: + - pattern-inside: | + function $BURN(..., address $FROM, ...) { + ... + _burn($FROM, ...); + ... + } + - pattern-either: + - pattern: require(_allowances[$S][$FROM] >= $X, ...) + - pattern: require(allowance($S, $FROM) >= $X, ...) + languages: + - solidity + severity: ERROR +- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + message: Detected input from a HTTPServletRequest going into the environment variables + of an 'exec' command. Instead, call the command with user-supplied arguments + by using the overloaded method with one String array as the argument. `exec({"command", + "arg1", "arg2"})`. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); + - focus-metavariable: $ENV_ARGS + metadata: + category: security + technology: + - java + cwe: + - 'CWE-454: External Initialization of Trusted Variables or Data Stores' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: false + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + shortlink: https://sg.run/EJAB + semgrep.dev: + rule: + r_id: 70981 + rv_id: 1409391 + rule_id: nJULjy + version_id: LjTRL6W + url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + origin: community +- patterns: + - pattern-either: + - pattern: | + provisioner "remote-exec" { + ... + } + - pattern: | + provisioner "local-exec" { + ... + } + - pattern-inside: | + resource "aws_instance" "..." { + ... + } + id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + message: Provisioners are a tool of last resort and should be avoided where possible. + Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute + arbitrary shell commands by design. + languages: + - terraform + severity: WARNING + metadata: + category: security + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command + Injection'')' + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + subcategory: + - audit + confidence: HIGH + likelihood: HIGH + impact: MEDIUM + technology: + - terraform + references: + - https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec + - https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + shortlink: https://sg.run/7EjQ + semgrep.dev: + rule: + r_id: 70982 + rv_id: 1263736 + rule_id: EwUxO1 + version_id: bZT53j1 + url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + origin: community +- id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + metadata: + category: security + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + technology: + - terraform + - aws + owasp: + - A05:2017 - Sensitive Data Exposure + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy + - https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + shortlink: https://sg.run/LWlY + semgrep.dev: + rule: + r_id: 70983 + rv_id: 1263748 + rule_id: 7KU3dr + version_id: 7ZTE346 + url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + origin: community + message: '`$POLICY` is missing a `condition` block which scopes users of this policy + to specific GitHub repositories. Without this, `$POLICY` is open to all users + on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub` + which scopes it to prevent this.' + languages: + - hcl + severity: WARNING + match: + where: + - metavariable: $IDENTIFIER + regex: .*oidc-provider/token\.actions\.githubusercontent\.com + all: + - inside: | + data "aws_iam_policy_document" $POLICY { + ... + } + - | + statement { + ... + principals { + ... + type = "Federated" + identifiers = [..., $IDENTIFIER, ...] + } + } + - not: | + statement { + ... + condition { + ... + variable = "token.actions.githubusercontent.com:sub" + } + } +- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + languages: + - clojure + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://xerces.apache.org/xerces2-j/features.html + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml + category: security + technology: + - clojure + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + shortlink: https://sg.run/v7An + semgrep.dev: + rule: + r_id: 71533 + rv_id: 1262608 + rule_id: bwU3Gj + version_id: WrTqKyD + url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + origin: community + message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. + Without prohibiting external entity declarations, this is vulnerable to XML external + entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern-inside: | + (ns ... (:require [clojure.xml :as ...])) + ... + - pattern-either: + - pattern-inside: | + (def ... ... ( ... )) + - pattern-inside: | + (defn ... ... ( ... )) + - pattern-either: + - pattern: (clojure.xml/parse $INPUT) + - patterns: + - pattern-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) + - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" + false) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ...) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ...) +- id: clojure.lang.security.use-of-sha1.use-of-sha1 + languages: + - clojure + severity: WARNING + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-328: Use of Weak Hash' + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/dvwX + semgrep.dev: + rule: + r_id: 71534 + rv_id: 1262610 + rule_id: NbUy12 + version_id: K3TKk7E + url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 + origin: community + patterns: + - pattern-either: + - pattern: (MessageDigest/getInstance $ALGO) + - pattern: (java.security.MessageDigest/getInstance $ALGO) + - metavariable-regex: + metavariable: $ALGO + regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) +- id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs + languages: + - generic + severity: WARNING + message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose + your application and its users to compromised code. SRIs allow you to consume + specific versions of content where if even a single byte is compromised, the resource + will not be loaded. Add an integrity attribute to your + - pattern-not: + paths: + include: + - '*.component' + - '*.page' +- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + languages: + - generic + severity: INFO + message: Visualforce Pages must have the cspHeader attribute set to true. This attribute + is available in API version 55 or higher. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + shortlink: https://sg.run/yoj8 + semgrep.dev: + rule: + r_id: 72424 + rv_id: 1262907 + rule_id: DbUj7d + version_id: RGT0L0r + url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + origin: community + patterns: + - pattern: ... + - pattern-not: ... + - pattern-not: ...... + - pattern-not: ...... + paths: + include: + - '*.page' +- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + languages: + - generic + severity: WARNING + message: Visualforce Pages must use API version 55 or higher for required use of + the cspHeader attribute set to true. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + shortlink: https://sg.run/rWr6 + semgrep.dev: + rule: + r_id: 72425 + rv_id: 1262908 + rule_id: WAUwJW + version_id: A8Tgdgn + url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + origin: community + patterns: + - pattern-inside: + - pattern-either: + - pattern-regex: '[>][0-9].[0-9][<]' + - pattern-regex: '[>][1-4][0-9].[0-9][<]' + - pattern-regex: '[>][5][0-4].[0-9][<]' + paths: + include: + - '*.page-meta.xml' +- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret + languages: + - python + message: The Django secret key is used as salt in HashIDs. The HashID mechanism + is not secure. By observing sufficient HashIDs, the salt used to construct them + can be recovered. This means the Django secret key can be obtained by attackers, + through the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - django + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret + shortlink: https://sg.run/bxeZ + semgrep.dev: + rule: + r_id: 72426 + rv_id: 946163 + rule_id: 0oUXqy + version_id: 0bT15nn + url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) + - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) + severity: ERROR +- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + languages: + - python + message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is + not secure. By observing sufficient HashIDs, the salt used to construct them can + be recovered. This means the Flask secret key can be obtained by attackers, through + the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - flask + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + shortlink: https://sg.run/N0Rx + semgrep.dev: + rule: + r_id: 72427 + rv_id: 946220 + rule_id: KxUX3z + version_id: 0bT15Px + url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) + - patterns: + - pattern-inside: | + $APP = flask.Flask(...) + ... + - pattern-either: + - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) + severity: ERROR +- id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + references: + - https://docs.python.org/3/library/xml.html + - https://github.com/tiran/defusedxml + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + shortlink: https://sg.run/n3jG + semgrep.dev: + rule: + r_id: 72436 + rv_id: 1263541 + rule_id: X5Uqnx + version_id: vdT06ER + url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + origin: community + message: The native Python `xml` library is vulnerable to XML External Entity (XXE) + attacks. These attacks can leak confidential data and "XML bombs" can cause denial + of service. Do not use this library to parse untrusted input. Instead the Python + documentation recommends using `defusedxml`. + languages: + - python + severity: ERROR + patterns: + - pattern: xml.etree.ElementTree.parse($...ARGS) + - pattern-not: xml.etree.ElementTree.parse("...") + fix: defusedxml.etree.ElementTree.parse($...ARGS) +- id: php.lang.security.tainted-exec.tainted-exec + mode: taint + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + pattern-sinks: + - pattern: exec(...) + - pattern: system(...) + - pattern: popen(...) + - pattern: passthru(...) + - pattern: shell_exec(...) + - pattern: pcntl_exec(...) + - pattern: proc_open(...) + pattern-sanitizers: + - pattern: escapeshellarg(...) + message: Executing non-constant commands. This can lead to command injection. You + should use `escapeshellarg()` when using command. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + references: + - https://www.stackhawk.com/blog/php-command-injection/ + - https://brightsec.com/blog/code-injection-php/ + - https://www.acunetix.com/websitesecurity/php-security-2/ + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec + shortlink: https://sg.run/JAkP + semgrep.dev: + rule: + r_id: 73146 + rv_id: 1263300 + rule_id: 9AUw06 + version_id: BjTkZ4y + url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec + origin: community + languages: + - php + severity: ERROR +- id: php.lang.security.injection.tainted-session.tainted-session + severity: WARNING + message: Session key based on user input risks session poisoning. The user can determine + the key used for the session, and thus write any session variable. Session variables + are typically trusted to be set only by the application, and manipulating the + session can result in access control issues. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-284: Improper Access Control' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://en.wikipedia.org/wiki/Session_poisoning + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session + shortlink: https://sg.run/bxNp + semgrep.dev: + rule: + r_id: 73470 + rv_id: 1263289 + rule_id: 4bUdoP + version_id: 8KT5rPE + url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $A . $B + - pattern: bin2hex(...) + - pattern: crc32(...) + - pattern: crypt(...) + - pattern: filter_input(...) + - pattern: filter_var(...) + - pattern: hash(...) + - pattern: md5(...) + - pattern: preg_filter(...) + - pattern: preg_grep(...) + - pattern: preg_match_all(...) + - pattern: sha1(...) + - pattern: sprintf(...) + - pattern: str_contains(...) + - pattern: str_ends_with(...) + - pattern: str_starts_with(...) + - pattern: strcasecmp(...) + - pattern: strchr(...) + - pattern: stripos(...) + - pattern: stristr(...) + - pattern: strnatcasecmp(...) + - pattern: strnatcmp(...) + - pattern: strncmp(...) + - pattern: strpbrk(...) + - pattern: strpos(...) + - pattern: strripos(...) + - pattern: strrpos(...) + - pattern: strspn(...) + - pattern: strstr(...) + - pattern: strtok(...) + - pattern: substr_compare(...) + - pattern: substr_count(...) + - pattern: vsprintf(...) + pattern-sinks: + - patterns: + - pattern-inside: $_SESSION[$KEY] = $VAL; + - pattern: $KEY +- id: python.django.security.django-no-csrf-token.django-no-csrf-token + patterns: + - pattern: ... + - pattern-either: + - pattern: | +
...
+ - pattern: | +
...
+ - pattern: | +
...
+ - metavariable-regex: + metavariable: $METHOD + regex: (?i)(post|put|delete|patch) + - pattern-not-inside: ...{% csrf_token %}... + - pattern-not-inside: ...{{ $VAR.csrf_token }}... + message: Manually-created forms in django templates should specify a csrf_token + to prevent CSRF attacks. + languages: + - generic + severity: WARNING + metadata: + category: security + cwe: 'CWE-352: Cross-Site Request Forgery (CSRF)' + references: + - https://docs.djangoproject.com/en/4.2/howto/csrf/ + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + subcategory: + - audit + technology: + - django + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.django.security.django-no-csrf-token.django-no-csrf-token + shortlink: https://sg.run/N0Bp + semgrep.dev: + rule: + r_id: 73471 + rv_id: 946160 + rule_id: PeUyYG + version_id: BjT1NRl + url: https://semgrep.dev/playground/r/BjT1NRl/python.django.security.django-no-csrf-token.django-no-csrf-token + origin: community + paths: + include: + - '*.html' +- id: python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-inside: | + if $FORM.is_valid(): + ... + - pattern-either: + - pattern: request.POST[...] + - pattern: request.POST.get(...) + message: Use $FORM.cleaned_data[] instead of request.POST[] after form.is_valid() + has been executed to only access sanitized data + languages: + - python + severity: WARNING + metadata: + category: security + cwe: 'CWE-20: Improper Input Validation' + references: + - https://docs.djangoproject.com/en/4.2/ref/forms/api/#accessing-clean-data + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + subcategory: + - audit + technology: + - django + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + shortlink: https://sg.run/kJn7 + semgrep.dev: + rule: + r_id: 73472 + rv_id: 946161 + rule_id: JDUjqx + version_id: DkTNpEJ + url: https://semgrep.dev/playground/r/DkTNpEJ/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + origin: community +- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + patterns: + - pattern: | + "*" + - pattern-inside: | + resources: $A + ... + - pattern-inside: | + verbs: $A + ... + - pattern-inside: | + - apiGroups: [""] + ... + - pattern-inside: | + apiVersion: rbac.authorization.k8s.io/v1 + ... + - pattern-inside: | + kind: ClusterRole + ... + message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. + Attaching excessive permissions to a ClusterRole associated with the core namespace + allows the V1 API to perform arbitrary actions on arbitrary resources attached + to the cluster. Prefer explicit allowlists of verbs/resources when configuring + the core API namespace. ' + languages: + - yaml + severity: WARNING + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole + - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups + category: security + technology: + - kubernetes + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + shortlink: https://sg.run/x6Dz + semgrep.dev: + rule: + r_id: 73474 + rv_id: 1263935 + rule_id: GdUR2A + version_id: 9lT4bw7 + url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + origin: community +- id: ocaml.lang.security.unsafe.ocamllint-unsafe + pattern-either: + - pattern: $X.unsafe_get + - pattern: $X.unsafe_set + - pattern: $X.unsafe_to_string + - pattern: $X.unsafe_of_string + - pattern: $X.unsafe_blit + - pattern: $X.unsafe_blit_string + - pattern: $X.unsafe_fill + - pattern: $X.unsafe_to_string + - pattern: $X.unsafe_getenv + - pattern: $X.unsafe_environment + - pattern: $X.unsafe_chr + - pattern: $X.unsafe_of_int + - pattern: $X.unsafe_output + - pattern: $X.unsafe_output_string + - pattern: $X.unsafe_read + - pattern: $X.unsafe_recv + - pattern: $X.unsafe_recvfrom + - pattern: $X.unsafe_send + - pattern: $X.unsafe_sendto + - pattern: $X.unsafe_set + - pattern: $X.unsafe_set_int16 + - pattern: $X.unsafe_set_int32 + - pattern: $X.unsafe_set_int64 + - pattern: $X.unsafe_set_int8 + - pattern: $X.unsafe_set_uint16_ne + - pattern: $X.unsafe_set_uint8 + - pattern: $X.unsafe_single_write + - pattern: $X.unsafe_string + - pattern: $X.unsafe_sub + - pattern: $X.unsafe_write + message: Unsafe functions do not perform boundary checks or have other side effects, + use with care. + languages: + - ocaml + severity: WARNING + metadata: + category: security + references: + - https://v2.ocaml.org/api/Bigarray.Array1.html#VALunsafe_get + - https://v2.ocaml.org/api/Bytes.html#VALunsafe_to_string + technology: + - ocaml + cwe: 'CWE-242: Use of Inherently Dangerous Function (4.12)' + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + subcategory: + - audit + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/ocaml.lang.security.unsafe.ocamllint-unsafe + shortlink: https://sg.run/d8K80 + semgrep.dev: + rule: + r_id: 92978 + rv_id: 945981 + rule_id: 6JUvjv6 + version_id: zyTlkwv + url: https://semgrep.dev/playground/r/zyTlkwv/ocaml.lang.security.unsafe.ocamllint-unsafe + origin: community +- id: python.fastapi.security.wildcard-cors.wildcard-cors + languages: + - python + message: CORS policy allows any origin (using wildcard '*'). This is insecure and + should be avoided. + mode: taint + pattern-sources: + - pattern: '[..., "*", ...]' + pattern-sinks: + - patterns: + - pattern: | + $APP.add_middleware( + CORSMiddleware, + allow_origins=$ORIGIN, + ...); + - focus-metavariable: $ORIGIN + severity: WARNING + metadata: + cwe: + - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - python + - fastapi + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + - https://cwe.mitre.org/data/definitions/942.html + likelihood: HIGH + impact: LOW + confidence: MEDIUM + vulnerability_class: + - Configuration + subcategory: + - vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors + shortlink: https://sg.run/KxApY + semgrep.dev: + rule: + r_id: 112311 + rv_id: 1263413 + rule_id: lBU4JQ3 + version_id: A8Tgd1R + url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors + origin: community +- id: go.lang.security.injection.open-redirect.open-redirect + languages: + - go + severity: WARNING + message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This + can lead to open redirect vulnerabilities, potentially allowing attackers to redirect + users to malicious web sites. It is recommend where possible to not allow user-input + to craft the redirect URL. When user-input is necessary to craft the request, + it is recommended to follow OWASP best practices to restrict the URL to domains + in an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + references: + - https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html + category: security + technology: + - go + confidence: HIGH + description: An HTTP redirect was found to be crafted from user-input leading + to an open redirect vulnerability + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect + shortlink: https://sg.run/2ZW45 + semgrep.dev: + rule: + r_id: 113619 + rv_id: 945608 + rule_id: DbU6RlN + version_id: GxTP7J7 + url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern: http.Redirect($W, $REQ, $URL, ...) + - focus-metavariable: $URL +- id: php.lang.security.base-convert-loses-precision.base-convert-loses-precision + message: The function base_convert uses 64-bit numbers internally, and does not + correctly convert large numbers. It is not suitable for random tokens such as + those used for session tokens or CSRF tokens. + metadata: + references: + - https://www.php.net/base_convert + - https://www.sjoerdlangkemper.nl/2017/03/15/dont-use-base-convert-on-random-tokens/ + category: security + technology: + - php + cwe: + - 'CWE-190: Integer Overflow or Wraparound' + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/php.lang.security.base-convert-loses-precision.base-convert-loses-precision + shortlink: https://sg.run/kxpGo + semgrep.dev: + rule: + r_id: 115928 + rv_id: 945988 + rule_id: 7KUgBAk + version_id: yeT0n4K + url: https://semgrep.dev/playground/r/yeT0n4K/php.lang.security.base-convert-loses-precision.base-convert-loses-precision + origin: community + languages: + - php + severity: WARNING + mode: taint + pattern-sources: + - pattern: hash(...) + - pattern: hash_hmac(...) + - pattern: sha1(...) + - pattern: md5(...) + - patterns: + - pattern: random_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + - patterns: + - pattern: openssl_random_pseudo_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + - patterns: + - pattern: $OBJ->get_random_bytes($N) + - metavariable-comparison: + metavariable: $N + comparison: $N > 7 + pattern-sinks: + - pattern: base_convert(...) + pattern-sanitizers: + - patterns: + - pattern: substr(..., $LENGTH) + - metavariable-comparison: + metavariable: $LENGTH + comparison: $LENGTH <= 7 +- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + message: Detected the decoding of a JWT token without a verify step. JWT tokens + must be verified before use, otherwise the token's integrity is unknown. This + means a malicious actor could forge a JWT token with any claims. Set 'verify' + to `true` before using the token. + severity: ERROR + metadata: + owasp: + - A05:2021 - Security Misconfiguration + - A07:2021 - Identification and Authentication Failures + - A02:2025 - Security Misconfiguration + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + - 'CWE-345: Insufficient Verification of Data Authenticity' + - 'CWE-347: Improper Verification of Cryptographic Signature' + category: security + subcategory: + - vuln + technology: + - jwt-simple + - jwt + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + references: + - https://www.npmjs.com/package/jwt-simple + - https://cwe.mitre.org/data/definitions/287 + - https://cwe.mitre.org/data/definitions/345 + - https://cwe.mitre.org/data/definitions/347 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Improper Authentication + source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + shortlink: https://sg.run/zdjod + semgrep.dev: + rule: + r_id: 120561 + rv_id: 1263191 + rule_id: r6UyNLy + version_id: 3ZT4Xxv + url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + origin: community + languages: + - javascript + - typescript + patterns: + - pattern-inside: | + $JWT = require('jwt-simple'); + ... + - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) + - metavariable-pattern: + metavariable: $NOVERIFY + patterns: + - pattern-either: + - pattern: | + true + - pattern: | + "..." +- id: php.lang.security.injection.printed-request.printed-request + mode: taint + message: '`Printing user input risks cross-site scripting vulnerability. You should + use `htmlentities()` when showing data to users.' + languages: + - php + severity: ERROR + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + pattern-sinks: + - pattern: print($...VARS); + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + fix: print(htmlentities($...VARS)); + metadata: + technology: + - php + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request + shortlink: https://sg.run/QrxEJ + semgrep.dev: + rule: + r_id: 128886 + rv_id: 1263284 + rule_id: KxUvRBw + version_id: ZRTKAk4 + url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request + origin: community +- id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + patterns: + - pattern-inside: | + &sessions.Options{ + ..., + SameSite: http.SameSiteNoneMode, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting + SameSite to Lax, Strict or Default for enhanced security. + metadata: + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://pkg.go.dev/github.com/gorilla/sessions#Options + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + shortlink: https://sg.run/x8Nwj + semgrep.dev: + rule: + r_id: 133074 + rv_id: 1262913 + rule_id: YGUpGd4 + version_id: K3TKkKB + url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + origin: community + fix-regex: + regex: (SameSite\s*:\s+)http.SameSiteNoneMode + replacement: \1http.SameSiteDefaultMode + severity: WARNING + languages: + - go +- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + languages: + - solidity + message: Missing check for 'from' and 'to' being the same before updating balances + could lead to incorrect balance manipulation on self-transfers. Include a check + to ensure 'from' and 'to' are not the same before updating balances to prevent + balance manipulation during self-transfers. + severity: ERROR + metadata: + category: security + technology: + - blockchain + - solidity + cwe: 'CWE-682: Incorrect Calculation' + subcategory: + - vuln + confidence: HIGH + likelihood: HIGH + impact: HIGH + owasp: + - A7:2021 Identification and Authentication Failures + references: + - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities + - https://x.com/shoucccc/status/1757777764646859121 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + shortlink: https://sg.run/Or6X7 + semgrep.dev: + rule: + r_id: 133075 + rv_id: 946620 + rule_id: 6JUv7Nz + version_id: A8TJzYz + url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + origin: community + patterns: + - pattern-either: + - pattern: | + _balances[$FROM] = $FROM_BALANCE - value; + - pattern: | + _balances[$TO] = $TO_BALANCE + value; + - pattern-not-inside: | + if ($FROM != $TO) { + ... + _balances[$FROM] = $FROM_BALANCE - value; + ... + _balances[$TO] = $TO_BALANCE + value; + ... + } + - pattern-inside: | + function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual { + ... + } +- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + languages: + - yaml + message: Basic authentication is considered weak and should be avoided. Use a different + authentication scheme, such of OAuth2, OpenID Connect, or mTLS. + severity: ERROR + patterns: + - pattern-inside: | + openapi: $VERSION + ... + components: + ... + securitySchemes: + ... + $SCHEME: + ... + - metavariable-regex: + metavariable: $VERSION + regex: 3.* + - pattern: | + type: http + ... + scheme: basic + metadata: + category: security + subcategory: + - vuln + technology: + - openapi + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + cwe: 'CWE-287: Improper Authentication' + owasp: + - A04:2021 Insecure Design + - A07:2021 Identification and Authentication Failures + references: + - https://cwe.mitre.org/data/definitions/287.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + shortlink: https://sg.run/v8wNW + semgrep.dev: + rule: + r_id: 133077 + rv_id: 947072 + rule_id: zdUKgEX + version_id: 0bT1ErG + url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + origin: community +- id: python.twilio.security.twiml-injection.twiml-injection + languages: + - python + severity: WARNING + message: Using non-constant TwiML (Twilio Markup Language) argument when creating + a Twilio conversation could allow the injection of additional TwiML commands + metadata: + cwe: + - 'CWE-91: XML Injection' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - python + - twilio + - twiml + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + subcategory: + - vuln + references: + - https://codeberg.org/fennix/funjection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection + shortlink: https://sg.run/GdEEy + semgrep.dev: + rule: + r_id: 134692 + rv_id: 1263580 + rule_id: oqUgjj2 + version_id: kbTzGp1 + url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection + origin: community + mode: taint + pattern-sources: + - pattern: | + f"..." + - pattern: | + "..." % ... + - pattern: | + "...".format(...) + - patterns: + - pattern: $ARG + - pattern-inside: | + def $F(..., $ARG, ...): + ... + pattern-sanitizers: + - pattern: xml.sax.saxutils.escape(...) + - pattern: html.escape(...) + pattern-sinks: + - patterns: + - pattern: | + $CLIENT.calls.create(..., twiml=$SINK, ...) + - focus-metavariable: $SINK +- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + message: A secret is hard-coded in the application. Secrets stored in source code, + such as credentials, identifiers, and other types of sensitive data, can be leaked + and used by internal or external malicious actors. It is recommended to rotate + the secret and retrieve them from a secure secret vault or Hardware Security Module + (HSM), alternatively environment variables can be used if allowed by your company + policy. + severity: WARNING + metadata: + likelihood: LOW + impact: HIGH + confidence: MEDIUM + category: security + subcategory: + - vuln + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2020-top25: true + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + technology: + - secrets + vulnerability_class: + - Hard-coded Secrets + source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + shortlink: https://sg.run/qN29x + semgrep.dev: + rule: + r_id: 137856 + rv_id: 1263257 + rule_id: ReUD6Kg + version_id: DkTRbLX + url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + origin: community + languages: + - kotlin + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: '$PASS = env[...] ?: $VALUE' + - metavariable-regex: + metavariable: $PASS + regex: (password|pass|passwd|loginPassword) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^[A-Za-z0-9/+=]+$ + paths: + include: + - '*build.gradle.kts' +- id: generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + pattern-regex: (?:api_live(?:_[a-zA-Z]{2})?\.[a-zA-Z0-9-_]{11}\.[-_a-zA-Z0-9]{32}) + languages: + - regex + message: Onfido live API Token detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - secrets + - onfido + confidence: HIGH + references: + - https://documentation.onfido.com/api/latest/#api-tokens + subcategory: + - audit + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + shortlink: https://sg.run/lBoKD + semgrep.dev: + rule: + r_id: 141957 + rv_id: 945509 + rule_id: WAUW9q3 + version_id: A8TJzE2 + url: https://semgrep.dev/playground/r/A8TJzE2/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token + origin: community +- id: php.lang.security.injection.tainted-callable.tainted-callable + severity: WARNING + message: Callable based on user input risks remote code execution. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/language.types.callable.php + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable + shortlink: https://sg.run/YGb33 + semgrep.dev: + rule: + r_id: 141958 + rv_id: 1263285 + rule_id: 0oULBKK + version_id: nWT2L5x + url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + pattern-sinks: + - patterns: + - pattern: $CALLABLE + - pattern-either: + - pattern-inside: $ARRAYITERATOR->uasort($CALLABLE) + - pattern-inside: $ARRAYITERATOR->uksort($CALLABLE) + - pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...) + - pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...) + - pattern-inside: $EVLOOP->fork($CALLABLE, ...) + - pattern-inside: $EVLOOP->idle($CALLABLE, ...) + - pattern-inside: $EVLOOP->prepare($CALLABLE, ...) + - pattern-inside: $EVWATCHER->setCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE) + - pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE) + - pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE) + - pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE) + - pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE) + - pattern-inside: $SQLITE3->setAuthorizer($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE) + - pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...) + - pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...) + - pattern-inside: apcu_entry($KEY, $CALLABLE, ...) + - pattern-inside: array_filter($ARRAY, $CALLABLE, ...) + - pattern-inside: array_map($CALLABLE, ...) + - pattern-inside: array_reduce($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk($ARRAY, $CALLABLE, ...) + - pattern-inside: call_user_func_array($CALLABLE, ...) + - pattern-inside: call_user_func($CALLABLE, ...) + - pattern-inside: Closure::fromCallable($CALLABLE) + - pattern-inside: createCollation($NAME, $CALLABLE) + - pattern-inside: eio_grp($CALLABLE, ...) + - pattern-inside: eio_nop($PRI, $CALLABLE, ...) + - pattern-inside: eio_sync($PRI, $CALLABLE, ...) + - pattern-inside: EvPrepare::createStopped($CALLABLE, ...) + - pattern-inside: fann_set_callback($ANN, $CALLABLE) + - pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...) + - pattern-inside: forward_static_call_array($CALLABLE, ...) + - pattern-inside: forward_static_call($CALLABLE, ...) + - pattern-inside: header_register_callback($CALLABLE) + - pattern-inside: ibase_set_event_handler($CALLABLE, ...) + - pattern-inside: IntlChar::enumCharTypes($CALLABLE) + - pattern-inside: iterator_apply($ITERATOR, $CALLABLE) + - pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE) + - pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...) + - pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new EvCheck($CALLABLE, ...) + - pattern-inside: new EventHttpRequest($CALLABLE, ...) + - pattern-inside: new EvFork($CALLABLE, ...) + - pattern-inside: new EvIdle($CALLABLE, ...) + - pattern-inside: new Fiber($CALLABLE) + - pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...) + - pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new Zookeeper($HOST, $CALLABLE, ...) + - pattern-inside: ob_start($CALLABLE, ...) + - pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE) + - pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE) + - pattern-inside: readline_completion_function($CALLABLE) + - pattern-inside: register_shutdown_function($CALLABLE, ...) + - pattern-inside: register_tick_function($CALLABLE, ...) + - pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE) + - pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...) + - pattern-inside: set_error_handler($CALLABLE, ...) + - pattern-inside: set_exception_handler($CALLABLE) + - pattern-inside: setAuthorizer($CALLABLE) + - pattern-inside: spl_autoload_register($CALLABLE, ...) + - pattern-inside: uasort($ARRAY, $CALLABLE) + - pattern-inside: uksort($ARRAY, $CALLABLE) + - pattern-inside: usort($ARRAY, $CALLABLE) + - pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_default_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE) + - pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE) + - pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...) +- id: dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + message: The Dockerfile(image) mounts docker.sock to the container which may allow + an attacker already inside of the container to escape container and execute arbitrary + commands on the host machine. + languages: + - dockerfile + - yaml + severity: ERROR + metadata: + cwe: + - 'CWE-862: Missing Authorization' + - 'CWE-269: Improper Privilege Management' + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - audit + technology: + - dockerfile + category: security + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html + - https://redfoxsec.com/blog/insecure-volume-mounts-in-docker/ + - https://blog.quarkslab.com/why-is-exposing-the-docker-socket-a-really-bad-idea.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + shortlink: https://sg.run/10AAQ + semgrep.dev: + rule: + r_id: 146566 + rv_id: 945266 + rule_id: oqUgAAk + version_id: WrTEoEq + url: https://semgrep.dev/playground/r/WrTEoEq/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount + origin: community + pattern-either: + - patterns: + - pattern: VOLUME $X + - metavariable-regex: + metavariable: $X + regex: /var/run/docker.sock + - patterns: + - pattern-regex: '- "/var/run/docker.sock:.*"' + - pattern-inside: | + volumes: + ... +- id: go.lang.security.reverseproxy-director.reverseproxy-director + message: ReverseProxy can remove headers added by Director. Consider using ReverseProxy.Rewrite + instead of ReverseProxy.Director. + languages: + - go + severity: WARNING + patterns: + - pattern-inside: | + import "net/http/httputil" + ... + - pattern-either: + - pattern: $PROXY.Director = $FUNC + - patterns: + - pattern-inside: | + httputil.ReverseProxy{ + ... + } + - pattern: | + Director: $FUNC + metadata: + cwe: + - 'CWE-115: Misinterpretation of Input' + category: security + subcategory: + - audit + technology: + - go + confidence: MEDIUM + likelihood: LOW + impact: LOW + references: + - https://github.com/golang/go/issues/50580 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.lang.security.reverseproxy-director.reverseproxy-director + shortlink: https://sg.run/9AYYR + semgrep.dev: + rule: + r_id: 146567 + rv_id: 945612 + rule_id: zdUKzzA + version_id: DkTNpvx + url: https://semgrep.dev/playground/r/DkTNpvx/go.lang.security.reverseproxy-director.reverseproxy-director + origin: community +- id: javascript.node-crypto.security.aead-no-final.aead-no-final + message: The 'final' call of a Decipher object checks the authentication tag in + a mode for authenticated encryption. Failing to call 'final' will invalidate all + integrity guarantees of the released ciphertext. + metadata: + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final + shortlink: https://sg.run/r6EEA + semgrep.dev: + rule: + r_id: 146569 + rv_id: 1263222 + rule_id: 2ZUz884 + version_id: zyTb2X0 + url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.update(...) + - pattern-not-inside: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.final(...) + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ +- id: javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + message: The deprecated functions 'createCipher' and 'createDecipher' generate the + same initialization vector every time. For counter modes such as CTR, GCM, or + CCM this leads to break of both confidentiality and integrity, if the key is used + more than once. Other modes are still affected in their strength, though they're + not completely broken. Use 'createCipheriv' or 'createDecipheriv' instead. + metadata: + cwe: + - 'CWE-1204: Generation of Weak Initialization Vector (IV)' + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://nodejs.org/api/crypto.html#cryptocreatecipheralgorithm-password-options + - https://nodejs.org/api/crypto.html#cryptocreatedecipheralgorithm-password-options + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + shortlink: https://sg.run/bw33r + semgrep.dev: + rule: + r_id: 146570 + rv_id: 945898 + rule_id: X5UQRR7 + version_id: ZRT3510 + url: https://semgrep.dev/playground/r/ZRT3510/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-either: + - pattern: | + $CRYPTO.createCipher(...) + - pattern: | + $CRYPTO.createDecipher(...) +- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode + of operation is missing an expected authentication tag length. If the expected + authentication tag length is not specified or otherwise checked, the application + might be tricked into verifying a shorter-than-expected authentication tag. This + can be abused by an attacker to spoof ciphertexts or recover the implicit authentication + key of GCM, allowing arbitrary forgeries. + metadata: + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ + - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + shortlink: https://sg.run/NbGG1 + semgrep.dev: + rule: + r_id: 146571 + rv_id: 1263223 + rule_id: j2UgPP3 + version_id: pZT03qd + url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + $CRYPTO.createDecipheriv('$ALGO', $KEY, $IV) + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm)$ +- id: php.lang.security.injection.tainted-exec.tainted-exec + languages: + - php + severity: WARNING + message: User input is passed to a function that executes a shell command. This + can lead to remote code execution. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec + shortlink: https://sg.run/kxEEz + semgrep.dev: + rule: + r_id: 146572 + rv_id: 1263286 + rule_id: 10UOGG5 + version_id: ExTExyR + url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: escapeshellcmd(...) + - pattern: escapeshellarg(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: exec(...) + - pattern: system(...) + - pattern: passthru(...) + - patterns: + - pattern: proc_open(...) + - pattern-not: proc_open([...], ...) + - pattern: popen(...) + - pattern: expect_popen(...) + - pattern: shell_exec(...) + - pattern: | + `...` +- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + languages: + - yaml + message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method: + $METHOD $PATH. This Action configuration will enable the ''Always Allow'' option + for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk + of a user selecting the ''Always Allow'' button is that the agent could perform + unintended actions on behalf of the user. When working with sensitive functionality, + it is always best to include a Human In The Loop (HITL) type of control. Consider + the trade-off between security and user friction and then make a risk-based decision + about this function.' + severity: WARNING + pattern-either: + - pattern-inside: | + post: + ... + x-openai-isConsequential: false + - pattern-inside: | + put: + ... + x-openai-isConsequential: false + - pattern-inside: | + patch: + ... + x-openai-isConsequential: false + - pattern-inside: | + delete: + ... + x-openai-isConsequential: false + metadata: + category: security + subcategory: + - audit + technology: + - openapi + - openai + likelihood: HIGH + impact: HIGH + confidence: HIGH + cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' + owasp: + - A04:2021 Insecure Design + - LLM08:2023 - Excessive Agency + references: + - https://platform.openai.com/docs/actions/consequential-flag + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + shortlink: https://sg.run/x8EEP + semgrep.dev: + rule: + r_id: 146574 + rv_id: 947071 + rule_id: yyURooD + version_id: WrTEZN8 + url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + origin: community +- id: python.lang.security.insecure-uuid-version.insecure-uuid-version + patterns: + - pattern: uuid.uuid1(...) + message: Using UUID version 1 for UUID generation can lead to predictable UUIDs + based on system information (e.g., MAC address, timestamp). This may lead to security + risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better + randomness and security. + metadata: + references: + - https://www.landh.tech/blog/20230811-sandwich-attack/ + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.3.2 Insecure UUID Generation + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values + version: '4' + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version + shortlink: https://sg.run/BYBgW + semgrep.dev: + rule: + r_id: 148295 + rv_id: 1263539 + rule_id: kxUd1yD + version_id: O9Tpx97 + url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version + origin: community + languages: + - python + severity: WARNING + fix-regex: + regex: uuid1 + replacement: uuid4 +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + pattern-either: + - patterns: + - pattern-inside: | + import "crypto/sha256" + ... + - pattern-either: + - pattern: | + sha256.New224() + - pattern: | + sha256.Sum224(...) + - patterns: + - pattern-inside: | + import "golang.org/x/crypto/sha3" + ... + - pattern-either: + - pattern: | + sha3.New224() + - pattern: | + sha3.Sum224(...) + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + category: security + technology: + - go + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + shortlink: https://sg.run/ReJwY + semgrep.dev: + rule: + r_id: 151749 + rv_id: 1262925 + rule_id: GdUvElR + version_id: 9lT4b4w + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + origin: community +- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + shortlink: https://sg.run/Ab2KQ + semgrep.dev: + rule: + r_id: 151750 + rv_id: 1263017 + rule_id: ReUDGEz + version_id: YDTZewo + url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + origin: community + pattern-either: + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) + - patterns: + - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: php.lang.security.audit.sha224-hash.sha224-hash + pattern-either: + - pattern: hash('sha224', ...); + - pattern: hash('sha512/224', ...); + - pattern: hash('sha3-224', ...); + - pattern: hash_hmac('sha224', ...); + - pattern: hash_hmac('sha512/224', ...); + - pattern: hash_hmac('sha3-224', ...); + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - php + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/BYXqv + semgrep.dev: + rule: + r_id: 151751 + rv_id: 1263275 + rule_id: AbU97EA + version_id: bZT53Jo + url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - php + severity: WARNING +- id: python.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/Db1Yv + semgrep.dev: + rule: + r_id: 151752 + rv_id: 1263511 + rule_id: BYUX0y9 + version_id: 5PTo1QL + url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: hashlib.sha224(...) + - pattern: hashlib.sha3_224(...) +- id: ruby.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/WABbo + semgrep.dev: + rule: + r_id: 151753 + rv_id: 1263592 + rule_id: DbU60wQ + version_id: 8KT5rRY + url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - ruby + severity: WARNING + pattern-either: + - pattern: Digest::SHA224.$FUNC + - pattern: OpenSSL::Digest::SHA224.$FUNC + - pattern: SHA3::Digest::SHA224(...) + - patterns: + - pattern-either: + - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) + - pattern: OpenSSL::HMAC.digest("$ALGO", ...) + - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") + - pattern: OpenSSL::Digest.digest("$ALGO", ...) + - pattern: OpenSSL::Digest.new("$ALGO", ...) + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + patterns: + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + database_version = "$DB" + ... + } + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = $VALUE + ... + } + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" + ... + } + ... + } + - metavariable-regex: + metavariable: $DB + regex: .*(MYSQL|POSTGRES).* + - focus-metavariable: $VALUE + fix: | + "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" + message: Ensure all Cloud SQL database instance require incoming connections to + use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + shortlink: https://sg.run/WANR2 + semgrep.dev: + rule: + r_id: 153509 + rv_id: 1263874 + rule_id: 5rUdGAz + version_id: 2KTv22E + url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + patterns: + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + database_version = "$DB" + ... + } + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = $VALUE + ... + } + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = "ENCRYPTED_ONLY" + ... + } + ... + } + - metavariable-regex: + metavariable: $DB + regex: .*(SQLSERVER).* + - focus-metavariable: $VALUE + fix: | + "ENCRYPTED_ONLY" + message: Ensure all Cloud SQL database instance require incoming connections to + use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value + that is supported. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + shortlink: https://sg.run/0o92j + semgrep.dev: + rule: + r_id: 153510 + rv_id: 1263875 + rule_id: GdUvX6A + version_id: X0Tzyyl + url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + origin: community + languages: + - hcl + severity: WARNING +- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + message: Function `flask.url_for` with `_external=True` argument will generate URLs + using the `Host` header of the HTTP request, which may lead to security risks + such as Host header injection + metadata: + cwe: + - 'CWE-673: External Influence of Sphere Definition' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/latest/api/#flask.url_for + - https://portswigger.net/kb/issues/00500300_host-header-injection + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + shortlink: https://sg.run/gEGeR + semgrep.dev: + rule: + r_id: 191541 + rv_id: 1263418 + rule_id: JDU5oql + version_id: K3TKk6n + url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-not: flask.url_for(..., _external=False, ...) + - pattern-not: url_for(..., _external=False, ...) + - pattern-either: + - pattern: flask.url_for(..., _external=$VAR, ...) + - pattern: url_for(..., _external=$VAR, ...) +- id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + languages: + - php + severity: WARNING + message: Detected usage of vulnerable functions with user input, which could lead + to SSRF vulnerabilities. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_POST[...] + - pattern: $_REQUEST[...] + - pattern: get_option(...) + - pattern: get_user_meta(...) + - pattern: get_query_var(...) + pattern-sinks: + - patterns: + - focus-metavariable: $URL + - pattern-either: + - pattern: wp_remote_get($URL, ...) + - pattern: wp_safe_remote_get($URL, ...) + - pattern: wp_safe_remote_request($URL, ...) + - pattern: wp_safe_remote_head($URL, ...) + - pattern: wp_oembed_get($URL, ...) + - pattern: vip_safe_wp_remote_get($URL, ...) + - pattern: wp_safe_remote_post($URL, ...) + paths: + include: + - '**/wp-content/plugins/**/*.php' + metadata: + cwe: 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: A10:2021 - Server-Side Request Forgery (SSRF) + category: security + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + subcategory: + - audit + technology: + - Wordpress Plugins + references: + - https://developer.wordpress.org/reference/functions/wp_safe_remote_get/ + - https://developer.wordpress.org/reference/functions/wp_remote_get/ + - https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/ + vulnerability_class: + - Server-Side Request Forgery (SSRF) + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + shortlink: https://sg.run/K3y06 + semgrep.dev: + rule: + r_id: 191611 + rv_id: 1039233 + rule_id: 6JUZyKX + version_id: JdTp6rq + url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + origin: community +- id: dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url + patterns: + - pattern: | + RUN ... $PIP install ... --extra-index-url ... + - metavariable-regex: + metavariable: $PIP + regex: pip|pip3 + message: 'When `--extra-index-url` is used in a `pip install` command, this is usually + meant to install a package from a package index other than the public one. However, + if a package is added with the same name to the public PyPi repository, and if + the version number is high enough, this package will be installed when building + this docker image. This package may be a malicious dependency. Such an attack + is called a dependency confusion attack. If using a private package index, prefer + to use `--index-url` if possible. ' + languages: + - dockerfile + severity: INFO + metadata: + references: + - https://pip.pypa.io/en/stable/cli/pip_install/#cmdoption-extra-index-url + - https://github.com/semgrep/semgrep-rules/issues/3032 + category: security + subcategory: + - audit + confidence: MEDIUM + impact: HIGH + likelihood: LOW + technology: + - docker + cwe: + - 'CWE-427: Uncontrolled Search Path Element' + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url + shortlink: https://sg.run/qk4p8 + semgrep.dev: + rule: + r_id: 197112 + rv_id: 1039209 + rule_id: pKUkLD3 + version_id: 1QTY5L3 + url: https://semgrep.dev/playground/r/1QTY5L3/dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url + origin: community +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action + with the name `discussion.yaml`. + paths: + include: + - '**/.github/workflows/discussion.yaml' + metadata: + category: security + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + shortlink: https://sg.run/JdYPZ + semgrep.dev: + rule: + r_id: 238946 + rv_id: 1263927 + rule_id: 7KUDRPj + version_id: 6xT29ol + url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, + which can lead to security vulnerabilities (CWE-502). Use a concrete struct type + instead. + severity: WARNING + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + category: security + technology: + - go + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/502.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + shortlink: https://sg.run/6WbKL + semgrep.dev: + rule: + r_id: 274359 + rv_id: 1409387 + rule_id: 4bUAQDG + version_id: ZRTDkjk + url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + origin: community + patterns: + - pattern-either: + - pattern: | + var $VAR interface{} + ... + json.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + yaml.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + xml.Unmarshal($DATA, &$VAR) +- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch + names can be silently repointed by the action owner, enabling supply-chain attacks + \u2014 as seen in the trivy-action and kics-github-action compromises. Pin the + reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`." + severity: WARNING + languages: + - yaml + metadata: + category: security + cwe: + - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' + - 'CWE-353: Missing Support for Integrity Check' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + shortlink: https://sg.run/2LgAL + semgrep.dev: + rule: + r_id: 288863 + rv_id: 1413422 + rule_id: GdUxYDx + version_id: xyTRDAd + url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + origin: community + patterns: + - pattern-inside: '{steps: ...}' + - pattern: | + uses: "$ACTION" + - metavariable-pattern: + metavariable: $ACTION + language: generic + patterns: + - pattern-not-regex: ^\./ + - pattern-not-regex: ^docker:// + - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' +- id: yaml.github-actions.security.secrets-inherit.secrets-inherit + languages: + - yaml + severity: ERROR + message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s + secrets to a reusable workflow. This violates the principle of least privilege + because the called workflow receives access to every secret in the repository, + not just the ones it needs. If the called workflow is compromised or sourced from + a third party, an attacker gains access to all repository secrets. Instead, explicitly + pass only the secrets that the called workflow requires using the `secrets:` map, + e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.' + metadata: + category: security + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow + - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit + shortlink: https://sg.run/X2PZB + semgrep.dev: + rule: + r_id: 288864 + rv_id: 1413424 + rule_id: ReUQnKg + version_id: e1T42L1 + url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit + origin: community + patterns: + - pattern-inside: | + jobs: + ... + - pattern: 'secrets: inherit' +- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*minimumReleaseAge) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: minimumReleaseAge\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 604800 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ + message: 'This bunfig.toml does not set a minimum release age or sets it too low. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge + = 604800` under the `[install]` section to wait 7 days before resolving newly + published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/bunfig.toml' + - '**/.bunfig.toml' + metadata: + category: security + technology: + - bun + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://bun.sh/docs/runtime/bunfig + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + shortlink: https://sg.run/JqPrR + semgrep.dev: + rule: + r_id: 291646 + rv_id: 1423385 + rule_id: oqUyJOb + version_id: BjTyRe5 + url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + origin: community +- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + pattern-either: + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + - package-ecosystem: $ECOSYSTEM + ... + - pattern-not: | + - package-ecosystem: $ECOSYSTEM + ... + cooldown: + ... + ... + - patterns: + - pattern-inside: | + updates: + ... + - pattern-regex: default-days\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + cooldown: + default-days: $DAYS + - metavariable-regex: + metavariable: $DAYS + regex: ^\D + - focus-metavariable: $DAYS + message: 'This Dependabot configuration does not set a cooldown period. Newly published + packages can be malicious or unstable. Add a `cooldown` block with `default-days: + 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing + updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.github/dependabot.yml' + - '**/.github/dependabot.yaml' + metadata: + category: security + technology: + - dependabot + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + shortlink: https://sg.run/5WvGK + semgrep.dev: + rule: + r_id: 291647 + rv_id: 1423386 + rule_id: zdUArOL + version_id: DkTwEGl + url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + origin: community +- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) + - pattern-not-regex: min-release-age + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: min-release-age\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)min-release-age\s*=\s*$ + message: 'This .npmrc does not set a minimum release age or sets it too low. Newly + published packages can be malicious or unstable. Add `min-release-age = 7` to + wait 7 days before resolving newly published package versions. Added in: v11.10 + Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/.npmrc' + metadata: + category: security + technology: + - npm + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ + - https://github.com/npm/cli/pull/8965 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + shortlink: https://sg.run/GRo1z + semgrep.dev: + rule: + r_id: 291648 + rv_id: 1423387 + rule_id: pKU6A82 + version_id: WrT7LdL + url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` + to transitive dependencies from being installed from untrusted sources. Added + in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + blockExoticSubdeps: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!true$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#blockexoticsubdeps + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + shortlink: https://sg.run/RrWRv + semgrep.dev: + rule: + r_id: 291649 + rv_id: 1423388 + rule_id: 2ZUQEZ5 + version_id: 0bTGnwj + url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + origin: community +- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + message: 'This pnpm workspace configuration does not set a minimum release age. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge: + 10080` (minutes) to wait at least seven days before installing newly published + package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 10080 + - focus-metavariable: $AGE + - patterns: + - pattern: | + minimumReleaseAge: $AGE + - metavariable-regex: + metavariable: $AGE + regex: ^\D + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + shortlink: https://sg.run/Aj0o0 + semgrep.dev: + rule: + r_id: 291650 + rv_id: 1423389 + rule_id: X5Uwn1n + version_id: K3TgxrW + url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent + malicious package updates from downgrading security settings. Added in: v10.21.0 + Reference: https://pnpm.io/settings#trustpolicy' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + trustPolicy: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!no-downgrade$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + shortlink: https://sg.run/B2Kz7 + semgrep.dev: + rule: + r_id: 291651 + rv_id: 1423390 + rule_id: j2U6J8N + version_id: qkTvDQn + url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + origin: community +- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-either: + - pattern: | + { ..., "matchPackageNames": [...], ... } + - pattern: | + { ..., "matchPackagePatterns": [...], ... } + - pattern: | + { ..., "matchDepTypes": [...], ... } + - pattern-not: | + { + ..., + "minimumReleaseAge": $AGE, + ... + } + - pattern-not: | + { + ..., + "minimumReleaseAge": false, + ... + } + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern: | + "minimumReleaseAge": "$AGE" + - metavariable-regex: + metavariable: $AGE + regex: ^(?!\d+ days?$) + - focus-metavariable: $AGE + message: 'This Renovate configuration does not set a minimum release age. Newly + published packages can be malicious or unstable. Add `"minimumReleaseAge": "7 + days"` within a `packageRules` entry to wait 7 days before proposing updates to + newly published package versions. Set `"minimumReleaseAge": false` to set an exception + for minimal release age for the package rule. Added in: v42' + languages: + - json + severity: MEDIUM + paths: + include: + - '**/renovate.json' + - '**/renovate.json5' + - '**/.renovaterc' + - '**/.renovaterc.json' + - '**/.renovaterc.json5' + metadata: + category: security + technology: + - renovate + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.renovatebot.com/configuration-options/#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + shortlink: https://sg.run/D8l2q + semgrep.dev: + rule: + r_id: 291652 + rv_id: 1443454 + rule_id: 10UbQrX + version_id: jQT1KAX + url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + origin: community +- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + pattern-either: + - patterns: + - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*exclude-newer) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P\d+) days?" + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" + - metavariable-regex: + metavariable: $VAL + regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T) + - focus-metavariable: $VAL + message: 'This pyproject.toml configures uv but does not set a dependency cooldown. + Newly published packages can be malicious or unstable. Add `exclude-newer = "7 + days"` under `[tool.uv]` to wait 7 days before resolving newly published package + versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/pyproject.toml' + - '**/uv.toml' + metadata: + category: security + technology: + - uv + - python + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + shortlink: https://sg.run/WeY0Z + semgrep.dev: + rule: + r_id: 291653 + rv_id: 1423392 + rule_id: 9AUo6vE + version_id: YDTwLle + url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + origin: community +- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) + - metavariable-regex: + metavariable: $VAL + regex: ^(?!['"]?\d+d['"]?$) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ + message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly + published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"` + to wait 7 days before resolving newly published package versions. Added in: 4.10 + Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.yarnrc.yml' + metadata: + category: security + technology: + - yarn + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + shortlink: https://sg.run/0gvNq + semgrep.dev: + rule: + r_id: 291654 + rv_id: 1423393 + rule_id: yyUBeEz + version_id: JdTnXlj + url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + origin: community +- id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`. + Without a cooldown, Poetry may resolve newly published package versions that have + not yet been vetted by the community. Supply chain attacks frequently involve + publishing a malicious version of a popular package and waiting for it to be pulled + in \u2014 most are detected and removed within days. Set `min-release-age = 7` + under `[solver]` to require that package versions are at least 7 days old before + they are considered during dependency resolution. Added in: v2.4.0" + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/poetry.toml' + - '**/config.toml' + pattern-either: + - pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z) + - pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P"[^"]*"|[0-6](?:\s|#|$)|false) + metadata: + category: security + technology: + - poetry + - python + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: MEDIUM + likelihood: LOW + impact: MEDIUM + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://python-poetry.org/docs/configuration/#solvermin-release-age + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + shortlink: https://sg.run/JqnYZ + semgrep.dev: + rule: + r_id: 309390 + rv_id: 1443453 + rule_id: kxUjBPy + version_id: X0TYPX6 + url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + origin: community +- id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown + below 7 days) allows Bundler to resolve newly published gem versions immediately, + before the community has had time to detect malicious releases. The May 2026 RubyGems + supply-chain attack demonstrated that threat actors can push compromised gem versions + and have them automatically pulled into builds within minutes. Add `cooldown: + 7` to each public source declaration so Bundler ignores gem versions published + within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org", + cooldown: 7`). If you operate an internal or private registry where the supply-chain + risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires + Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`; + `bundle install` with an existing lockfile is unaffected.' + languages: + - ruby + severity: MEDIUM + paths: + include: + - '**/Gemfile' + - '**/gems.rb' + exclude: + - '**/vendor/**' + - '**/.bundle/**' + pattern-either: + - patterns: + - pattern: source "...", ... + - pattern-not: 'source "...", ..., cooldown: $N, ...' + - patterns: + - pattern: 'source "...", ..., cooldown: $N, ...' + - metavariable-comparison: + metavariable: $N + comparison: $N > 0 and $N < 7 + - focus-metavariable: $N + metadata: + category: security + technology: + - bundler + - ruby + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: MEDIUM + likelihood: LOW + impact: MEDIUM + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + shortlink: https://sg.run/5Wlkl + semgrep.dev: + rule: + r_id: 309391 + rv_id: 1443455 + rule_id: wdUzPbP + version_id: 1QTEjAN + url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + origin: community +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell + interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote + server is compromised or the URL is hijacked, an attacker can execute arbitrary + code in your CI runner. Consider downloading the file first, verifying its checksum + or signature, and then executing it." + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + technology: + - github-actions + - bash + - curl + cwe2021-top25: true + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + shortlink: https://sg.run/GR8K1 + semgrep.dev: + rule: + r_id: 309392 + rv_id: 1443456 + rule_id: x8UAgrE + version_id: 9lT3zYb + url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + languages: + - yaml + message: "A secret is exposed in the workflow-level `env:` block, making it available + to every job and step in this workflow \u2014 including any untrusted code run + in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level + `env:` so the secret is only available where it is actually needed." + metadata: + category: security + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets + - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow + technology: + - github-actions + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + shortlink: https://sg.run/Rrn12 + semgrep.dev: + rule: + r_id: 309393 + rv_id: 1443457 + rule_id: OrUnq7z + version_id: yeTqX9r + url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + origin: community + patterns: + - pattern-inside: | + env: + ... + - pattern-regex: \$\{\{\s*secrets\. + - pattern-not-inside: 'jobs: ...' + severity: WARNING +- id: javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html + message: Dynamically rendering arbitrary HTML on your website can be very dangerous + because it can easily lead to XSS vulnerabilities. Only use HTML interpolation + on trusted content and never on user-provided content. + metadata: + references: + - https://vuejs.org/v2/guide/syntax.html#Raw-HTML + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - vue + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html + shortlink: https://sg.run/0QEw + semgrep.dev: + rule: + r_id: 9354 + rv_id: 1263250 + rule_id: 2ZUb2o + version_id: PkTR3Kj + url: https://semgrep.dev/playground/r/PkTR3Kj/javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html + origin: community + languages: + - regex + severity: WARNING + paths: + include: + - '*.vue' + pattern-regex: <[^<>]*v-html= +- id: javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection + message: If unverified user data can reach the `wkhtmltoimage` it can result in + Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - wkhtmltoimage + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection + shortlink: https://sg.run/KlDn + semgrep.dev: + rule: + r_id: 9355 + rv_id: 1263251 + rule_id: X5U8yj + version_id: JdTzx4D + url: https://semgrep.dev/playground/r/JdTzx4D/javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $WK = require('wkhtmltoimage'); + ... + - pattern-not-inside: | + var $INPUT = "..."; + ... + - pattern: $WK.generate($INPUT,...) + - pattern-not: $WK.generate("...",...) +- id: javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection + message: If unverified user data can reach the `wkhtmltopdf` it can result in Server-Side + Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - wkhtmltopdf + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection + shortlink: https://sg.run/qx8O + semgrep.dev: + rule: + r_id: 9356 + rv_id: 1263252 + rule_id: j2Uv58 + version_id: 5PTo1xA + url: https://semgrep.dev/playground/r/5PTo1xA/javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $WK = require('wkhtmltopdf'); + ... + - pattern-not-inside: | + var $INPUT = "..."; + ... + - pattern: $WK($INPUT,...) + - pattern-not: $WK("...",...) +- id: javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + message: If unverified user data can reach the XML Parser it can result in XML External + or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + category: security + technology: + - xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + shortlink: https://sg.run/l27o + semgrep.dev: + rule: + r_id: 9357 + rv_id: 1263253 + rule_id: 10UKpB + version_id: GxTkeg8 + url: https://semgrep.dev/playground/r/GxTkeg8/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern: | + var $XML = require('xml2json'); + ... + $XML.toJson(...); + - pattern-not: | + var $XML = require('xml2json'); + ... + $XML.toJson("...",...); + - pattern-not: |- + var $XML = require('xml2json'); + ... + var $S = "..."; + ... + $XML.toJson($S,...); +- id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement + pattern: | + { + "Effect": "Allow", + "Principal": "*", + "Resource": [ + ..., "=~/arn:aws:s3.*/", ... + ], + ... + } + message: Detected public S3 bucket policy. This policy allows anyone to access certain + properties of or items in the bucket. Do not do this unless you will never have + sensitive data inside the bucket. + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + references: + - https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html + category: security + technology: + - aws + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + shortlink: https://sg.run/Yv1d + semgrep.dev: + rule: + r_id: 9358 + rv_id: 1263255 + rule_id: 9AU1br + version_id: A8Tgdxq + url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + origin: community + severity: WARNING + languages: + - json +- id: kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + message: A formatted or concatenated string was detected as input to a java.lang.Runtime + call. This is dangerous if a variable is controlled by user input and could result + in a command injection. Ensure your variables are not controlled by users or sufficiently + sanitized. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#COMMAND_INJECTION. + category: security + technology: + - kt + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + shortlink: https://sg.run/6nEK + semgrep.dev: + rule: + r_id: 9359 + rv_id: 1263259 + rule_id: yyUnpo + version_id: 0bTKzZ9 + url: https://semgrep.dev/playground/r/0bTKzZ9/kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + origin: community + severity: ERROR + languages: + - kt + pattern-either: + - pattern: $RUNTIME.exec($X + $Y) + - pattern: $RUNTIME.exec(String.format(...)) + - pattern: $RUNTIME.loadLibrary($X + $Y) + - pattern: $RUNTIME.loadLibrary(String.format(...)) +- id: kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTPONLY_COOKIE + category: security + technology: + - kt + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly + shortlink: https://sg.run/ox7X + semgrep.dev: + rule: + r_id: 9360 + rv_id: 1263260 + rule_id: r6UrKQ + version_id: K3TKkRO + url: https://semgrep.dev/playground/r/K3TKkRO/kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly + origin: community + message: A cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' + flag for cookies instructs the browser to forbid client-side scripts from reading + the cookie. Set the 'HttpOnly' flag by calling 'cookie.setHttpOnly(true);' + severity: WARNING + languages: + - kt + patterns: + - pattern-not-inside: | + $COOKIE.setValue("") + ... + - pattern-either: + - pattern: $COOKIE.setHttpOnly(false) + - patterns: + - pattern-not-inside: | + $COOKIE.setHttpOnly(...) + ... + - pattern: $RESPONSE.addCookie($COOKIE) +- id: kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_COOKIE + category: security + technology: + - kt + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag + shortlink: https://sg.run/zv7n + semgrep.dev: + rule: + r_id: 9361 + rv_id: 1263261 + rule_id: bwUw3j + version_id: qkTR7r9 + url: https://semgrep.dev/playground/r/qkTR7r9/kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag + origin: community + message: A cookie was detected without setting the 'secure' flag. The 'secure' flag + for cookies prevents the client from transmitting the cookie over insecure channels + such as HTTP. Set the 'secure' flag by calling '$COOKIE.setSecure(true);' + severity: WARNING + languages: + - kt + patterns: + - pattern-not-inside: | + $COOKIE.setValue("") + ... + - pattern-either: + - pattern: $COOKIE.setSecure(false) + - patterns: + - pattern-not-inside: | + $COOKIE.setSecure(...) + ... + - pattern: $RESPONSE.addCookie($COOKIE) +- id: ocaml.lang.compatibility.deprecated.deprecated-pervasives + pattern: Pervasives.$X + message: Pervasives is deprecated and will not be available after 4.10. Use Stdlib. + languages: + - ocaml + severity: ERROR + metadata: + category: compatibility + technology: + - ocaml + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ocaml.lang.compatibility.deprecated.deprecated-pervasives + shortlink: https://sg.run/dKe0 + semgrep.dev: + rule: + r_id: 9378 + rv_id: 945962 + rule_id: 3qUP1E + version_id: K3TJbDY + url: https://semgrep.dev/playground/r/K3TJbDY/ocaml.lang.compatibility.deprecated.deprecated-pervasives + origin: community diff --git a/backend/app/sandbox/rules/owasp-top-ten.yaml b/backend/app/sandbox/rules/owasp-top-ten.yaml new file mode 100644 index 0000000..f8f8dd4 --- /dev/null +++ b/backend/app/sandbox/rules/owasp-top-ten.yaml @@ -0,0 +1,41421 @@ +rules: +- id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: The host for this proxy URL is dynamically determined. This can be dangerous + if the host can be injected by an attacker because it may forcibly alter destination + of the proxy. Consider hardcoding acceptable destinations and retrieving them + with 'map' or something similar. + metadata: + source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + references: + - https://nginx.org/en/docs/http/ngx_http_map_module.html + category: security + technology: + - nginx + confidence: MEDIUM + cwe: + - 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + shortlink: https://sg.run/ndpb + semgrep.dev: + rule: + r_id: 9036 + rv_id: 1262671 + rule_id: GdU7yl + version_id: kbTzG2j + url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + origin: community + pattern-either: + - pattern: proxy_pass $SCHEME://$$HOST ...; + - pattern: proxy_pass $$SCHEME://$$HOST ...; +- id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: The protocol scheme for this proxy is dynamically determined. This can + be dangerous if the scheme can be injected by an attacker because it may forcibly + alter the connection scheme. Consider hardcoding a scheme for this proxy. + metadata: + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + shortlink: https://sg.run/EkAo + semgrep.dev: + rule: + r_id: 9037 + rv_id: 1262672 + rule_id: ReUg7n + version_id: w8TRoAJ + url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + origin: community + pattern: proxy_pass $$SCHEME:// ...; +- id: generic.nginx.security.header-injection.header-injection + pattern: | + location ... <$VARIABLE> ... { + ... + add_header ... $$VARIABLE + ... + } + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: ERROR + message: 'The $$VARIABLE path parameter is added as a header in the response. This + could allow an attacker to inject a newline and add a new header into the response. + This is called HTTP response splitting. To fix, do not allow whitespace in the + path parameter: ''[^\s]+''.' + metadata: + cwe: + - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP + Request/Response Splitting'')' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md + - https://owasp.org/www-community/attacks/HTTP_Response_Splitting + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection + shortlink: https://sg.run/7oj4 + semgrep.dev: + rule: + r_id: 9038 + rv_id: 1262673 + rule_id: AbUz8p + version_id: xyTjzNW + url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection + origin: community +- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version + patterns: + - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; + - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; + - pattern-not: ssl_protocols TLSv1.2; + - pattern-not: ssl_protocols TLSv1.3; + - pattern: ssl_protocols ...; + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 + and TLS1.3; older versions are known to be broken and are susceptible to attacks. + Prefer use of TLSv1.2 or later. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ + category: security + technology: + - nginx + confidence: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + shortlink: https://sg.run/gLKy + semgrep.dev: + rule: + r_id: 9041 + rv_id: 1262676 + rule_id: WAUo9k + version_id: vdT06O4 + url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + origin: community +- id: generic.nginx.security.missing-ssl-version.missing-ssl-version + patterns: + - pattern: server { ... listen $PORT ssl; ... } + - pattern-not-inside: server { ... ssl_protocols ... } + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: This server configuration is missing the 'ssl_protocols' directive. By + default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions + older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2 + TLSv1.3' to use secure TLS versions. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://nginx.org/en/docs/http/configuring_https_servers.html + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version + shortlink: https://sg.run/3xzl + semgrep.dev: + rule: + r_id: 9043 + rv_id: 1262678 + rule_id: KxUbeA + version_id: ZRTKAle + url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version + origin: community +- id: generic.nginx.security.request-host-used.request-host-used + pattern-either: + - pattern: $http_host + - pattern: $host + paths: + include: + - '*conf*' + - '*nginx*' + - '*vhost*' + - '**/sites-available/*' + - '**/sites-enabled/*' + languages: + - generic + severity: WARNING + message: '''$http_host'' and ''$host'' variables may contain a malicious value from + attacker controlled ''Host'' request header. Use an explicitly configured host + value or a allow list for validation.' + metadata: + cwe: + - 'CWE-290: Authentication Bypass by Spoofing' + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md + - https://portswigger.net/web-security/host-header + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/generic.nginx.security.request-host-used.request-host-used + shortlink: https://sg.run/4x3Z + semgrep.dev: + rule: + r_id: 9044 + rv_id: 1262680 + rule_id: qNUjGg + version_id: ExTExrN + url: https://semgrep.dev/playground/r/ExTExrN/generic.nginx.security.request-host-used.request-host-used + origin: community +- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + pattern-regex: rk_live_[0-9a-zA-Z]{24} + languages: + - regex + message: Stripe Restricted API Key detected + severity: ERROR + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + category: security + technology: + - secrets + - stripe + confidence: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + shortlink: https://sg.run/ZvdL + semgrep.dev: + rule: + r_id: 9079 + rv_id: 1262900 + rule_id: 5rUOWq + version_id: K3TKkKj + url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + origin: community +- id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + patterns: + - pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END + - metavariable-regex: + metavariable: $...USERNAME + regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z + - metavariable-regex: + metavariable: $...PASSWORD + regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32} + - metavariable-regex: + metavariable: $PROTOCOL + regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*) + languages: + - generic + message: Username and password in URI detected + severity: ERROR + metadata: + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + category: security + technology: + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + shortlink: https://sg.run/8yA4 + semgrep.dev: + rule: + r_id: 9084 + rv_id: 1262903 + rule_id: DbUple + version_id: YDTZeZE + url: https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + origin: community +- id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + patterns: + - pattern-not-inside: | + &sessions.Options{ + ..., + HttpOnly: true, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: A session cookie was detected without setting the 'HttpOnly' flag. The + 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts + from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by + setting 'HttpOnly' to 'true' in the Options struct. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + shortlink: https://sg.run/4xJZ + semgrep.dev: + rule: + r_id: 9088 + rv_id: 1262911 + rule_id: qNUj6g + version_id: WrTqKqe + url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + origin: community + fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + patterns: + - pattern-not-inside: | + &sessions.Options{ + ..., + Secure: true, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' + flag for cookies prevents the client from transmitting the cookie over insecure + channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in + the Options struct. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + shortlink: https://sg.run/PJdE + semgrep.dev: + rule: + r_id: 9089 + rv_id: 1262912 + rule_id: lBU9kw + version_id: 0bTKzKk + url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + origin: community + fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + shortlink: https://sg.run/J9yZ + semgrep.dev: + rule: + r_id: 9090 + rv_id: 1262916 + rule_id: PeUZ4X + version_id: YDTZeZB + url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + origin: community + message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This + creates a connection without encryption to a gRPC server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Instead, + establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' + function. You can create a create credentials using a ''tls.Config{}'' struct + with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' + languages: + - go + severity: ERROR + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + shortlink: https://sg.run/5Q5l + semgrep.dev: + rule: + r_id: 9091 + rv_id: 1262917 + rule_id: JDUy0B + version_id: 6xT2923 + url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + origin: community + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. + This allows for a connection without encryption to this server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Include + credentials derived from an SSL certificate in order to create a secure gRPC connection. + You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", + "cert.key")'. + languages: + - go + severity: ERROR + mode: taint + pattern-sinks: + - requires: OPTIONS and not CREDS + pattern: grpc.NewServer($OPT, ...) + - requires: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() +- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + shortlink: https://sg.run/Gej1 + semgrep.dev: + rule: + r_id: 9092 + rv_id: 1262919 + rule_id: 5rUOWQ + version_id: zyTb2bz + url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + origin: community + languages: + - go + severity: ERROR + patterns: + - pattern-either: + - pattern-inside: | + import "github.com/golang-jwt/jwt" + ... + - pattern-inside: | + import "github.com/dgrijalva/jwt-go" + ... + - pattern-either: + - pattern: | + jwt.SigningMethodNone + - pattern: jwt.UnsafeAllowNoneSignatureType +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - jwt + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + shortlink: https://sg.run/Rod2 + semgrep.dev: + rule: + r_id: 9093 + rv_id: 1262920 + rule_id: GdU7Ny + version_id: pZT0305 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + origin: community + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + []byte("$F") + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $TOKEN.SignedString($F) + - focus-metavariable: $F +- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` + unless you know what you're doing This method parses the token but doesn't validate + the signature. It's only ever useful in cases where you know the signature is + valid (because it has been checked previously in the stack) and you want to extract + values from it. + metadata: + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: MEDIUM + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + shortlink: https://sg.run/Av66 + semgrep.dev: + rule: + r_id: 9094 + rv_id: 1262918 + rule_id: ReUgJJ + version_id: o5TbDbq + url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-inside: | + import "github.com/dgrijalva/jwt-go" + ... + - pattern: | + $JWT.ParseUnverified(...) +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + patterns: + - pattern-either: + - patterns: + - pattern: | + exec.Cmd {...,Path: $CMD,...} + - pattern-not: | + exec.Cmd {...,Path: "...",...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: $ARGS,...} + - pattern-not: | + exec.Cmd {...,Args: []string{...},...} + - pattern-not-inside: | + $ARGS = []string{"...",...}; + ... + - pattern-not-inside: | + $CMD = "..."; + ... + $ARGS = []string{$CMD,...}; + ... + - pattern-not-inside: | + $CMD = exec.LookPath("..."); + ... + $ARGS = []string{$CMD,...}; + ... + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,...},...} + - pattern-not: | + exec.Cmd {...,Args: []string{"...",...},...} + - pattern-not-inside: | + $CMD,$ERR := exec.LookPath("..."); + ... + - pattern-not-inside: | + $CMD = "..."; + ... + - patterns: + - pattern-either: + - pattern: | + exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...} + - patterns: + - pattern: | + exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...} + - pattern-inside: | + $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); + ... + - pattern-not: | + exec.Cmd {...,Args: []string{"...","...","...",...},...} + - pattern-not-inside: | + $EXE = "..."; + ... + - pattern-inside: | + import "os/exec" + ... + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + shortlink: https://sg.run/Dorj + semgrep.dev: + rule: + r_id: 9108 + rv_id: 1262934 + rule_id: 2ZUb8l + version_id: e1Tyjeg + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + origin: community + severity: ERROR + languages: + - go +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + message: The package `net/http/cgi` is on the import blocklist. The package is + vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http` + or a web framework to build a web application instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec + references: + - https://godoc.org/golang.org/x/crypto/sha3 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + shortlink: https://sg.run/l2gj + semgrep.dev: + rule: + r_id: 9113 + rv_id: 1262921 + rule_id: yyUnov + version_id: 2KTv2vJ + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + origin: community + languages: + - go + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import "net/http/cgi" + ... + - pattern: | + cgi.$FUNC(...) +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + message: Disabled host key verification detected. This allows man-in-the-middle + attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. + See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to + learn more about the problem and how to fix it. + metadata: + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + shortlink: https://sg.run/Yv6X + semgrep.dev: + rule: + r_id: 9114 + rv_id: 1262922 + rule_id: r6UrW9 + version_id: X0TzyzN + url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + origin: community + languages: + - go + severity: WARNING + pattern: ssh.InsecureIgnoreHostKey() +- id: go.lang.security.audit.crypto.math_random.math-random-used + metadata: + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + shortlink: https://sg.run/6nK6 + semgrep.dev: + rule: + r_id: 9115 + rv_id: 1262923 + rule_id: bwUwy8 + version_id: jQTn5nj + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + origin: community + message: Do not use `math/rand`. Use `crypto/rand` instead. + languages: + - go + severity: WARNING + patterns: + - pattern-either: + - pattern: | + import $RAND "$MATH" + - pattern: | + import "$MATH" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: | + ... + rand.$FUNC(...) + - pattern-inside: | + ... + $RAND.$FUNC(...) + - focus-metavariable: + - $MATH + fix: | + crypto/rand +- id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + message: '`MinVersion` is missing from this TLS configuration. By default, as of + Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications + should default to TLS 1.3 with all other protocols disabled. Only where it is + known that a web server must support legacy clients with unsupported an insecure + browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 + to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration + to bump the minimum version to TLS 1.3.' + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + shortlink: https://sg.run/oxEN + semgrep.dev: + rule: + r_id: 9116 + rv_id: 1262924 + rule_id: NbUk4X + version_id: 1QTypyp + url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern: | + tls.Config{ $...CONF } + - pattern-not: | + tls.Config{..., MinVersion: ..., ...} + fix: | + tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 } +- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, + SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + shortlink: https://sg.run/zvE1 + semgrep.dev: + rule: + r_id: 9117 + rv_id: 1262926 + rule_id: kxUkJ2 + version_id: yeTxpxj + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + origin: community + languages: + - go + severity: WARNING + fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered + weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. + See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other + cipher suites to use. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: HIGH + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + shortlink: https://sg.run/px8N + semgrep.dev: + rule: + r_id: 9118 + rv_id: 1262927 + rule_id: wdUJYk + version_id: rxTAKAZ + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + shortlink: https://sg.run/2xB5 + semgrep.dev: + rule: + r_id: 9119 + rv_id: 1262928 + rule_id: x8Un6q + version_id: bZT535Y + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + origin: community + patterns: + - pattern-inside: | + import "crypto/md5" + ... + - pattern-either: + - pattern: | + md5.New() + - pattern: | + md5.Sum(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + shortlink: https://sg.run/XBYA + semgrep.dev: + rule: + r_id: 9120 + rv_id: 1262929 + rule_id: OrU31O + version_id: NdTzyz1 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + origin: community + patterns: + - pattern-inside: | + import "crypto/sha1" + ... + - pattern-either: + - pattern: | + sha1.New() + - pattern: | + sha1.Sum(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + message: Detected DES cipher algorithm which is insecure. The algorithm is considered + weak and has been deprecated. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + shortlink: https://sg.run/jREA + semgrep.dev: + rule: + r_id: 9121 + rv_id: 1262930 + rule_id: eqU8B3 + version_id: kbTzGzA + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + origin: community + patterns: + - pattern-inside: | + import "crypto/des" + ... + - pattern-either: + - pattern: | + des.NewTripleDESCipher(...) + - pattern: | + des.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many + known vulnerabilities. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + shortlink: https://sg.run/1ZAD + semgrep.dev: + rule: + r_id: 9122 + rv_id: 1262931 + rule_id: v8Unl0 + version_id: w8TRoRQ + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + origin: community + patterns: + - pattern-inside: | + import "crypto/rc4" + ... + - pattern: rc4.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - go + confidence: HIGH + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + shortlink: https://sg.run/9oY4 + semgrep.dev: + rule: + r_id: 9123 + rv_id: 1262932 + rule_id: d8UjY3 + version_id: xyTjz8L + url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + rsa.GenerateKey(..., $BITS) + - pattern: | + rsa.GenerateMultiPrimeKey(..., $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 + - focus-metavariable: + - $BITS + fix: | + 2048 +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + message: Detected a network listener listening on 0.0.0.0 or an empty string. This + could unexpectedly expose the server publicly as it binds to all available interfaces. + Instead, specify another IP address that is not 0.0.0.0 nor the empty string. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: HIGH + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdE0 + semgrep.dev: + rule: + r_id: 9125 + rv_id: 1262939 + rule_id: nJUz3J + version_id: ExTExoK + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + origin: community + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) +- id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + patterns: + - pattern-not-inside: | + http.Cookie{ + ..., + HttpOnly: true, + ..., + } + - pattern: | + http.Cookie{ + ..., + } + message: A session cookie was detected without setting the 'HttpOnly' flag. The + 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts + from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by + setting 'HttpOnly' to 'true' in the Cookie. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + shortlink: https://sg.run/b73e + semgrep.dev: + rule: + r_id: 9126 + rv_id: 1262940 + rule_id: EwU2Z6 + version_id: 7ZTE3BW + url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + origin: community + fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + patterns: + - pattern-not-inside: | + http.Cookie{ + ..., + Secure: true, + ..., + } + - pattern: | + http.Cookie{ + ..., + } + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' + flag for cookies prevents the client from transmitting the cookie over insecure + channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in + the Options struct. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + shortlink: https://sg.run/N4G7 + semgrep.dev: + rule: + r_id: 9127 + rv_id: 1262941 + rule_id: 7KUQ8X + version_id: LjTkgGE + url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + origin: community + fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep + could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous + because they deserialize function code to run when certain Request events occur, + which could lead to code being run without your knowledge. Ensure that your ClientTrace + is statically defined. + metadata: + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + shortlink: https://sg.run/kXEK + semgrep.dev: + rule: + r_id: 9128 + rv_id: 1262942 + rule_id: L1Uyjp + version_id: 8KT5rNv + url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + origin: community + patterns: + - pattern-not-inside: | + package $PACKAGE + ... + &httptrace.ClientTrace { ... } + ... + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. If user data can reach this template, you may have a XSS vulnerability. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + category: security + technology: + - go + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + shortlink: https://sg.run/weE0 + semgrep.dev: + rule: + r_id: 9129 + rv_id: 1262943 + rule_id: 8GUjDW + version_id: gETB7Pe + url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTML($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTML($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTML($OTHER, ...) +- id: go.lang.security.audit.net.use-tls.use-tls + pattern: http.ListenAndServe($ADDR, $HANDLER) + fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + shortlink: https://sg.run/dKbY + semgrep.dev: + rule: + r_id: 9134 + rv_id: 1262948 + rule_id: PeUZ8X + version_id: JdTzxkn + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + origin: community + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. + See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + languages: + - go + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + patterns: + - pattern-inside: | + func $FUNC(..., $W http.ResponseWriter, ...) { + ... + var $TEMPLATE = "..." + ... + $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) + ... + } + - pattern-either: + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) + message: Found data going from url query parameters into formatted data written + to ResponseWriter. This could be XSS and should not be done. If you must do this, + ensure your data is sanitized or escaped. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + shortlink: https://sg.run/Zvon + semgrep.dev: + rule: + r_id: 9135 + rv_id: 1262949 + rule_id: JDUyXB + version_id: 5PTo1qr + url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + origin: community + severity: WARNING + languages: + - go +- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + technology: + - java + - secrets + - jwt + category: security + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + shortlink: https://sg.run/RoDK + semgrep.dev: + rule: + r_id: 9149 + rv_id: 1262980 + rule_id: oqUeAn + version_id: d6Tyx8j + url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern-either: + - pattern: | + (Algorithm $ALG) = $ALGO.$HMAC("$Y"); + - pattern: | + $SECRET = "$Y"; + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + - pattern: | + class $CLASS { + ... + $TYPE $SECRET = "$Y"; + ... + $RETURNTYPE $FUNC (...) { + ... + (Algorithm $ALG) = $ALGO.$HMAC($SECRET); + ... + } + ... + } + - focus-metavariable: $Y + - metavariable-regex: + metavariable: $HMAC + regex: (HMAC384|HMAC256|HMAC512) +- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + shortlink: https://sg.run/Av14 + semgrep.dev: + rule: + r_id: 9150 + rv_id: 1262981 + rule_id: zdUkzR + version_id: ZRTKADq + url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + origin: community + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $JWT.sign(com.auth0.jwt.algorithms.Algorithm.none()); + - pattern: | + $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $JWT.sign($NONE); + - pattern: |- + class $CLASS { + ... + $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none(); + ... + $RETURNTYPE $FUNC (...) { + ... + $JWT.sign($NONE); + ... + } + ... + } +- id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + message: Detected the decoding of a JWT token without a verify step. JWT tokens + must be verified before use, otherwise the token's integrity is unknown. This + means a malicious actor could forge a JWT token with any claims. Call '.verify()' + before using the token. + metadata: + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + confidence: MEDIUM + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + shortlink: https://sg.run/Bk95 + semgrep.dev: + rule: + r_id: 9151 + rv_id: 1262979 + rule_id: pKUOE9 + version_id: vdT06Lp + url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + origin: community + languages: + - java + severity: WARNING + patterns: + - pattern: | + com.auth0.jwt.JWT.decode(...); + - pattern-not-inside: |- + class $CLASS { + ... + $RETURNTYPE $FUNC (...) { + ... + $VERIFIER.verify(...); + ... + } + } +- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - jax-rs + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + shortlink: https://sg.run/DoWj + semgrep.dev: + rule: + r_id: 9152 + rv_id: 1262984 + rule_id: 2ZUb9l + version_id: 7ZTE3KW + url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } + - pattern: |- + $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } +- id: java.jboss.security.session_sqli.find-sql-string-concatenation + message: In $METHOD, $X is used to construct a SQL query via string concatenation. + languages: + - java + severity: ERROR + pattern-either: + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + Session $SESSION = ...; + ... + String $QUERY = ... + $X + ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + - pattern: | + $RETURN $METHOD(...,String $X,...){ + ... + String $QUERY = ... + $X + ...; + ... + Session $SESSION = ...; + ... + PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); + ... + ResultSet $RESULT = $PS.executeQuery(); + ... + } + metadata: + category: security + technology: + - jboss + confidence: MEDIUM + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation + shortlink: https://sg.run/W8kA + semgrep.dev: + rule: + r_id: 9153 + rv_id: 1262986 + rule_id: X5U8rQ + version_id: 8KT5r3v + url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation + origin: community +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + shortlink: https://sg.run/oxXN + semgrep.dev: + rule: + r_id: 9160 + rv_id: 1263064 + rule_id: NbUk7X + version_id: zyTb2rq + url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (java.io.File $FILE) = ... + - pattern: | + (java.io.FileOutputStream $FOS) = ... + - pattern: | + new java.io.FileInputStream(...) + severity: ERROR + languages: + - java +- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.3 Insecue Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + shortlink: https://sg.run/zvO1 + semgrep.dev: + rule: + r_id: 9161 + rv_id: 1263065 + rule_id: kxUk12 + version_id: pZT03A1 + url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + origin: community + message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling + of the message payload when ObjectMessage.getObject() is called. Deserialization + of untrusted data can lead to security flaws; a remote attacker could via a crafted + JMS ObjectMessage to execute arbitrary code with the permissions of the application + listening/consuming JMS Messages. In this case, the JMS MessageListener consume + an ObjectMessage type received inside the onMessage method, which may lead to + arbitrary code execution when calling the $Y.getObject method. + patterns: + - pattern-inside: | + public class $JMS_LISTENER implements MessageListener { + ... + public void onMessage(Message $JMS_MSG) { + ... + } + } + - pattern-either: + - pattern-inside: $X = $Y.getObject(...); + - pattern-inside: $X = ($Z) $Y.getObject(...); +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + message: 'Cross-site scripting detected in HttpServletResponse writer with variable + ''$VAR''. User input was detected going directly from the HttpServletRequest into + output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + ''Encode.forHtml($VAR)''.' + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + shortlink: https://sg.run/pxjN + semgrep.dev: + rule: + r_id: 9162 + rv_id: 1263066 + rule_id: wdUJOk + version_id: 2KTv2EG + url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + origin: community + severity: ERROR + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: | + $WRITER = $RESP.getWriter(...); + ... + $WRITER.write(..., $VAR, ...); + languages: + - java +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + shortlink: https://sg.run/XBwA + semgrep.dev: + rule: + r_id: 9164 + rv_id: 1263069 + rule_id: OrU35O + version_id: 1QTypQZ + url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + origin: community + message: XML external entities are not explicitly disabled for this XMLInputFactory. + This could be vulnerable to XML external entity vulnerabilities. Explicitly disable + external entities by setting "javax.xml.stream.isSupportingExternalEntities" to + false. + patterns: + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); + ... + } + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + languages: + - java +- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + shortlink: https://sg.run/9o74 + semgrep.dev: + rule: + r_id: 9167 + rv_id: 1262989 + rule_id: d8UjJ3 + version_id: 3ZT4X2r + url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + origin: community + message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits + or more, or switch to use AES instead. + severity: WARNING + languages: + - java + patterns: + - pattern: | + $KEYGEN = KeyGenerator.getInstance("Blowfish"); + ... + $KEYGEN.init($SIZE); + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 128 +- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A + malicious actor could discern the difference between plaintext with valid or invalid + padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' + instead. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE + references: + - https://capec.mitre.org/data/definitions/463.html + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY + category: security + technology: + - java + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + shortlink: https://sg.run/ydxr + semgrep.dev: + rule: + r_id: 9168 + rv_id: 1262990 + rule_id: ZqU5oD + version_id: 44TEjbE + url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + origin: community + severity: WARNING + fix: | + "AES/GCM/NoPadding" + languages: + - java + patterns: + - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") + - pattern: | + "=~/.*\/CBC\/PKCS5Padding/" +- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + message: When data from an untrusted source is put into a logger and not neutralized + correctly, an attacker could forge log entries or include malicious content. + metadata: + cwe: + - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + shortlink: https://sg.run/wek0 + semgrep.dev: + rule: + r_id: 9173 + rv_id: 1262995 + rule_id: 8GUjwW + version_id: RGT0LEr + url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + class $CLASS { + ... + Logger $LOG = ...; + ... + } + - pattern-either: + - pattern-inside: | + $X $METHOD(...,HttpServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...,ServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + ServletRequest $REQ = ...; + ... + } + - pattern-either: + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.$LEVEL(<... $VAL ...>); + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.log($LEVEL,<... $VAL ...>); + - pattern: | + $LOG.$LEVEL(<... $REQ.getParameter(...) ...>); + - pattern: | + $LOG.log($LEVEL,<... $REQ.getParameter(...) ...>); +- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps + - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string + shortlink: https://sg.run/OPXp + semgrep.dev: + rule: + r_id: 9175 + rv_id: 1409389 + rule_id: QrUzxR + version_id: ExTeyBP + url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + $ANNOT $FUNC (..., $INPUT, ...) { + ... + } + - pattern: (String $INPUT) + - focus-metavariable: $INPUT + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $INPUT + - pattern: $X += $INPUT + - pattern: String.format(..., $INPUT, ...) + - pattern: String.join(..., $INPUT, ...) + - pattern: (String $STR).concat($INPUT) + - pattern: $INPUT.concat(...) + - patterns: + - pattern-either: + - pattern: $STRB.append($INPUT) + - pattern: new $STRB(..., $INPUT, ...) + - metavariable-type: + metavariable: $STRB + type: StringBuilder + label: CONCAT + requires: INPUT + pattern-propagators: + - pattern: (StringBuffer $S).append($X) + from: $X + to: $S + - pattern: (StringBuilder $S).append($X) + from: $X + to: $S + pattern-sinks: + - patterns: + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) + - pattern-either: + - pattern: (Statement $S).$SQLFUNC(...) + - pattern: (PreparedStatement $P).$SQLFUNC(...) + - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) + - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) + - pattern: (EntityManager $EM).$SQLFUNC(...) + - metavariable-regex: + metavariable: $SQLFUNC + regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare + requires: CONCAT + pattern-sanitizers: + - patterns: + - pattern: (CriteriaBuilder $CB).$ANY(...) + severity: ERROR + languages: + - java +- id: java.lang.security.audit.http-response-splitting.http-response-splitting + metadata: + cwe: + - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP + Request/Response Splitting'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING + references: + - https://www.owasp.org/index.php/HTTP_Response_Splitting + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting + shortlink: https://sg.run/eL0l + semgrep.dev: + rule: + r_id: 9176 + rv_id: 1263023 + rule_id: 3qUPyK + version_id: X0Tzykw + url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting + origin: community + message: Older Java application servers are vulnerable to HTTP response splitting, + which may occur if an HTTP request can be injected with CRLF characters. This + finding is reported for completeness; it is recommended to ensure your environment + is not affected by testing this yourself. + severity: INFO + languages: + - java + pattern-either: + - pattern: | + $VAR = $REQ.getParameter(...); + ... + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); + - patterns: + - pattern-inside: | + $RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) { + ... + } + - pattern: | + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); +- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + metadata: + cwe: + - 'CWE-297: Improper Validation of Certificate with Host Mismatch' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + shortlink: https://sg.run/vzN4 + semgrep.dev: + rule: + r_id: 9177 + rv_id: 1263024 + rule_id: 4bUkrW + version_id: jQTn5Dv + url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + origin: community + message: Insecure SMTP connection detected. This connection will trust any SSL certificate. + Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'. + severity: WARNING + patterns: + - pattern-not-inside: | + $EMAIL.setSSLCheckServerIdentity(true); + ... + - pattern-inside: | + $EMAIL = new SimpleEmail(...); + ... + - pattern: $EMAIL.send(...); + languages: + - java +- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + message: Application redirects to a destination URL specified by a user-supplied + parameter that is not validated. This could direct users to malicious locations. + Consider using an allowlist to validate URLs. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.1.5 Open Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + impact: LOW + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + shortlink: https://sg.run/Q51P + semgrep.dev: + rule: + r_id: 9186 + rv_id: 1263048 + rule_id: WAUo0p + version_id: PkTR329 + url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } + - pattern: |- + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } +- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context + shortlink: https://sg.run/4x7E + semgrep.dev: + rule: + r_id: 9188 + rv_id: 1263050 + rule_id: KxUb1k + version_id: 5PTo1rW + url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context + origin: community + message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL + versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") + for the best security. + severity: WARNING + languages: + - java + patterns: + - pattern-not: SSLContext.getInstance("TLSv1.3") + - pattern-not: SSLContext.getInstance("TLSv1.2") + - pattern: SSLContext.getInstance("...") + fix-regex: + regex: (.*?)\.getInstance\(.*?\) + replacement: \1.getInstance("TLSv1.2") +- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + message: DES is considered deprecated. AES is the recommended cipher. Upgrade to + use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + for more information. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + shortlink: https://sg.run/5Q73 + semgrep.dev: + rule: + r_id: 9191 + rv_id: 1262996 + rule_id: PeUZNg + version_id: A8TgdEn + url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") + - pattern-inside: $CIPHER.getInstance("DES") + - pattern-either: + - pattern: | + "=~/DES/.*/" + - pattern: | + "DES" + fix: | + "AES/GCM/NoPadding" + languages: + - java + - kt +- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended + cipher. Upgrade to use AES. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE + references: + - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + shortlink: https://sg.run/Geqn + semgrep.dev: + rule: + r_id: 9192 + rv_id: 1262997 + rule_id: JDUy8J + version_id: BjTkZyQ + url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $CIPHER.getInstance("=~/DESede.*/") + - pattern: | + $CRYPTO.KeyGenerator.getInstance("DES") + languages: + - java + - kt +- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + shortlink: https://sg.run/Ro9K + semgrep.dev: + rule: + r_id: 9193 + rv_id: 1262998 + rule_id: 5rUOb6 + version_id: DkTRbwL + url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + origin: community + message: Cipher in ECB mode is detected. ECB mode produces the same output for the + same input each time which allows an attacker to intercept and replay the data. + Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + severity: WARNING + languages: + - java + patterns: + - pattern: | + Cipher $VAR = $CIPHER.getInstance($MODE); + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* +- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + patterns: + - pattern-either: + - pattern: new NullCipher(...); + - pattern: new javax.crypto.NullCipher(...); + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + shortlink: https://sg.run/AvA4 + semgrep.dev: + rule: + r_id: 9194 + rv_id: 1263001 + rule_id: GdU7pw + version_id: K3TKkgB + url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + message: Initialization Vectors (IVs) for block ciphers should be randomly generated + each time they are used. Using a static IV means the same plaintext encrypts to + the same ciphertext every time, weakening the strength of the encryption. + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cwe.mitre.org/data/definitions/329.html + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + shortlink: https://sg.run/BkB5 + semgrep.dev: + rule: + r_id: 9195 + rv_id: 1263002 + rule_id: ReUgj1 + version_id: qkTR7vP + url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + byte[] $IV = { + ... + }; + ... + new IvParameterSpec($IV, ...); + - pattern: | + class $CLASS { + byte[] $IV = { + ... + }; + ... + $METHOD(...) { + ... + new IvParameterSpec($IV, ...); + ... + } + } +- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING + references: + - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + - kotlin + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + shortlink: https://sg.run/DoOj + semgrep.dev: + rule: + r_id: 9196 + rv_id: 1263003 + rule_id: AbUzoj + version_id: l4TJRpK + url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + origin: community + message: Using RSA without OAEP mode weakens the encryption. + severity: WARNING + languages: + - java + - kt + pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") +- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + metadata: + functional-categories: + - net::search::crypto-config::java.net + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + shortlink: https://sg.run/W8zA + semgrep.dev: + rule: + r_id: 9197 + rv_id: 1263008 + rule_id: BYUN3X + version_id: RGT0LEj + url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + origin: community + message: Detected use of a Java socket that is not encrypted. As a result, the traffic + could be read by an attacker intercepting the network traffic. Use an SSLSocket + created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. + severity: WARNING + languages: + - java + pattern-either: + - pattern: new ServerSocket(...) + - pattern: new Socket(...) +- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::key-length::java.security + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/4x6x + semgrep.dev: + rule: + r_id: 9200 + rv_id: 1263019 + rule_id: 0oU5P5 + version_id: o5TbDLY + url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern: | + KeyPairGenerator $KEY = $G.getInstance("RSA"); + ... + $KEY.initialize($BITS); + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 +- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + message: Detected a request with potential user-input going into a OutputStream + or Writer object. This bypasses any view or template environments, including HTML + escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. + Consider using a view technology such as JavaServer Faces (JSFs) which automatically + escapes HTML views. + severity: WARNING + options: + interfile: true + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html + subcategory: + - vuln + technology: + - java + - servlets + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + shortlink: https://sg.run/KlRL + semgrep.dev: + rule: + r_id: 9211 + rv_id: 1263055 + rule_id: j2Uv7B + version_id: DkTRbXy + url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + origin: community + languages: + - java + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...) + - pattern: | + (HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...) + - pattern: | + (java.io.PrintWriter $WRITER).$WRITE(...) + - pattern: | + (PrintWriter $WRITER).$WRITE(...) + - pattern: | + (javax.servlet.ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (ServletOutputStream $WRITER).$WRITE(...) + - pattern: | + (java.io.OutputStream $WRITER).$WRITE(...) + - pattern: | + (OutputStream $WRITER).$WRITE(...) + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) + - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) + - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) + - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) +- id: java.spring.security.audit.spring-sqli.spring-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: $ARG + - pattern-inside: | + public $T $M (..., String $ARG,...){...} + pattern-sanitizers: + - not_conflicting: true + pattern-either: + - patterns: + - focus-metavariable: $A + - pattern-inside: | + new $TYPE(...,$A,...); + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - focus-metavariable: $A + - pattern: | + new PreparedStatementCreatorFactory($A,...); + - patterns: + - focus-metavariable: $A + - pattern: | + (JdbcTemplate $T).$M($A,...) + - patterns: + - pattern: (String $A) + - pattern-inside: | + (JdbcTemplate $T).batchUpdate(...) + - patterns: + - focus-metavariable: $A + - pattern: | + NamedParameterBatchUpdateUtils.$M($A,...) + - patterns: + - focus-metavariable: $A + - pattern: | + BatchUpdateUtils.$M($A,...) + message: Detected a string argument from a public method contract in a raw SQL statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You + can obtain a PreparedStatement using 'connection.prepareStatement'. + languages: + - java + severity: WARNING + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - spring + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli + shortlink: https://sg.run/1Z3x + semgrep.dev: + rule: + r_id: 9222 + rv_id: 1263082 + rule_id: eqU8N2 + version_id: ZRTKAWW + url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli + origin: community +- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + message: Application redirects a user to a destination URL specified by a user supplied + parameter that is not validated. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + shortlink: https://sg.run/9oXz + semgrep.dev: + rule: + r_id: 9223 + rv_id: 1263083 + rule_id: v8Un7w + version_id: nWT2Lk0 + url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,String $URL,...) { + return "redirect:" + $URL; + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + return $REDIR; + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + new ModelAndView("redirect:" + $URL); + ... + } + - pattern: |- + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + new ModelAndView($REDIR); + ... + } +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) + in an AngularJS application could provide additional attack surface for XSS vulnerabilities. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + shortlink: https://sg.run/N4DG + semgrep.dev: + rule: + r_id: 9227 + rv_id: 1263094 + rule_id: EwU20Z + version_id: 5PTo1EW + url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern: | + $sceProvider.enabled(false); +- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + message: The use of $sce.trustAs can be dangerous if unsanitized user input flows + through this API. + metadata: + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + technology: + - angular + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + shortlink: https://sg.run/OPW2 + semgrep.dev: + rule: + r_id: 9231 + rv_id: 1263098 + rule_id: gxU1QX + version_id: BjTkZv0 + url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + app.controller(..., function($scope,$sce) { + ... + }); + - pattern: $scope.$X + pattern-sinks: + - pattern: $sce.trustAs(...) + - pattern: $sce.trustAsHtml(...) +- id: javascript.browser.security.open-redirect.js-open-redirect + message: The application accepts potentially user-controlled input `$PROP` which + can control the location of the current window context. This can lead two types + of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript + URIs. It is recommended to validate user-controllable input before allowing it + to control the redirection. + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.1 Insecue Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + version: '4' + category: security + confidence: HIGH + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + technology: + - browser + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect + shortlink: https://sg.run/3xRe + semgrep.dev: + rule: + r_id: 9243 + rv_id: 1263122 + rule_id: WAUopl + version_id: pZT03x0 + url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + new URLSearchParams($WINDOW. ... .location.search).get('...') + - pattern: | + new URLSearchParams(location.search).get('...') + - pattern: | + new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') + - pattern: | + new URLSearchParams(location.hash.substring(1)).get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.hash.substring(1)) + ... + - pattern: $PROPS.get('...') + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URL($WINDOW. ... .location.href) + ... + - pattern-inside: | + $PROPS = new URL(location.href) + ... + - pattern: $PROPS.searchParams.get('...') + - patterns: + - pattern-either: + - pattern: | + new URL($WINDOW. ... .location.href).searchParams.get('...') + - pattern: | + new URL(location.href).searchParams.get('...') + pattern-sinks: + - patterns: + - pattern-either: + - pattern: location.href = $SINK + - pattern: $THIS. ... .location.href = $SINK + - pattern: location.replace($SINK) + - pattern: $THIS. ... .location.replace($SINK) + - pattern: location = $SINK + - pattern: $WINDOW. ... .location = $SINK + - focus-metavariable: $SINK + - metavariable-pattern: + patterns: + - pattern-not: | + "..." + $VALUE + - pattern-not: | + `...${$VALUE}` + metavariable: $SINK +- id: javascript.browser.security.raw-html-concat.raw-html-concat + message: User controlled data in a HTML string may result in XSS + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/xss/ + category: security + technology: + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat + shortlink: https://sg.run/4xAx + semgrep.dev: + rule: + r_id: 9244 + rv_id: 1263123 + rule_id: 0oU5b5 + version_id: 2KTv2wp + url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $STRING + $EXPR + - pattern-not: $STRING + "..." + - metavariable-pattern: + patterns: + - pattern: <$TAG ... + - pattern-not: <$TAG ...>...... + metavariable: $STRING + language: generic + - patterns: + - pattern: $EXPR + $STRING + - pattern-not: '"..." + $STRING' + - metavariable-pattern: + patterns: + - pattern: '... + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('node-expat') + ... + - pattern-inside: | + import $XML from 'node-expat' + ... + - pattern-inside: | + import * as $XML from 'node-expat' + ... + - pattern-either: + - pattern-inside: | + $PARSER = new $XML.Parser(...); + ... + - pattern-either: + - pattern: $PARSER.parse($QUERY) + - pattern: $PARSER.write($QUERY) + - focus-metavariable: $QUERY +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + shortlink: https://sg.run/Do1d + semgrep.dev: + rule: + r_id: 9252 + rv_id: 1263166 + rule_id: pKUOjy + version_id: pZT03Q0 + url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern-inside: | + import $JWT from 'express-jwt'; + ... + - pattern-inside: | + import * as $JWT from 'express-jwt'; + ... + - pattern-inside: | + import { ..., $JWT, ... } from 'express-jwt'; + ... + - pattern-either: + - pattern: | + $JWT({...,secret: "$Y",...},...) + - pattern: | + $OPTS = "$Y"; + ... + $JWT({...,secret: $OPTS},...); + - focus-metavariable: $Y +- id: javascript.express.security.express-phantom-injection.express-phantom-injection + message: If unverified user data can reach the `phantom` methods it can result in + Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://phantomjs.org/page-automation.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection + shortlink: https://sg.run/W8BL + semgrep.dev: + rule: + r_id: 9253 + rv_id: 1263167 + rule_id: 2ZUbx3 + version_id: 2KTv26p + url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('phantom'); + ... + - pattern-inside: | + import 'phantom'; + ... + - pattern-either: + - pattern: $PAGE.open($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.openUrl($SINK,...) + - pattern: $PAGE.evaluateJavaScript($SINK,...) + - pattern: $PAGE.property("content",$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + message: If unverified user data can reach the `puppeteer` methods it can result + in Server-Side Request Forgery vulnerabilities + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + category: security + technology: + - express + references: + - https://pptr.dev/api/puppeteer.page + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + shortlink: https://sg.run/0QJB + semgrep.dev: + rule: + r_id: 9254 + rv_id: 1263168 + rule_id: X5U8Nz + version_id: X0TzyJY + url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('puppeteer'); + ... + - pattern-inside: | + import 'puppeteer'; + ... + - pattern-either: + - pattern: $PAGE.goto($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.evaluate($SINK,...) + - pattern: $PAGE.evaluate($CODE,$SINK,...) + - pattern: $PAGE.evaluateHandle($SINK,...) + - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + message: Make sure that unverified user data can not reach `sandbox`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + shortlink: https://sg.run/KlwL + semgrep.dev: + rule: + r_id: 9255 + rv_id: 1263169 + rule_id: j2UvXB + version_id: jQTn59D + url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $SANDBOX = require('sandbox'); + ... + - pattern-either: + - patterns: + - pattern-inside: | + $S = new $SANDBOX(...); + ... + - pattern: | + $S.run(...) + - pattern: | + new $SANDBOX($OPTS).run(...) + - pattern: new $SANDBOX().run(...) +- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + message: Make sure that unverified user data can not reach the XML Parser, as it + can result in XML External or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + shortlink: https://sg.run/XBD4 + semgrep.dev: + rule: + r_id: 9264 + rv_id: 1263174 + rule_id: x8Uneb + version_id: bZT534J + url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $EXPAT.toJson($SINK,...) + - focus-metavariable: $SINK +- id: javascript.express.security.require-request.require-request + message: If an attacker controls the x in require(x) then they can cause code to + load that was not intended to run on the server. + options: + interfile: true + metadata: + interfile: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html + category: security + technology: + - express + references: + - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/javascript.express.security.require-request.require-request + shortlink: https://sg.run/jRbl + semgrep.dev: + rule: + r_id: 9265 + rv_id: 1263177 + rule_id: OrU3WK + version_id: w8TRo0d + url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern: require($SINK) + - focus-metavariable: $SINK +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + message: "Don\u2019t use the default session cookie name Using the default session + cookie name can open your app to attacks. The security issue posed is similar + to X-Powered-By: a potential attacker can use it to fingerprint the server and + target attacks accordingly." + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + shortlink: https://sg.run/1Z5x + semgrep.dev: + rule: + r_id: 9266 + rv_id: 1263130 + rule_id: eqU8k2 + version_id: bZT536J + url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {name:...} ...>,...) + - pattern-not-inside: | + $OPTS = <... {name:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.name = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + message: 'Default session middleware settings: `secure` not set. It ensures the + browser only sends the cookie over HTTPS.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + shortlink: https://sg.run/9oKz + semgrep.dev: + rule: + r_id: 9267 + rv_id: 1263131 + rule_id: v8Unzw + version_id: NdTzyrv + url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{secure:true}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {secure:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {secure:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.secure = true; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.secure = true; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + message: 'Default session middleware settings: `httpOnly` not set. It ensures the + cookie is sent only over HTTP(S), not client JavaScript, helping to protect against + cross-site scripting attacks.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + shortlink: https://sg.run/ydBO + semgrep.dev: + rule: + r_id: 9268 + rv_id: 1263132 + rule_id: d8UjGo + version_id: kbTzGev + url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{httpOnly:true}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {httpOnly:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {httpOnly:true} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.httpOnly = true; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.httpOnly = true; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + message: 'Default session middleware settings: `domain` not set. It indicates the + domain of the cookie; use it to compare against the domain of the server in which + the URL is being requested. If they match, then check the path attribute next.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + shortlink: https://sg.run/rd41 + semgrep.dev: + rule: + r_id: 9269 + rv_id: 1263133 + rule_id: ZqU5Pn + version_id: w8TRoyd + url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{domain:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {domain:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {domain:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.domain = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.domain = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + message: 'Default session middleware settings: `path` not set. It indicates the + path of the cookie; use it to compare against the request path. If this and domain + match, then send the cookie in the request.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + shortlink: https://sg.run/b7pd + semgrep.dev: + rule: + r_id: 9270 + rv_id: 1263134 + rule_id: nJUz4X + version_id: xyTjzQD + url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{path:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {path:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {path:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.path = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie.path = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + message: 'Default session middleware settings: `expires` not set. Use it to set + expiration date for persistent cookies.' + severity: WARNING + languages: + - javascript + - typescript + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + shortlink: https://sg.run/N4eG + semgrep.dev: + rule: + r_id: 9271 + rv_id: 1263135 + rule_id: EwU2DZ + version_id: O9TpxRq + url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + origin: community + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('cookie-session'); + ... + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) + - pattern-not-inside: | + $OPTS = <... {cookie:{expires:...}} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE = <... {expires:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $OPTS.cookie = <... {expires:...} ...>; + ... + $SESSION($OPTS,...); + - pattern-not-inside: | + $OPTS = ...; + ... + $COOKIE.expires = ...; + ... + $SESSION($OPTS,...); + - pattern-not-inside: |- + $OPTS = ...; + ... + $OPTS.cookie.expires = ...; + ... + $SESSION($OPTS,...); +- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + message: No token revoking configured for `express-jwt`. A leaked token could still + be used and unable to be revoked. Consider using function as the `isRevoked` option. + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecure Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - express + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + shortlink: https://sg.run/kXNo + semgrep.dev: + rule: + r_id: 9272 + rv_id: 1263137 + rule_id: 7KUQ9k + version_id: vdT06Bg + url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JWT = require('express-jwt'); + ... + - pattern: $JWT(...) + - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) + - pattern-not-inside: |- + $OPTS = <... {isRevoked:...} ...>; + ... + $JWT($OPTS,...); +- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + message: Possible writing outside of the destination, make sure that the target + path is nested in the intended destination + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + category: security + references: + - https://owasp.org/www-community/attacks/Path_Traversal + technology: + - express + - node.js + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + shortlink: https://sg.run/weRn + semgrep.dev: + rule: + r_id: 9273 + rv_id: 1263141 + rule_id: L1Uyb8 + version_id: ExTExX0 + url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern-inside: | + $PATH = require('path'); + ... + - pattern-inside: | + import $PATH from 'path'; + ... + - pattern-either: + - pattern: $PATH.join(...,$SINK,...) + - pattern: $PATH.resolve(...,$SINK,...) + - patterns: + - focus-metavariable: $SINK + - pattern-inside: | + import 'path'; + ... + - pattern-either: + - pattern: path.join(...,$SINK,...) + - pattern: path.resolve(...,$SINK,...) + pattern-sanitizers: + - pattern: $Y.replace(...) + - pattern: $Y.indexOf(...) + - pattern: | + function ... (...) { + ... + <... $Y.indexOf(...) ...> + ... + } + - patterns: + - pattern: $FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: sanitize +- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + message: Xml Parser is used inside Request Event. Make sure that unverified user + data can not reach the XML Parser, as it can result in XML External or Internal + Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + category: security + technology: + - express + references: + - https://www.npmjs.com/package/xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + shortlink: https://sg.run/x1AA + semgrep.dev: + rule: + r_id: 9274 + rv_id: 1263146 + rule_id: 8GUjkk + version_id: QkTGqgo + url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('xml2json'); + ... + - pattern-inside: | + import 'xml2json'; + ... + - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) + - focus-metavariable: $INPUT +- id: javascript.express.security.audit.res-render-injection.res-render-injection + message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to + the loading of other HTML/templating pages that they may not be authorized to + render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index` + to access other HTML pages on the file system. Where possible, do not allow users + to define what should be loaded in $RES.render or use an allow list for the existing + application. + options: + interfile: true + metadata: + interfile: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + category: security + technology: + - express + references: + - http://expressjs.com/en/4x/api.html#res.render + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection + shortlink: https://sg.run/eLjd + semgrep.dev: + rule: + r_id: 9276 + rv_id: 1263149 + rule_id: QrUzrq + version_id: PkTR3OY + url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.render($SINK, ...) + - focus-metavariable: $SINK +- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write + message: Detected directly writing to a Response object from user-defined input. + This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting + (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + vulnerability_class: + - Cross-Site-Scripting (XSS) + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write + shortlink: https://sg.run/vzGl + semgrep.dev: + rule: + r_id: 9277 + rv_id: 1263150 + rule_id: 3qUPA1 + version_id: JdTzxeg + url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.$SET('Content-Type', '$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + function ... ($REQ, $RES) { + ... + $RES.set('$TYPE') + } + - pattern-not-inside: | + $APP.$METHOD(..., function $FUNC($REQ, $RES) { + ... + $RES.set('$TYPE') + }) + - pattern-not-inside: | + function ... ($REQ, $RES, $NEXT) { + ... + $RES.set('$TYPE') + } + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response) => { + ... + $RES.$SET('Content-Type', '$TYPE') + } + - pattern-not-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + { + ... + $RES.set('$TYPE') + } + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: function ... (..., $RES,...) {...} + - pattern-either: + - pattern: $RES.write($ARG) + - pattern: $RES.send($ARG) + - pattern-not: $RES. ... .set('...'). ... .send($ARG) + - pattern-not: $RES. ... .type('...'). ... .send($ARG) + - pattern-not-inside: $RES.$METHOD({ ... }) + - focus-metavariable: $ARG + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'express-xss-sanitizer'; + ... + - pattern-inside: | + import * as $S from "express-xss-sanitizer"; + ... + - pattern-inside: | + const { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + var { ..., $S, ... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + let { ...,$S,... } = require('express-xss-sanitizer'); + ... + - pattern-inside: | + $S = require("express-xss-sanitizer") + ... + - pattern: $S(...) + - patterns: + - pattern: $RES. ... .type('$F'). ... .send(...) + - metavariable-regex: + metavariable: $F + regex: (?!.*text/html) + - patterns: + - pattern-inside: | + $X = [...]; + ... + - pattern: | + if(<... !$X.includes($SOURCE)...>) { + ... + return ... + } + ... + - pattern: $SOURCE +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/Ro1g + semgrep.dev: + rule: + r_id: 9293 + rv_id: 1263182 + rule_id: JDUyRl + version_id: d6TyxbX + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JOSE = require("jose"); + ... + - pattern-either: + - pattern-inside: | + var {JWT} = $JOSE; + ... + - pattern-inside: | + var {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + const {JWT} = $JOSE; + ... + - pattern-inside: | + const {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + let {JWT} = $JOSE; + ... + - pattern-inside: | + let {JWK, JWT} = $JOSE; + ... + - pattern-either: + - pattern: | + JWT.verify($P, "...", ...); + - pattern: | + JWT.sign($P, "...", ...); + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: | + $JWT.sign($P, JWK.asKey("..."), ...); + options: + symbolic_propagation: true + interfile: true +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + shortlink: https://sg.run/AvRL + semgrep.dev: + rule: + r_id: 9294 + rv_id: 1263183 + rule_id: 5rUOGN + version_id: ZRTKAyb + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern-either: + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + var $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + JWT.verify($P, JWK.None,...); +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - javascript + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/4xN9 + semgrep.dev: + rule: + r_id: 9300 + rv_id: 1263189 + rule_id: WAUon7 + version_id: gETB75D + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,"...",...); + - pattern-inside: | + $JWT.verify($DATA,"...",...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $JWT = require("jsonwebtoken") + ... + - pattern-inside: | + import $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import * as $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import {...,$JWT,...} from "jsonwebtoken" + ... + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,$VALUE,...); + - pattern-inside: | + $JWT.verify($DATA,$VALUE,...); + - focus-metavariable: $VALUE +- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + shortlink: https://sg.run/PJXv + semgrep.dev: + rule: + r_id: 9301 + rv_id: 1263190 + rule_id: 0oU53g + version_id: QkTGqQo + url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-inside: | + $JWT = require("jsonwebtoken"); + ... + - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) +- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + message: Detected use of dynamic execution of JavaScript which may come from user-input, + which can lead to Cross-Site-Scripting (XSS). Where possible avoid including user-input + in functions which dynamically execute user-input. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval! + category: security + technology: + - javascript + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + shortlink: https://sg.run/6nwK + semgrep.dev: + rule: + r_id: 9315 + rv_id: 1263214 + rule_id: yyUngo + version_id: WrTqKkJ + url: https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $PROP = new URLSearchParams($WINDOW. ... .location.search).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams(location.search).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams(location.hash.substring(1)).get('...') + ... + - focus-metavariable: $PROP + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.search) + ... + - pattern-inside: | + $PROPS = new + URLSearchParams($WINDOW. ... .location.hash.substring(1)) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.hash.substring(1)) + ... + - pattern: $PROPS.get('...') + - focus-metavariable: $PROPS + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval(<... $SINK ...>) + - pattern: window.eval(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>)(...) + - pattern: setTimeout(<... $SINK ...>,...) + - pattern: setInterval(<... $SINK ...>,...) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: location.href = $FUNC(...) + - pattern: location.hash = $FUNC(...) + - pattern: location.search = $FUNC(...) + - pattern: $WINDOW. ... .location.href = $FUNC(...) + - pattern: $WINDOW. ... .location.hash = $FUNC(...) + - pattern: $WINDOW. ... .location.search = $FUNC(...) +- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - nodejs + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + shortlink: https://sg.run/vz70 + semgrep.dev: + rule: + r_id: 9333 + rv_id: 1263225 + rule_id: QrUzq6 + version_id: X0TzyoE + url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + {..., clientSecret: "...", ...} + - pattern: | + {..., secretOrKey: "...", ...} + - pattern: | + {..., consumerSecret: "...", ...} + - patterns: + - pattern-inside: | + $OBJ = {} + ... + - pattern-either: + - pattern: | + $OBJ.clientSecret = "..." + - pattern: | + $OBJ.secretOrKey = "..." + - pattern: | + $OBJ.consumerSecret = "..." + - pattern: $OBJ + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern: | + {..., clientSecret: $SECRET, ...} + - pattern: | + {..., secretOrKey: $SECRET, ...} + - pattern: | + {..., consumerSecret: $SECRET, ...} + - patterns: + - pattern-inside: | + $SECRET = '...' + ... + - pattern-either: + - pattern-inside: | + $VALUE = {..., clientSecret: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., secretOrKey: $SECRET, ...} + ... + - pattern-inside: | + $VALUE = {..., consumerSecret: $SECRET, ...} + ... + - pattern: $VALUE + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $F = require("$I").Strategy + ... + - pattern-inside: | + $F = require("$I") + ... + - pattern-inside: | + import { $STRAT as $F } from '$I' + ... + - pattern-inside: | + import $F from '$I' + ... + - metavariable-regex: + metavariable: $I + regex: (passport-.*) + - pattern-inside: | + new $F($VALUE,...) + - focus-metavariable: $VALUE +- id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement + pattern: | + { + "Effect": "Allow", + "Principal": "*", + "Resource": [ + ..., "=~/arn:aws:s3.*/", ... + ], + ... + } + message: Detected public S3 bucket policy. This policy allows anyone to access certain + properties of or items in the bucket. Do not do this unless you will never have + sensitive data inside the bucket. + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + references: + - https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html + category: security + technology: + - aws + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + shortlink: https://sg.run/Yv1d + semgrep.dev: + rule: + r_id: 9358 + rv_id: 1263255 + rule_id: 9AU1br + version_id: A8Tgdxq + url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + origin: community + severity: WARNING + languages: + - json +- id: php.lang.security.assert-use.assert-use + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + - patterns: + - pattern: | + Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... }) + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern: assert($SINK, ...); + - pattern-not: assert("...", ...); + - pattern: $SINK + message: Calling assert with user input is equivalent to eval'ing. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + references: + - https://www.php.net/manual/en/function.assert + - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php + category: security + technology: + - php + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use + shortlink: https://sg.run/3xXW + semgrep.dev: + rule: + r_id: 9387 + rv_id: 1263272 + rule_id: DbUpjk + version_id: 9lT4bLx + url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use + origin: community + languages: + - php + severity: ERROR +- id: php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + patterns: + - pattern-either: + - pattern: | + $ARG = $IS_VERIFIED; + ... + curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $ARG); + - pattern: curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $IS_VERIFIED) + - metavariable-regex: + metavariable: $IS_VERIFIED + regex: 0|false|null + message: SSL verification is disabled but should not be (currently CURLOPT_SSL_VERIFYPEER= + $IS_VERIFIED) + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://www.saotn.org/dont-turn-off-curlopt_ssl_verifypeer-fix-php-configuration/ + category: security + technology: + - php + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + shortlink: https://sg.run/PJqv + semgrep.dev: + rule: + r_id: 9389 + rv_id: 1263277 + rule_id: 0oU5Xg + version_id: kbTzG9b + url: https://semgrep.dev/playground/r/kbTzG9b/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + origin: community + languages: + - php + severity: ERROR +- id: php.lang.security.phpinfo-use.phpinfo-use + pattern: phpinfo(...); + message: The 'phpinfo' function may reveal sensitive information about your environment. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + references: + - https://www.php.net/manual/en/function.phpinfo + - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/PhpinfosSniff.php + category: security + technology: + - php + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/php.lang.security.phpinfo-use.phpinfo-use + shortlink: https://sg.run/W82E + semgrep.dev: + rule: + r_id: 9397 + rv_id: 1263298 + rule_id: ReUglY + version_id: RGT0LN0 + url: https://semgrep.dev/playground/r/RGT0LN0/php.lang.security.phpinfo-use.phpinfo-use + origin: community + languages: + - php + severity: ERROR +- id: python.boto3.security.hardcoded-token.hardcoded-token + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://bento.dev/checks/boto3/hardcoded-access-token/ + - https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/ + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - boto3 + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token + shortlink: https://sg.run/LwQ6 + semgrep.dev: + rule: + r_id: 9439 + rv_id: 1263347 + rule_id: 5rUOwK + version_id: gETB78n + url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token + origin: community + languages: + - python + severity: WARNING + mode: taint + pattern-sources: + - pattern: | + "..." + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $W(...,$TOKEN="$VALUE",...) + - pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...) + - metavariable-regex: + metavariable: $TOKEN + regex: (aws_session_token|aws_access_key_id|aws_secret_access_key) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^AKI + - pattern-regex: ^[A-Za-z0-9/+=]+$ + - metavariable-analysis: + metavariable: $VALUE + analyzer: entropy +- id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + message: IDEA (International Data Encryption Algorithm) is a block cipher created + in 1991. It is an optional component of the OpenPGP standard. This cipher is + susceptible to attacks when using weak keys. It is recommended that you do not + use this cipher for new applications. Use a strong symmetric cipher such as EAS + instead. With the `cryptography` package it is recommended to use `Fernet` which + is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, + keep using the `Cipher` class from the hazmat primitives but use the AES algorithm + instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://tools.ietf.org/html/rfc5469 + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + shortlink: https://sg.run/3xyK + semgrep.dev: + rule: + r_id: 9443 + rv_id: 1263350 + rule_id: BYUNPg + version_id: 44TEjNJ + url: https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY) + - metavariable-regex: + metavariable: $IDEA + regex: ^(IDEA)$ + - focus-metavariable: $IDEA + fix: AES +- id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + message: ECB (Electronic Code Book) is the simplest mode of operation for block + ciphers. Each block of data is encrypted in the same way. This means identical + plaintext blocks will always result in identical ciphertext blocks, which can + leave significant patterns in the output. Use a different, cryptographically strong + mode instead, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B305 + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes + - https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption + category: security + technology: + - cryptography + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + functional-categories: + - crypto::search::mode::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + shortlink: https://sg.run/4xr5 + semgrep.dev: + rule: + r_id: 9444 + rv_id: 1263351 + rule_id: DbUp5g + version_id: PkTR3w7 + url: https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + origin: community + severity: WARNING + languages: + - python + pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV) + fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV) +- id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$SHA(...) + - metavariable-pattern: + metavariable: $SHA + pattern: | + SHA1 + - focus-metavariable: $SHA + fix: | + SHA256 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B303 + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + shortlink: https://sg.run/J9Qy + semgrep.dev: + rule: + r_id: 9446 + rv_id: 1263353 + rule_id: 0oU5dN + version_id: 5PTo1l0 + url: https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + origin: community + severity: WARNING + languages: + - python +- id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(..., + key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE, + ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 + - focus-metavariable: $SIZE + fix: | + 2048 + message: Detected an insufficient key size for DSA. NIST recommends a key size of + 2048 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::key-length::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + shortlink: https://sg.run/5Qb0 + semgrep.dev: + rule: + r_id: 9447 + rv_id: 1263354 + rule_id: KxUb0x + version_id: GxTkeOK + url: https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + origin: community + languages: + - python + severity: WARNING +- id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + patterns: + - pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...) + - pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE + - metavariable-pattern: + metavariable: $SIZE + pattern-either: + - pattern: SECP192R1 + - pattern: SECT163K1 + - pattern: SECT163R2 + - focus-metavariable: $SIZE + fix: | + SECP256R1 + message: Detected an insufficient curve size for EC. NIST recommends a key size + of 224 or higher. For example, use 'ec.SECP256R1'. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves + category: security + technology: + - cryptography + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::key-length::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + shortlink: https://sg.run/GeQq + semgrep.dev: + rule: + r_id: 9448 + rv_id: 1263355 + rule_id: qNUjZ3 + version_id: RGT0LW6 + url: https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + origin: community + languages: + - python + severity: WARNING +- id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(..., + key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP, + $SIZE, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 + - focus-metavariable: $SIZE + fix: | + 2048 + message: Detected an insufficient key size for RSA. NIST recommends a key size of + 2048 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + category: security + technology: + - cryptography + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::key-length::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/RoQq + semgrep.dev: + rule: + r_id: 9449 + rv_id: 1263356 + rule_id: lBU9jn + version_id: A8TgdPK + url: https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + languages: + - python + severity: WARNING +- id: python.distributed.security.require-encryption + patterns: + - pattern: | + distributed.security.Security(..., require_encryption=$VAL, ...) + - metavariable-pattern: + metavariable: $VAL + pattern: | + False + - focus-metavariable: $VAL + fix: | + True + message: Initializing a security context for Dask (`distributed`) without "require_encryption" + keyword argument may silently fail to provide security. + severity: WARNING + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters + category: security + technology: + - distributed + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.distributed.security.require-encryption + shortlink: https://sg.run/AvQ2 + semgrep.dev: + rule: + r_id: 9450 + rv_id: 1263358 + rule_id: YGURy0 + version_id: DkTRbol + url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption + origin: community + languages: + - python +- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + shortlink: https://sg.run/9oyr + semgrep.dev: + rule: + r_id: 9467 + rv_id: 1409400 + rule_id: OrU3e6 + version_id: GxTlb9e + url: https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + origin: community + message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`, + `cpickle`, `dill`, `shelve`, or `yaml`, which are known to lead to remote code + execution vulnerabilities. + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: | + def $INSIDE(..., $PARAM, ...): + ... + - pattern-either: + - pattern: request.$REQFUNC(...) + - pattern: request.$REQFUNC.get(...) + - pattern: request.$REQFUNC[...] + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + pickle.$PICKLEFUNC(...) + - pattern: | + _pickle.$PICKLEFUNC(...) + - pattern: | + cPickle.$PICKLEFUNC(...) + - pattern: | + shelve.$PICKLEFUNC(...) + - metavariable-regex: + metavariable: $PICKLEFUNC + regex: dumps|dump|load|loads + - patterns: + - pattern: dill.$DILLFUNC(...) + - metavariable-regex: + metavariable: $DILLFUNC + regex: dump|dump_session|dumps|load|load_session|loads + - patterns: + - pattern: yaml.$YAMLFUNC(...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...) + - metavariable-regex: + metavariable: $YAMLFUNC + regex: dump|dump_all|load|load_all +- id: python.django.security.injection.open-redirect.open-redirect + message: Data from request ($DATA) is passed to redirect(). This is an open redirect + and could be exploited. Ensure you are redirecting to safe URLs by using django.utils.http.is_safe_url(). + See https://cwe.mitre.org/data/definitions/601.html for more information. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/ + - https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231 + category: security + technology: + - django + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect + shortlink: https://sg.run/Ave2 + semgrep.dev: + rule: + r_id: 9494 + rv_id: 1263393 + rule_id: PeUZgr + version_id: 3ZT4XD7 + url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-not-inside: | + def $FUNC(...): + ... + django.utils.http.is_safe_url(...) + ... + - pattern-not-inside: | + def $FUNC(...): + ... + if <... django.utils.http.is_safe_url(...) ...>: + ... + - pattern-not-inside: | + def $FUNC(...): + ... + django.utils.http.url_has_allowed_host_and_scheme(...) + ... + - pattern-not-inside: | + def $FUNC(...): + ... + if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>: + ... + - pattern-either: + - pattern: django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.shortcuts.redirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.shortcuts.redirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.shortcuts.redirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.shortcuts.redirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", + ...) + - pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), + ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + django.shortcuts.redirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.shortcuts.redirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.shortcuts.redirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.shortcuts.redirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), + ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + django.shortcuts.redirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.shortcuts.redirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.shortcuts.redirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.shortcuts.redirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W, ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + django.shortcuts.redirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.shortcuts.redirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.shortcuts.redirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.shortcuts.redirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.shortcuts.redirect(..., $INTERM, ...) + - pattern: $A = django.shortcuts.redirect(..., request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...), + ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W, ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...), + ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", + ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseRedirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseRedirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseRedirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...), + ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", + ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...), + ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseRedirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseRedirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseRedirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", + ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...), + ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", + ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseRedirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseRedirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseRedirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", + ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...], + ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", + ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), + ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseRedirect(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseRedirect(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseRedirect(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseRedirect(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W, + ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W, + ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...", + ...) + - metavariable-regex: + metavariable: $W + regex: (?!get_full_path) +- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + message: Found user-controlled request data passed into HttpResponse. This could + be vulnerable to XSS, leading to attackers gaining access to user cookies and + protected information. Ensure that the request data is properly escaped or sanitzed. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + shortlink: https://sg.run/BkvA + semgrep.dev: + rule: + r_id: 9495 + rv_id: 1263398 + rule_id: JDUydR + version_id: GxTke5K + url: https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...), + ...) + - pattern: django.http.HttpResponse(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponse(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponse(..., request.$W[...], ...) + - pattern: return django.http.HttpResponse(..., request.$W[...], ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W, ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., f"...{$DATA}...", ...) + - pattern: $A = django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $A = django.http.HttpResponse(..., $INTERM, ...) + - pattern: return django.http.HttpResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponse(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponse(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponse(..., $INTERM, ...) +- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + message: Found user-controlled request data passed into a HttpResponseBadRequest. + This could be vulnerable to XSS, leading to attackers gaining access to user cookies + and protected information. Ensure that the request data is properly escaped or + sanitzed. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + shortlink: https://sg.run/DoZP + semgrep.dev: + rule: + r_id: 9496 + rv_id: 1263399 + rule_id: 5rUOX1 + version_id: RGT0LY6 + url: https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...), + ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...", + ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W, + ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.http.HttpResponseBadRequest(..., $INTERM, ...) + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...) +- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse + message: Found user-controlled request data being passed into a file open, which + is them passed as an argument into the FileResponse. This is dangerous because + an attacker could specify an arbitrary file to read, which could result in leaking + important data. Be sure to validate or sanitize the user-inputted filename in + the request data before using it in FileResponse. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + shortlink: https://sg.run/W862 + semgrep.dev: + rule: + r_id: 9497 + rv_id: 1263400 + rule_id: GdU7QR + version_id: A8Tgd1K + url: https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: return django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: django.http.FileResponse(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W(...), ...) + - pattern: return django.http.FileResponse(..., request.$W(...), ...) + - pattern: django.http.FileResponse(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W[...], ...) + - pattern: return django.http.FileResponse(..., request.$W[...], ...) + - pattern: django.http.FileResponse(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.http.FileResponse(..., open($DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = open($DATA, ...) + ... + django.http.FileResponse(..., $INTERM, ...) + - pattern: $A = django.http.FileResponse(..., request.$W, ...) + - pattern: return django.http.FileResponse(..., request.$W, ...) +- id: python.django.security.injection.request-data-write.request-data-write + message: Found user-controlled request data passed into '.write(...)'. This could + be dangerous if a malicious actor is able to control data into sensitive files. + For example, a malicious actor could force rolling of critical log files, or cause + a denial-of-service by using up available disk space. Instead, ensure that request + data is properly escaped or sanitized. + metadata: + cwe: + - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write + shortlink: https://sg.run/0Q6j + semgrep.dev: + rule: + r_id: 9498 + rv_id: 1263401 + rule_id: ReUg5z + version_id: BjTkZO5 + url: https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write + origin: community + languages: + - python + severity: WARNING + pattern-either: + - pattern: $F.write(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $F.write(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $F.write(..., $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $F.write(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $F.write(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $F.write(..., $INTERM, ...) + - pattern: $A = $F.write(..., request.$W.get(...), ...) + - pattern: return $F.write(..., request.$W.get(...), ...) + - pattern: $F.write(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $F.write(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $F.write(..., $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $F.write(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $F.write(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $F.write(..., $INTERM, ...) + - pattern: $A = $F.write(..., request.$W(...), ...) + - pattern: return $F.write(..., request.$W(...), ...) + - pattern: $F.write(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $F.write(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $F.write(..., $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $F.write(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $F.write(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $F.write(..., $INTERM, ...) + - pattern: $A = $F.write(..., request.$W[...], ...) + - pattern: return $F.write(..., request.$W[...], ...) + - pattern: $F.write(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $F.write(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $F.write(..., $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $F.write(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $F.write(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $F.write(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $F.write(..., $INTERM, ...) + - pattern: $A = $F.write(..., request.$W, ...) + - pattern: return $F.write(..., request.$W, ...) +- id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string + message: Found user data in a call to 'eval'. This is extremely dangerous because + it can enable an attacker to execute remote code. See https://owasp.org/www-community/attacks/Code_Injection + for more information. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + category: security + technology: + - django + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + shortlink: https://sg.run/4x2z + semgrep.dev: + rule: + r_id: 9500 + rv_id: 1263383 + rule_id: BYUNw9 + version_id: vdT06xG + url: https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + origin: community + patterns: + - pattern-inside: | + def $F(...): + ... + - pattern-either: + - pattern: eval(..., $STR % request.$W.get(...), ...) + - pattern: | + $V = request.$W.get(...) + ... + eval(..., $STR % $V, ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = $STR % $V + ... + eval(..., $S, ...) + - pattern: eval(..., "..." % request.$W(...), ...) + - pattern: | + $V = request.$W(...) + ... + eval(..., $STR % $V, ...) + - pattern: | + $V = request.$W(...) + ... + $S = $STR % $V + ... + eval(..., $S, ...) + - pattern: eval(..., $STR % request.$W[...], ...) + - pattern: | + $V = request.$W[...] + ... + eval(..., $STR % $V, ...) + - pattern: | + $V = request.$W[...] + ... + $S = $STR % $V + ... + eval(..., $S, ...) + - pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: | + $V = request.$W.get(...) + ... + eval(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = $STR.format(..., $V, ...) + ... + eval(..., $S, ...) + - pattern: eval(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: | + $V = request.$W(...) + ... + eval(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W(...) + ... + $S = $STR.format(..., $V, ...) + ... + eval(..., $S, ...) + - pattern: eval(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: | + $V = request.$W[...] + ... + eval(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W[...] + ... + $S = $STR.format(..., $V, ...) + ... + eval(..., $S, ...) + - pattern: | + $V = request.$W.get(...) + ... + eval(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = f"...{$V}..." + ... + eval(..., $S, ...) + - pattern: | + $V = request.$W(...) + ... + eval(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W(...) + ... + $S = f"...{$V}..." + ... + eval(..., $S, ...) + - pattern: | + $V = request.$W[...] + ... + eval(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W[...] + ... + $S = f"...{$V}..." + ... + eval(..., $S, ...) + languages: + - python + severity: WARNING +- id: python.django.security.injection.code.user-eval.user-eval + message: Found user data in a call to 'eval'. This is extremely dangerous because + it can enable an attacker to execute arbitrary remote code on the system. Instead, + refactor your code to not use 'eval' and instead use a safe library for the specific + functionality you need. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + - https://owasp.org/www-community/attacks/Code_Injection + category: security + technology: + - django + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval + shortlink: https://sg.run/PJDW + semgrep.dev: + rule: + r_id: 9501 + rv_id: 1263384 + rule_id: DbUpDQ + version_id: d6Tyx2A + url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval + origin: community + patterns: + - pattern-inside: | + def $F(...): + ... + - pattern-either: + - pattern: eval(..., request.$W.get(...), ...) + - pattern: | + $V = request.$W.get(...) + ... + eval(..., $V, ...) + - pattern: eval(..., request.$W(...), ...) + - pattern: | + $V = request.$W(...) + ... + eval(..., $V, ...) + - pattern: eval(..., request.$W[...], ...) + - pattern: | + $V = request.$W[...] + ... + eval(..., $V, ...) + languages: + - python + severity: WARNING +- id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string + message: Found user data in a call to 'exec'. This is extremely dangerous because + it can enable an attacker to execute arbitrary remote code on the system. Instead, + refactor your code to not use 'eval' and instead use a safe library for the specific + functionality you need. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://owasp.org/www-community/attacks/Code_Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + shortlink: https://sg.run/J9JW + semgrep.dev: + rule: + r_id: 9502 + rv_id: 1263385 + rule_id: WAUovx + version_id: ZRTKA1p + url: https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + origin: community + patterns: + - pattern-inside: | + def $F(...): + ... + - pattern-either: + - pattern: exec(..., $STR % request.$W.get(...), ...) + - pattern: | + $V = request.$W.get(...) + ... + exec(..., $STR % $V, ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = $STR % $V + ... + exec(..., $S, ...) + - pattern: exec(..., "..." % request.$W(...), ...) + - pattern: | + $V = request.$W(...) + ... + exec(..., $STR % $V, ...) + - pattern: | + $V = request.$W(...) + ... + $S = $STR % $V + ... + exec(..., $S, ...) + - pattern: exec(..., $STR % request.$W[...], ...) + - pattern: | + $V = request.$W[...] + ... + exec(..., $STR % $V, ...) + - pattern: | + $V = request.$W[...] + ... + $S = $STR % $V + ... + exec(..., $S, ...) + - pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: | + $V = request.$W.get(...) + ... + exec(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = $STR.format(..., $V, ...) + ... + exec(..., $S, ...) + - pattern: exec(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: | + $V = request.$W(...) + ... + exec(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W(...) + ... + $S = $STR.format(..., $V, ...) + ... + exec(..., $S, ...) + - pattern: exec(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: | + $V = request.$W[...] + ... + exec(..., $STR.format(..., $V, ...), ...) + - pattern: | + $V = request.$W[...] + ... + $S = $STR.format(..., $V, ...) + ... + exec(..., $S, ...) + - pattern: | + $V = request.$W.get(...) + ... + exec(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W.get(...) + ... + $S = f"...{$V}..." + ... + exec(..., $S, ...) + - pattern: | + $V = request.$W(...) + ... + exec(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W(...) + ... + $S = f"...{$V}..." + ... + exec(..., $S, ...) + - pattern: | + $V = request.$W[...] + ... + exec(..., f"...{$V}...", ...) + - pattern: | + $V = request.$W[...] + ... + $S = f"...{$V}..." + ... + exec(..., $S, ...) + - pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...), + ...), ...) + - pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...), + ...) + - pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...), + ...), ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...), + ...), ...) + - pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...", + ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...), + ...) + - pattern: | + $DATA = request.$W.get(...) + ... + exec(..., base64.decodestring($DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = base64.decodestring($DATA, ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = base64.decodestring(bytes($DATA, ...), ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + exec(..., base64.decodestring($DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = base64.decodestring($DATA, ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = base64.decodestring(bytes($DATA, ...), ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + exec(..., base64.decodestring($DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = base64.decodestring($DATA, ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = base64.decodestring(bytes($DATA, ...), ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + exec(..., base64.decodestring($DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = base64.decodestring($DATA, ...) + ... + exec(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = base64.decodestring(bytes($DATA, ...), ...) + ... + exec(..., $INTERM, ...) + languages: + - python + severity: WARNING +- id: python.django.security.injection.code.user-exec.user-exec + message: Found user data in a call to 'exec'. This is extremely dangerous because + it can enable an attacker to execute arbitrary remote code on the system. Instead, + refactor your code to not use 'eval' and instead use a safe library for the specific + functionality you need. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://owasp.org/www-community/attacks/Code_Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec + shortlink: https://sg.run/5Q3X + semgrep.dev: + rule: + r_id: 9503 + rv_id: 1263386 + rule_id: 0oU5AW + version_id: nWT2LA2 + url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec + origin: community + patterns: + - pattern-inside: | + def $F(...): + ... + - pattern-either: + - pattern: exec(..., request.$W.get(...), ...) + - pattern: | + $V = request.$W.get(...) + ... + exec(..., $V, ...) + - pattern: exec(..., request.$W(...), ...) + - pattern: | + $V = request.$W(...) + ... + exec(..., $V, ...) + - pattern: exec(..., request.$W[...], ...) + - pattern: | + $V = request.$W[...] + ... + exec(..., $V, ...) + - pattern: | + loop = asyncio.get_running_loop() + ... + await loop.run_in_executor(None, exec, request.$W[...]) + - pattern: | + $V = request.$W[...] + ... + loop = asyncio.get_running_loop() + ... + await loop.run_in_executor(None, exec, $V) + - pattern: | + loop = asyncio.get_running_loop() + ... + await loop.run_in_executor(None, exec, request.$W.get(...)) + - pattern: | + $V = request.$W.get(...) + ... + loop = asyncio.get_running_loop() + ... + await loop.run_in_executor(None, exec, $V) + languages: + - python + severity: WARNING +- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system + message: Request data detected in os.system. This could be vulnerable to a command + injection and should be avoided. If this must be done, use the 'subprocess' module + instead and pass the arguments as a list. See https://owasp.org/www-community/attacks/Command_Injection + for more information. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + shortlink: https://sg.run/Gen2 + semgrep.dev: + rule: + r_id: 9504 + rv_id: 1263387 + rule_id: KxUbp2 + version_id: ExTExPo + url: https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: os.system(..., request.$W.get(...), ...) + - pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: os.system(..., $S % request.$W.get(...), ...) + - pattern: os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W.get(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W.get(...), ...) + - pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: return os.system(..., request.$W.get(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return os.system(..., $S % request.$W.get(...), ...) + - pattern: return os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: os.system(..., request.$W(...), ...) + - pattern: os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: os.system(..., $S % request.$W(...), ...) + - pattern: os.system(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W(...), ...) + - pattern: $A = os.system(..., f"...{request.$W(...)}...", ...) + - pattern: return os.system(..., request.$W(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return os.system(..., $S % request.$W(...), ...) + - pattern: return os.system(..., f"...{request.$W(...)}...", ...) + - pattern: os.system(..., request.$W[...], ...) + - pattern: os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: os.system(..., $S % request.$W[...], ...) + - pattern: os.system(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W[...], ...) + - pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = os.system(..., $S % request.$W[...], ...) + - pattern: $A = os.system(..., f"...{request.$W[...]}...", ...) + - pattern: return os.system(..., request.$W[...], ...) + - pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return os.system(..., $S % request.$W[...], ...) + - pattern: return os.system(..., f"...{request.$W[...]}...", ...) + - pattern: os.system(..., request.$W, ...) + - pattern: os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: os.system(..., $S % request.$W, ...) + - pattern: os.system(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + os.system(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + os.system(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + os.system(..., $INTERM, ...) + - pattern: $A = os.system(..., request.$W, ...) + - pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = os.system(..., $S % request.$W, ...) + - pattern: $A = os.system(..., f"...{request.$W}...", ...) + - pattern: return os.system(..., request.$W, ...) + - pattern: return os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: return os.system(..., $S % request.$W, ...) + - pattern: return os.system(..., f"...{request.$W}...", ...) +- id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body + message: Found request data in an EmailMessage that is set to use HTML. This is + dangerous because HTML emails are susceptible to XSS. An attacker could inject + data into this HTML email, causing XSS. + metadata: + cwe: + - 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream + Component (''Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + category: security + technology: + - django + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + shortlink: https://sg.run/RoBe + semgrep.dev: + rule: + r_id: 9505 + rv_id: 1263390 + rule_id: qNUj02 + version_id: 8KT5rOn + url: https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + $EMAIL.content_subtype = "html" + ... + - pattern-either: + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.EmailMessage($SUBJ, $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.EmailMessage($SUBJ, $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.EmailMessage($SUBJ, $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.EmailMessage($SUBJ, $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $B.$C(..., $DATA, ...) + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.EmailMessage($SUBJ, $INTERM, ...) + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...) +- id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + message: Found request data in 'send_mail(...)' that uses 'html_message'. This is + dangerous because HTML emails are susceptible to XSS. An attacker could inject + data into this HTML email, causing XSS. + metadata: + cwe: + - 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream + Component (''Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + category: security + technology: + - django + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + shortlink: https://sg.run/Avx8 + semgrep.dev: + rule: + r_id: 9506 + rv_id: 1263391 + rule_id: lBU9Ll + version_id: gETB7Gn + url: https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.send_mail(..., html_message=$DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...), + ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...), + ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.send_mail(..., html_message=$DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...), + ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W(...), + ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.send_mail(..., html_message=$DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...], + ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W[...], + ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.send_mail(..., html_message=$DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.core.mail.send_mail(..., html_message=$INTERM, ...) + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...) +- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + message: Found request data in a call to 'open'. Ensure the request data is validated + or sanitized, otherwise it could result in path traversal attacks and therefore + sensitive data being leaked. To mitigate, consider using os.path.abspath or os.path.realpath + or the pathlib library. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + shortlink: https://sg.run/W8qg + semgrep.dev: + rule: + r_id: 9509 + rv_id: 1263396 + rule_id: oqUe7z + version_id: JdTzxAw + url: https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: open(..., request.$W.get(...), ...) + - pattern: open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: open(..., $S % request.$W.get(...), ...) + - pattern: open(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W.get(...) + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W.get(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = open(..., $S % request.$W.get(...), ...) + - pattern: $A = open(..., f"...{request.$W.get(...)}...", ...) + - pattern: return open(..., request.$W.get(...), ...) + - pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return open(..., $S % request.$W.get(...), ...) + - pattern: return open(..., f"...{request.$W.get(...)}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W(...), ...) + - pattern: open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: open(..., $S % request.$W(...), ...) + - pattern: open(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W(...) + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = open(..., $S % request.$W(...), ...) + - pattern: $A = open(..., f"...{request.$W(...)}...", ...) + - pattern: return open(..., request.$W(...), ...) + - pattern: return open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return open(..., $S % request.$W(...), ...) + - pattern: return open(..., f"...{request.$W(...)}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W[...], ...) + - pattern: open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: open(..., $S % request.$W[...], ...) + - pattern: open(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W[...] + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W[...], ...) + - pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = open(..., $S % request.$W[...], ...) + - pattern: $A = open(..., f"...{request.$W[...]}...", ...) + - pattern: return open(..., request.$W[...], ...) + - pattern: return open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return open(..., $S % request.$W[...], ...) + - pattern: return open(..., f"...{request.$W[...]}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + with open(..., $DATA, ...) as $FD: + ... + - pattern: open(..., request.$W, ...) + - pattern: open(..., $S.format(..., request.$W, ...), ...) + - pattern: open(..., $S % request.$W, ...) + - pattern: open(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + open(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: | + $DATA = request.$W + ... + open(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + open(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + with open(..., $INTERM, ...) as $FD: + ... + - pattern: $A = open(..., request.$W, ...) + - pattern: $A = open(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = open(..., $S % request.$W, ...) + - pattern: $A = open(..., f"...{request.$W}...", ...) + - pattern: return open(..., request.$W, ...) + - pattern: return open(..., $S.format(..., request.$W, ...), ...) + - pattern: return open(..., $S % request.$W, ...) + - pattern: return open(..., f"...{request.$W}...", ...) + - pattern: | + $DATA = request.$W + ... + with open(..., $DATA, ...) as $FD: + ... +- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + message: User-controlled data from a request is passed to 'extra()'. This could + lead to a SQL injection and therefore protected information could be leaked. Instead, + use parameterized queries or escape the user-controlled data by using `params` + and not using quote placeholders in the SQL string. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + shortlink: https://sg.run/0Ql5 + semgrep.dev: + rule: + r_id: 9510 + rv_id: 1263402 + rule_id: zdUkx1 + version_id: DkTRb4l + url: https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...), + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...", + ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], + ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...), + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...], + ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...), + ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...], + ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) +- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + message: User-controlled data from request is passed to 'RawSQL()'. This could lead + to a SQL injection and therefore protected information could be leaked. Instead, + use parameterized queries or escape the user-controlled data by using `params` + and not using quote placeholders in the SQL string. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + shortlink: https://sg.run/Kl4X + semgrep.dev: + rule: + r_id: 9511 + rv_id: 1263403 + rule_id: pKUOBp + version_id: WrTqK2L + url: https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...), + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...), + ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...), + ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...), + ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...), + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...], + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...", + ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W, + ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + django.db.models.expressions.RawSQL(..., $INTERM, ...) + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + django.db.models.expressions.RawSQL($INTERM, ...) +- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + message: User-controlled data from a request is passed to 'execute()'. This could + lead to a SQL injection and therefore protected information could be leaked. Instead, + use django's QuerySets, which are built with query parameterization and therefore + not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + shortlink: https://sg.run/qx7y + semgrep.dev: + rule: + r_id: 9512 + rv_id: 1263404 + rule_id: 2ZUbDL + version_id: 0bTKzRj + url: https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: return $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W(...), ...) + - pattern: return $CURSOR.execute(..., request.$W(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W[...], ...) + - pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...) + - pattern: $CURSOR.execute(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W[...], ...) + - pattern: return $CURSOR.execute(..., request.$W[...], ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W, ...) + - pattern: $CURSOR.execute(..., f"...{request.$W}...", ...) + - pattern: $CURSOR.execute(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $CURSOR.execute(..., $INTERM, ...) + - pattern: $A = $CURSOR.execute(..., request.$W, ...) + - pattern: return $CURSOR.execute(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $CURSOR.execute($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) + - pattern: |- + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $CURSOR.execute($INTERM, ...) +- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + message: Data that is possible user-controlled from a python request is passed to + `raw()`. This could lead to SQL injection and attackers gaining access to protected + information. Instead, use django's QuerySets, which are built with query parameterization + and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + shortlink: https://sg.run/l2v9 + semgrep.dev: + rule: + r_id: 9513 + rv_id: 1263405 + rule_id: X5U8v5 + version_id: K3TKkBW + url: https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: return $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W, ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + $MODEL.objects.raw(..., $INTERM, ...) + - pattern: $A = $MODEL.objects.raw(..., request.$W, ...) + - pattern: return $MODEL.objects.raw(..., request.$W, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $MODEL.objects.raw($STR % (..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % (..., $DATA, ...) + ... + $MODEL.objects.raw($INTERM, ...) +- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. See https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + to learn more about SSRF vulnerabilities. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + shortlink: https://sg.run/YvY4 + semgrep.dev: + rule: + r_id: 9514 + rv_id: 1263406 + rule_id: j2UvEw + version_id: qkTR7zn + url: https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W.get(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W.get(...), ...) + - pattern: return requests.$METHOD(..., request.$W.get(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W(...), ...) + - pattern: return requests.$METHOD(..., request.$W(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W[...], ...) + - pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...) + - pattern: requests.$METHOD(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W[...], ...) + - pattern: return requests.$METHOD(..., request.$W[...], ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W, ...) + - pattern: requests.$METHOD(..., f"...{request.$W}...", ...) + - pattern: requests.$METHOD(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + requests.$METHOD(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + requests.$METHOD(..., $INTERM, ...) + - pattern: $A = requests.$METHOD(..., request.$W, ...) + - pattern: return requests.$METHOD(..., request.$W, ...) +- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF), which could result in attackers + gaining access to private organization data. To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - django + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + shortlink: https://sg.run/6n2B + semgrep.dev: + rule: + r_id: 9515 + rv_id: 1263407 + rule_id: 10UKDo + version_id: l4TJRwD + url: https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-inside: | + def $FUNC(...): + ... + - pattern-either: + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...), + ...) + - pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W.get(...) + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W(...), ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W(...) + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W(...) + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W[...], ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...) + - pattern: urllib.request.urlopen(..., request.$W[...], ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W[...] + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W[...] + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W[...], ...) + - pattern: return urllib.request.urlopen(..., request.$W[...], ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W, ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...) + - pattern: urllib.request.urlopen(..., request.$W, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR.format(..., $DATA, ...) + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR % $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR % $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., f"...{$DATA}...", ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = f"...{$DATA}..." + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: | + $DATA = request.$W + ... + urllib.request.urlopen(..., $STR + $DATA, ...) + - pattern: | + $DATA = request.$W + ... + $INTERM = $STR + $DATA + ... + urllib.request.urlopen(..., $INTERM, ...) + - pattern: $A = urllib.request.urlopen(..., request.$W, ...) + - pattern: return urllib.request.urlopen(..., request.$W, ...) +- id: python.django.security.passwords.password-empty-string.password-empty-string + message: '''$VAR'' is the empty string and is being used to set the password on + ''$MODEL''. If you meant to set an unusable password, set the password to None + or call ''set_unusable_password()''.' + metadata: + cwe: + - 'CWE-521: Weak Password Requirements' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + category: security + technology: + - django + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string + shortlink: https://sg.run/oxnR + semgrep.dev: + rule: + r_id: 9516 + rv_id: 1263411 + rule_id: 9AU1jW + version_id: GxTke5Q + url: https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string + origin: community + patterns: + - pattern-either: + - pattern: | + $MODEL.set_password($EMPTY) + ... + $MODEL.save() + - pattern: | + $VAR = $EMPTY + ... + $MODEL.set_password($VAR) + ... + $MODEL.save() + - metavariable-regex: + metavariable: $EMPTY + regex: (\'\'|\"\") + languages: + - python + severity: ERROR +- id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + message: '''$VAR'' is using the empty string as its default and is being used to + set the password on ''$MODEL''. If you meant to set an unusable password, set + the default value to ''None'' or call ''set_unusable_password()''.' + metadata: + cwe: + - 'CWE-521: Weak Password Requirements' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + category: security + technology: + - django + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + shortlink: https://sg.run/zvBW + semgrep.dev: + rule: + r_id: 9517 + rv_id: 1263412 + rule_id: yyUn6Z + version_id: RGT0LYX + url: https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + origin: community + languages: + - python + severity: ERROR + patterns: + - pattern-either: + - pattern: | + $VAR = request.$W.get($X, $EMPTY) + ... + $MODEL.set_password($VAR) + ... + $MODEL.save(...) + - pattern: | + def $F(..., $VAR=$EMPTY, ...): + ... + $MODEL.set_password($VAR) + - metavariable-pattern: + metavariable: $EMPTY + pattern: '""' + - focus-metavariable: $EMPTY + fix: | + None +- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + message: Running flask app with host 0.0.0.0 could expose the server publicly. + metadata: + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - flask + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + shortlink: https://sg.run/eLby + semgrep.dev: + rule: + r_id: 9532 + rv_id: 1263414 + rule_id: L1Uy1n + version_id: BjTkZOY + url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + origin: community + languages: + - python + severity: WARNING + pattern-either: + - pattern: app.run(..., host="0.0.0.0", ...) + - pattern: app.run(..., "0.0.0.0", ...) +- id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + patterns: + - pattern-not-inside: | + if __name__ == '__main__': + ... + - pattern-not-inside: | + def $X(...): + ... + - pattern: app.run(...) + message: top-level app.run(...) is ignored by flask. Consider putting app.run(...) + behind a guard, like inside a function + metadata: + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - flask + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + shortlink: https://sg.run/vz5b + semgrep.dev: + rule: + r_id: 9533 + rv_id: 1263415 + rule_id: 8GUjdX + version_id: DkTRb4z + url: https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + origin: community + languages: + - python + severity: WARNING +- id: python.flask.security.audit.debug-enabled.debug-enabled + patterns: + - pattern-inside: | + import flask + ... + - pattern: $APP.run(..., debug=True, ...) + message: Detected Flask app with debug=True. Do not deploy to production with this + flag enabled as it will leak sensitive information. Instead, consider using Flask + configuration variables or setting 'debug' using system environment variables. + metadata: + cwe: + - 'CWE-489: Active Debug Code' + owasp: A06:2017 - Security Misconfiguration + references: + - https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ + category: security + technology: + - flask + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled + shortlink: https://sg.run/dKrd + semgrep.dev: + rule: + r_id: 9534 + rv_id: 946206 + rule_id: gxU1bd + version_id: 8KTKjwR + url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled + origin: community + severity: WARNING + languages: + - python +- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + message: Detected Flask route directly returning a formatted string. This is subject + to cross-site scripting if user input can reach the string. Consider using the + template engine instead and rendering pages with 'render_template()'. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + shortlink: https://sg.run/Zv6o + semgrep.dev: + rule: + r_id: 9535 + rv_id: 1263416 + rule_id: QrUz49 + version_id: WrTqKAz + url: https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + origin: community + languages: + - python + severity: WARNING + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $PARAM, ...): + ... + - pattern: $PARAM + - pattern: | + request.$FUNC.get(...) + - pattern: | + request.$FUNC(...) + - pattern: request.$FUNC[...] + pattern-sinks: + - patterns: + - pattern-not-inside: return "..." + - pattern-either: + - pattern: return "...".format(...) + - pattern: return "..." % ... + - pattern: return "..." + ... + - pattern: return ... + "..." + - pattern: return f"...{...}..." + - patterns: + - pattern: return $X + - pattern-either: + - pattern-inside: | + $X = "...".format(...) + ... + - pattern-inside: | + $X = "..." % ... + ... + - pattern-inside: | + $X = "..." + ... + ... + - pattern-inside: | + $X = ... + "..." + ... + - pattern-inside: | + $X = f"...{...}..." + ... + - pattern-not-inside: | + $X = "..." + ... +- id: python.flask.security.injection.os-system-injection.os-system-injection + languages: + - python + severity: ERROR + message: User data detected in os.system. This could be vulnerable to a command + injection and should be avoided. If this must be done, use the 'subprocess' module + instead and pass the arguments as a list. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection + shortlink: https://sg.run/4xzz + semgrep.dev: + rule: + r_id: 9544 + rv_id: 1263429 + rule_id: BYUN99 + version_id: 1QTypw7 + url: https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection + origin: community + pattern-either: + - patterns: + - pattern: os.system(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + os.system(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + os.system(..., <... $INTERM ...>, ...) + - pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W[...] ...>, ...) + - pattern: os.system(..., <... flask.request.$W(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + os.system(<... $INTERM ...>) + - pattern: os.system(...) +- id: python.flask.security.injection.path-traversal-open.path-traversal-open + languages: + - python + severity: ERROR + message: Found request data in a call to 'open'. Ensure the request data is validated + or sanitized, otherwise it could result in path traversal attacks. + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open + shortlink: https://sg.run/PJRW + semgrep.dev: + rule: + r_id: 9545 + rv_id: 1263430 + rule_id: DbUpOQ + version_id: 9lT4b94 + url: https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open + origin: community + pattern-either: + - patterns: + - pattern: open(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + open(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + with open(..., <... $ROUTEVAR ...>, ...) as $FD: + ... + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + open(..., <... $INTERM ...>, ...) + - pattern: open(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: open(..., <... flask.request.$W[...] ...>, ...) + - pattern: open(..., <... flask.request.$W(...) ...>, ...) + - pattern: open(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + open(<... $INTERM ...>, ...) + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + with open(<... $INTERM ...>, ...) as $F: + ... + - pattern: open(...) +- id: python.flask.security.injection.ssrf-requests.ssrf-requests + languages: + - python + severity: ERROR + message: Data from request object is passed to a new server-side request. This could + lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes + and hosts are validated against an allowlist, do not forward the response to the + user, and ensure proper authentication and transport-layer security in the proxied + request. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests + shortlink: https://sg.run/J9LW + semgrep.dev: + rule: + r_id: 9546 + rv_id: 1263432 + rule_id: WAUoRx + version_id: rxTAKJn + url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests + origin: community + pattern-either: + - patterns: + - pattern: requests.$FUNC(...) + - pattern-either: + - pattern-inside: | + @$APP.$ROUTE_METHOD($ROUTE, ...) + def $ROUTE_FUNC(..., $ROUTEVAR, ...): + ... + requests.$FUNC(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.$ROUTE_METHOD($ROUTE, ...) + def $ROUTE_FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + requests.$FUNC(..., <... $INTERM ...>, ...) + - metavariable-regex: + metavariable: $ROUTE_METHOD + regex: ^(route|get|post|put|delete|patch)$ + - pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + requests.$FUNC(<... $INTERM ...>, ...) + - pattern: requests.$FUNC(...) +- id: python.flask.security.injection.user-eval.eval-injection + languages: + - python + severity: ERROR + message: Detected user data flowing into eval. This is code injection and should + be avoided. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + category: security + technology: + - flask + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection + shortlink: https://sg.run/5QpX + semgrep.dev: + rule: + r_id: 9547 + rv_id: 1263436 + rule_id: 0oU54W + version_id: w8TRoB0 + url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection + origin: community + pattern-either: + - patterns: + - pattern: eval(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + eval(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + eval(..., <... $INTERM ...>, ...) + - pattern: eval(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W[...] ...>, ...) + - pattern: eval(..., <... flask.request.$W(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + eval(..., <... $INTERM ...>, ...) + - pattern: eval(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + eval(..., <... $INTERM ...>, ...) + - pattern: eval(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + eval(..., <... $INTERM ...>, ...) + - pattern: eval(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + eval(..., <... $INTERM ...>, ...) + - pattern: eval(...) +- id: python.flask.security.injection.user-exec.exec-injection + languages: + - python + severity: ERROR + message: Detected user data flowing into exec. This is code injection and should + be avoided. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html + category: security + technology: + - flask + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection + shortlink: https://sg.run/Ge42 + semgrep.dev: + rule: + r_id: 9548 + rv_id: 1263437 + rule_id: KxUbl2 + version_id: xyTjzD9 + url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection + origin: community + pattern-either: + - patterns: + - pattern: exec(...) + - pattern-either: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + exec(..., <... $ROUTEVAR ...>, ...) + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + $INTERM = <... $ROUTEVAR ...> + ... + exec(..., <... $INTERM ...>, ...) + - pattern: exec(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W[...] ...>, ...) + - pattern: exec(..., <... flask.request.$W(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W.get(...) ...> + ... + exec(..., <... $INTERM ...>, ...) + - pattern: exec(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W[...] ...> + ... + exec(..., <... $INTERM ...>, ...) + - pattern: exec(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W(...) ...> + ... + exec(..., <... $INTERM ...>, ...) + - pattern: exec(...) + - patterns: + - pattern-inside: | + $INTERM = <... flask.request.$W ...> + ... + exec(..., <... $INTERM ...>, ...) + - pattern: exec(...) +- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + metadata: + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + shortlink: https://sg.run/l2E9 + semgrep.dev: + rule: + r_id: 9557 + rv_id: 1263452 + rule_id: X5U8P5 + version_id: PkTR3X3 + url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + origin: community + patterns: + - pattern: | + jwt.encode($_, "...", ...) + languages: + - python + severity: ERROR +- id: python.jwt.security.jwt-none-alg.jwt-python-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + category: security + technology: + - jwt + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg + shortlink: https://sg.run/Yvp4 + semgrep.dev: + rule: + r_id: 9558 + rv_id: 1263453 + rule_id: j2UvKw + version_id: JdTzxYj + url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg + origin: community + languages: + - python + severity: ERROR + pattern-either: + - pattern: | + jwt.encode(...,algorithm="none",...) + - pattern: jwt.decode(...,algorithms=[...,"none",...],...) +- id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + patterns: + - pattern-either: + - patterns: + - pattern: | + jwt.decode(..., options={..., "verify_signature": $BOOL, ...}, ...) + - metavariable-pattern: + metavariable: $BOOL + pattern: | + False + - focus-metavariable: $BOOL + - patterns: + - pattern: | + $OPTS = {..., "verify_signature": $BOOL, ...} + ... + jwt.decode(..., options=$OPTS, ...) + - metavariable-pattern: + metavariable: $BOOL + pattern: | + False + - focus-metavariable: $BOOL + message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity + checks for the token which means the token could be tampered with by malicious + actors. Ensure that the JWT token is verified. + metadata: + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + references: + - https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96 + category: security + technology: + - jwt + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + shortlink: https://sg.run/6nyB + semgrep.dev: + rule: + r_id: 9559 + rv_id: 1263454 + rule_id: 10UKjo + version_id: 5PTo12w + url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + origin: community + fix: | + True + severity: ERROR + languages: + - python +- id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + pattern: hashlib.sha1(...) + fix-regex: + regex: sha1 + replacement: sha256 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B303 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + shortlink: https://sg.run/ydYx + semgrep.dev: + rule: + r_id: 9624 + rv_id: 1263537 + rule_id: x8UnBk + version_id: w8TRoE7 + url: https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.insecure-hash-function.insecure-hash-function + message: Detected use of an insecure MD4 or MD5 hash function. These functions have + known vulnerabilities and are considered deprecated. Consider using 'SHA256' or + a similar function instead. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function + shortlink: https://sg.run/rdBn + semgrep.dev: + rule: + r_id: 9625 + rv_id: 1263538 + rule_id: OrU30g + version_id: xyTjzEe + url: https://semgrep.dev/playground/r/xyTjzEe/python.lang.security.insecure-hash-function.insecure-hash-function + origin: community + languages: + - python + severity: WARNING + pattern-either: + - pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...) + - pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...) +- id: python.lang.security.unverified-ssl-context.unverified-ssl-context + patterns: + - pattern-either: + - pattern: ssl._create_unverified_context(...) + - pattern: ssl._create_default_https_context = ssl._create_unverified_context + fix-regex: + regex: _create_unverified_context + replacement: create_default_context + message: Unverified SSL context detected. This will permit insecure connections + without verifying SSL certificates. Use 'ssl.create_default_context' instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-295: Improper Certificate Validation' + references: + - https://docs.python.org/3/library/ssl.html#ssl-security + - https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context + shortlink: https://sg.run/N4lp + semgrep.dev: + rule: + r_id: 9627 + rv_id: 1263540 + rule_id: v8UnkQ + version_id: e1Tyjlj + url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context + origin: community + severity: ERROR + languages: + - python +- id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + pattern: ssl.wrap_socket(...) + message: '''ssl.wrap_socket()'' is deprecated. This function creates an insecure + socket without server name indication or hostname matching. Instead, create an + SSL context using ''ssl.SSLContext()'' and use that to wrap a socket.' + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://docs.python.org/3/library/ssl.html#ssl.wrap_socket + - https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + shortlink: https://sg.run/PJOY + semgrep.dev: + rule: + r_id: 9645 + rv_id: 1263516 + rule_id: BYUN2e + version_id: DkTRbgn + url: https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + origin: community + languages: + - python + severity: WARNING +- id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + patterns: + - pattern: subprocess.$FUNC(..., shell=$TRUE, ...) + - metavariable-pattern: + metavariable: $TRUE + pattern: "True \n" + - pattern-not: subprocess.$FUNC("...", shell=True, ...) + - focus-metavariable: $TRUE + message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous + because this call will spawn the command using a shell process. Doing so propagates + current shell settings and variables, which makes it much easier for a malicious + actor to execute commands. Use 'shell=False' instead. + fix: | + False + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - secure default + likelihood: HIGH + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + shortlink: https://sg.run/J92w + semgrep.dev: + rule: + r_id: 9646 + rv_id: 1263518 + rule_id: DbUpz2 + version_id: 0bTKzDK + url: https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.weak-ssl-version.weak-ssl-version + message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL + versions are considered weak encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2' + or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30 + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.3 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + version: '4' + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + - https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2 + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version + shortlink: https://sg.run/RoZO + semgrep.dev: + rule: + r_id: 9649 + rv_id: 1263520 + rule_id: KxUbNG + version_id: qkTR7Ev + url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version + origin: community + languages: + - python + severity: WARNING + pattern-either: + - pattern: ssl.PROTOCOL_SSLv2 + - pattern: ssl.PROTOCOL_SSLv3 + - pattern: ssl.PROTOCOL_TLSv1 + - pattern: ssl.PROTOCOL_TLSv1_1 + - pattern: pyOpenSSL.SSL.SSLv2_METHOD + - pattern: pyOpenSSL.SSL.SSLv23_METHOD + - pattern: pyOpenSSL.SSL.SSLv3_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_1_METHOD +- id: python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + options: + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern: | + "$URL" + - metavariable-pattern: + metavariable: $URL + language: regex + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + pattern-sinks: + - patterns: + - pattern-inside: | + with requests.Session(...) as $SESSION: + ... + - pattern-either: + - pattern: $SESSION.$W($SINK, ...) + - pattern: $SESSION.request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + fix-regex: + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + count: 1 + message: Detected a request using 'http://'. This request will be unencrypted. Use + 'https://' instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + asvs: + section: V9 Communications Verification Requirements + control_id: 9.2.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + category: security + technology: + - requests + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + shortlink: https://sg.run/Bk5W + semgrep.dev: + rule: + r_id: 9651 + rv_id: 1263484 + rule_id: lBU9BZ + version_id: vdT06wb + url: https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + origin: community + languages: + - python + severity: INFO +- id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + options: + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern: | + "$URL" + - metavariable-pattern: + metavariable: $URL + language: regex + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.Session(...).$W($SINK, ...) + - pattern: requests.Session(...).request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + fix-regex: + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + count: 1 + message: Detected a request using 'http://'. This request will be unencrypted. Use + 'https://' instead. + languages: + - python + severity: INFO + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + category: security + technology: + - requests + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + shortlink: https://sg.run/DoBY + semgrep.dev: + rule: + r_id: 9652 + rv_id: 1263485 + rule_id: YGURXw + version_id: d6Tyx02 + url: https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + origin: community +- id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + fix-regex: + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + count: 1 + message: Detected a request using 'http://'. This request will be unencrypted, and + attackers could listen into traffic on the network and be able to obtain sensitive + information. Use 'https://' instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + category: security + technology: + - requests + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + shortlink: https://sg.run/W8J4 + semgrep.dev: + rule: + r_id: 9653 + rv_id: 1263486 + rule_id: 6JUjpG + version_id: ZRTKA9v + url: https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + origin: community + languages: + - python + severity: INFO + options: + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern: | + "$URL" + - metavariable-pattern: + metavariable: $URL + language: regex + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.$W($SINK, ...) + - pattern: requests.request($METHOD, $SINK, ...) + - pattern: requests.Request($METHOD, $SINK, ...) + - focus-metavariable: $SINK +- id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + patterns: + - pattern: | + $LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...) + - metavariable-regex: + metavariable: $LOGGER_OBJ + regex: (?i)(_logger|logger|self.logger|log) + - metavariable-regex: + metavariable: $LOGGER_CALL + regex: (debug|info|warn|warning|error|exception|critical) + - metavariable-regex: + metavariable: $FORMAT_STRING + regex: (?i).*(api.key|secret|credential|token|password).*\%s.* + message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING + being logged. This may lead to secret credentials being exposed. Make sure that + the logger is not logging sensitive information. + severity: WARNING + languages: + - python + metadata: + cwe: + - 'CWE-532: Insertion of Sensitive Information into Log File' + category: security + technology: + - python + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + shortlink: https://sg.run/ydNx + semgrep.dev: + rule: + r_id: 9668 + rv_id: 1263501 + rule_id: x8UnJk + version_id: A8TgdOR + url: https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + origin: community +- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose + the server publicly as it binds to all available interfaces. Consider instead + getting correct address from an environment variable or configuration file. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - python + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdln + semgrep.dev: + rule: + r_id: 9669 + rv_id: 1263505 + rule_id: OrU3og + version_id: 0bTKzDL + url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + origin: community + languages: + - python + severity: INFO + pattern-either: + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("0.0.0.0", ...)) + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("::", ...)) + - pattern: | + $S = socket.socket(...) + ... + $S.bind(("", ...)) +- id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + patterns: + - pattern-either: + - pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...) + - pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...) + - pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...) + - pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...) + - metavariable-regex: + metavariable: $REQS + regex: (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\") + message: certificate verification explicitly disabled, insecure connections possible + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - python + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + shortlink: https://sg.run/b7yp + semgrep.dev: + rule: + r_id: 9670 + rv_id: 1263506 + rule_id: eqU87k + version_id: K3TKkZn + url: https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is + recommended to use HTTPSConnectionPool instead for to encrypt communications. + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool + category: security + technology: + - python + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + shortlink: https://sg.run/N4Np + semgrep.dev: + rule: + r_id: 9671 + rv_id: 1263507 + rule_id: v8UnWQ + version_id: qkTR7E1 + url: https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + origin: community + languages: + - python + severity: ERROR + pattern-either: + - pattern: urllib3.HTTPConnectionPool(...) + - pattern: urllib3.connectionpool.HTTPConnectionPool(...) +- id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation + - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 + category: security + technology: + - pyyaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + shortlink: https://sg.run/we9Y + semgrep.dev: + rule: + r_id: 9673 + rv_id: 1263530 + rule_id: ZqU5jZ + version_id: 1QTyprw + url: https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + origin: community + languages: + - python + message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, + `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe + methods of deserializing YAML. An attacker with control over the YAML input could + create special YAML input that allows the attacker to run arbitrary Python code. + This would allow the attacker to steal files, download and install malware, or + otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. + fix-regex: + regex: unsafe_load + replacement: safe_load + count: 1 + severity: ERROR + patterns: + - pattern-inside: | + import yaml + ... + - pattern-not-inside: | + $YAML = ruamel.yaml.YAML(...) + ... + - pattern-either: + - pattern: yaml.unsafe_load(...) + - pattern: yaml.load(..., Loader=yaml.Loader, ...) + - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load(..., Loader=yaml.CLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) + - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) +- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ + category: security + technology: + - ruamel.yaml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + shortlink: https://sg.run/x1rz + semgrep.dev: + rule: + r_id: 9674 + rv_id: 1263531 + rule_id: nJUzqK + version_id: 9lT4bvG + url: https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + origin: community + languages: + - python + message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create + arbitrary Python objects. A malicious actor could exploit this to run arbitrary + code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead. + severity: ERROR + pattern-either: + - pattern: ruamel.yaml.YAML(..., typ='unsafe', ...) + - pattern: ruamel.yaml.YAML(..., typ='base', ...) +- id: python.lang.security.deserialization.pickle.avoid-shelve + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve + shortlink: https://sg.run/dKkZ + semgrep.dev: + rule: + r_id: 9678 + rv_id: 1263535 + rule_id: 8GUje2 + version_id: NdTzyb4 + url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve + origin: community + languages: + - python + message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code + execution vulnerabilities. When unpickling, the serialized data could be manipulated + to run arbitrary code. Instead, consider serializing the relevant data as JSON + or a similar text-based serialization format. + severity: WARNING + pattern: shelve.$FUNC(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + message: Detected XOR cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use AES instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + shortlink: https://sg.run/L0yr + semgrep.dev: + rule: + r_id: 9683 + rv_id: 1263549 + rule_id: PeUk5W + version_id: gETB7j3 + url: https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.XOR.new(...) + - pattern: Crypto.Cipher.XOR.new(...) +- id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + shortlink: https://sg.run/3ALr + semgrep.dev: + rule: + r_id: 9687 + rv_id: 1263553 + rule_id: ReUPO3 + version_id: PkTR3vk + url: https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.SHA.new(...) + - pattern: Cryptodome.Hash.SHA.new (...) +- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + message: Detected an insufficient key size for DSA. NIST recommends a key size of + 2048 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://www.pycryptodome.org/src/public_key/dsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + shortlink: https://sg.run/4y8l + semgrep.dev: + rule: + r_id: 9688 + rv_id: 1263554 + rule_id: AbUWje + version_id: JdTzxbQ + url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + origin: community + options: + symbolic_propagation: true + languages: + - python + severity: WARNING + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.DSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 +- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + message: Detected an insufficient key size for RSA. NIST recommends a key size of + 3072 or higher. + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + references: + - https://www.pycryptodome.org/src/public_key/rsa#rsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/PprY + semgrep.dev: + rule: + r_id: 9689 + rv_id: 1263555 + rule_id: BYUBWe + version_id: 5PTo1jL + url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + options: + symbolic_propagation: true + languages: + - python + severity: WARNING + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.RSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 3072 +- id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + patterns: + - pattern-either: + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query.join(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + $SESSION.query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - pattern: | + def $FUNC(...,$VAR,...): + ... + query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause + sql injections if the developer inputs raw SQL into the before-mentioned clauses. + This pattern captures relevant cases in which the developer inputs raw SQL into + the distinct, having, group_by, order_by or filter clauses and injects user-input + into the raw SQL with any function besides "bindparams". Use bindParams to securely + bind user-input to SQL statements. + fix-regex: + regex: format + replacement: bindparams + languages: + - python + severity: WARNING + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - sqlalchemy + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + shortlink: https://sg.run/J3Xo + semgrep.dev: + rule: + r_id: 9702 + rv_id: 1263579 + rule_id: BYUBWo + version_id: NdTzyL4 + url: https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + origin: community +- id: ruby.lang.security.bad-deserialization.bad-deserialization + mode: taint + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + pattern-sinks: + - pattern-either: + - pattern: | + CSV.load(...) + - pattern: | + Marshal.load(...) + - pattern: | + Marshal.restore(...) + - pattern: | + Oj.object_load(...) + - pattern: | + Oj.load($X) + message: Checks for unsafe deserialization. Objects in Ruby can be serialized into + strings, then later loaded from strings. However, uses of load and object_load + can cause remote code execution. Loading user input with MARSHAL or CSV can potentially + be dangerous. Use JSON in a secure fashion instead. + metadata: + references: + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + technology: + - ruby + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization + shortlink: https://sg.run/DJj2 + semgrep.dev: + rule: + r_id: 9708 + rv_id: 1263595 + rule_id: lBUdQg + version_id: 3ZT4Xqp + url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization + origin: community + languages: + - ruby + severity: ERROR +- id: ruby.lang.security.force-ssl-false.force-ssl-false + message: Checks for configuration setting of force_ssl to false. Force_ssl forces + usage of HTTPS, which could lead to network interception of unencrypted application + traffic. To fix, set config.force_ssl = true. + metadata: + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false + shortlink: https://sg.run/YgkW + semgrep.dev: + rule: + r_id: 9714 + rv_id: 1263605 + rule_id: 2ZU4lx + version_id: WrTqKB3 + url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false + origin: community + languages: + - ruby + severity: WARNING + pattern: config.force_ssl = false + fix-regex: + regex: =\s*false + replacement: = true +- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + patterns: + - pattern-inside: | + class $CONTROLLER < ApplicationController + ... + http_basic_authenticate_with ..., :password => "$SECRET", ... + end + - focus-metavariable: $SECRET + message: Detected hardcoded password used in basic authentication in a controller + class. Including this password in version control could expose this credential. + Consider refactoring to use environment variables or configuration files. + severity: WARNING + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown + category: security + technology: + - ruby + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + shortlink: https://sg.run/6r0w + semgrep.dev: + rule: + r_id: 9715 + rv_id: 1263606 + rule_id: X5UZWK + version_id: 0bTKzNK + url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + origin: community + languages: + - ruby +- id: ruby.lang.security.no-eval.ruby-eval + message: Use of eval with user-controllable input detected. This can lead to attackers + running arbitrary code. Ensure external data does not reach here, otherwise this + is a security vulnerability. Consider other ways to do this without eval. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe2022-top25: true + cwe2021-top25: true + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb + subcategory: + - vuln + technology: + - ruby + - rails + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval + shortlink: https://sg.run/bDwZ + semgrep.dev: + rule: + r_id: 9726 + rv_id: 1263615 + rule_id: OrUGNk + version_id: A8TgdDv + url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval + origin: community + languages: + - ruby + mode: taint + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + - patterns: + - pattern: | + RubyVM::InstructionSequence.compile(...) + - pattern-not: | + RubyVM::InstructionSequence.compile("...") + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.eval + - pattern: $X.class_eval + - pattern: $X.instance_eval + - pattern: $X.module_eval + - pattern: $X.eval(...) + - pattern: $X.class_eval(...) + - pattern: $X.instance_eval(...) + - pattern: $X.module_eval(...) + - pattern: eval(...) + - pattern: class_eval(...) + - pattern: module_eval(...) + - pattern: instance_eval(...) + - pattern-not: $M("...",...) +- id: ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + pattern: OpenSSL::SSL::VERIFY_NONE + message: Detected SSL that will accept an unverified connection. This makes the + connections susceptible to man-in-the-middle attacks. Use 'OpenSSL::SSL::VERIFY_PEER' + instead. + fix-regex: + regex: VERIFY_NONE + replacement: VERIFY_PEER + severity: WARNING + languages: + - ruby + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + shortlink: https://sg.run/kLxX + semgrep.dev: + rule: + r_id: 9728 + rv_id: 1263617 + rule_id: v8U5Yn + version_id: DkTRbl4 + url: https://semgrep.dev/playground/r/DkTRbl4/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + origin: community +- id: ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + message: Should not use md5 to generate hashes. md5 is proven to be vulnerable through + the use of brute-force attacks. Could also result in collisions, leading to potential + collision attacks. Use SHA256 or other hashing functions instead. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://www.ibm.com/support/pages/security-bulletin-vulnerability-md5-signature-and-hash-algorithm-affects-sterling-integrator-and-sterling-file-gateway-cve-2015-7575 + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + shortlink: https://sg.run/O1re + semgrep.dev: + rule: + r_id: 9731 + rv_id: 1263619 + rule_id: nJUYxZ + version_id: 0bTKzN8 + url: https://semgrep.dev/playground/r/0bTKzN8/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + origin: community + languages: + - ruby + severity: WARNING + pattern-either: + - pattern: Digest::MD5.base64digest $X + - pattern: Digest::MD5.hexdigest $X + - pattern: Digest::MD5.digest $X + - pattern: Digest::MD5.new + - pattern: OpenSSL::Digest::MD5.base64digest $X + - pattern: OpenSSL::Digest::MD5.hexdigest $X + - pattern: OpenSSL::Digest::MD5.digest $X + - pattern: OpenSSL::Digest::MD5.new +- id: ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + message: Should not use SHA1 to generate hashes. There is a proven SHA1 hash collision + by Google, which could lead to vulnerabilities. Use SHA256, SHA3 or other hashing + functions instead. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html + - https://shattered.io/ + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + shortlink: https://sg.run/e4qX + semgrep.dev: + rule: + r_id: 9732 + rv_id: 1263620 + rule_id: EwU4jq + version_id: K3TKkEZ + url: https://semgrep.dev/playground/r/K3TKkEZ/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + origin: community + languages: + - ruby + severity: WARNING + pattern-either: + - pattern: Digest::SHA1.$FUNC + - pattern: OpenSSL::Digest::SHA1.$FUNC + - pattern: OpenSSL::HMAC.$FUNC("sha1",...) +- id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + pattern: acl = "public-read-write" + languages: + - hcl + severity: ERROR + message: S3 bucket with public read-write access detected. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl + - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + shortlink: https://sg.run/0nok + semgrep.dev: + rule: + r_id: 9754 + rv_id: 1263900 + rule_id: 6JUqvn + version_id: PkTR3y5 + url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + origin: community +- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting + (XSS) vulnerability if this comes from user-provided input. If you have to use + `$TRUST`, ensure it does not come from user-input or use the appropriate prevention + mechanism e.g. input validation or sanitization depending on the context. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://angular.io/api/platform-browser/DomSanitizer + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + confidence: MEDIUM + category: security + technology: + - angular + - browser + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + shortlink: https://sg.run/KWxP + semgrep.dev: + rule: + r_id: 9755 + rv_id: 1263902 + rule_id: oqUzgA + version_id: 5PTo1zk + url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + origin: community + languages: + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X: string, ...}) { ... } + - pattern-inside: | + function ...(..., $X: string, ...) { ... } + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.$TRUST($Y) + - focus-metavariable: $Y + - pattern-not: | + $X.$TRUST(`...`) + - pattern-not: | + $X.$TRUST("...") + - metavariable-regex: + metavariable: $TRUST + regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern: sanitizer.sanitize(...) + - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); +- id: typescript.react.security.react-insecure-request.react-insecure-request + message: Unencrypted request over HTTP detected. + metadata: + vulnerability: Insecure Transport + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://www.npmjs.com/package/axios + category: security + technology: + - react + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request + shortlink: https://sg.run/1n0b + semgrep.dev: + rule: + r_id: 9766 + rv_id: 1263918 + rule_id: NbUA3O + version_id: A8Tgd2p + url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request + origin: community + languages: + - typescript + - javascript + severity: ERROR + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + import $AXIOS from 'axios'; + ... + $AXIOS.$METHOD(...) + - pattern-inside: | + $AXIOS = require('axios'); + ... + $AXIOS.$METHOD(...) + - pattern: $AXIOS.$VERB("$URL",...) + - metavariable-regex: + metavariable: $VERB + regex: ^(get|post|delete|head|patch|put|options) + - patterns: + - pattern-either: + - pattern-inside: | + import $AXIOS from 'axios'; + ... + $AXIOS(...) + - pattern-inside: | + $AXIOS = require('axios'); + ... + $AXIOS(...) + - pattern-either: + - pattern: '$AXIOS({url: "$URL"}, ...)' + - pattern: | + $OPTS = {url: "$URL"} + ... + $AXIOS($OPTS, ...) + - pattern: fetch("$URL", ...) + - metavariable-regex: + metavariable: $URL + regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) +- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + message: Detection of dangerouslySetInnerHTML from non-constant definition. This + can inadvertently expose users to cross-site scripting (XSS) attacks if this comes + from user-provided input. If you have to use dangerouslySetInnerHTML, consider + using a sanitization library such as DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + shortlink: https://sg.run/rAx6 + semgrep.dev: + rule: + r_id: 9769 + rv_id: 1263912 + rule_id: x8UWvK + version_id: l4TJR0v + url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-not-inside: | + $F. ... .$SANITIZEUNC(...) + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern-either: + - pattern: | + {...,dangerouslySetInnerHTML: {__html: $X},...} + - pattern: | + <$Y ... dangerouslySetInnerHTML={{__html: $X}} /> + - pattern-not: | + <$Y ... dangerouslySetInnerHTML={{__html: "..."}} /> + - pattern-not: | + {...,dangerouslySetInnerHTML:{__html: "..."},...} + - metavariable-pattern: + patterns: + - pattern-not: | + {...} + metavariable: $X + - pattern-not: | + <... {__html: "..."} ...> + - pattern-not: | + <... {__html: `...`} ...> + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + message: Detection of $HTML from non-constant definition. This can inadvertently + expose users to cross-site scripting (XSS) attacks if this comes from user-provided + input. If you have to use $HTML, consider using a sanitization library such as + DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln + - https://developer.mozilla.org/en-US/docs/Web/API/Document/write + - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + shortlink: https://sg.run/E5x8 + semgrep.dev: + rule: + r_id: 9781 + rv_id: 1263916 + rule_id: QrU68w + version_id: GxTkeRl + url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" + - pattern: "window.document. ... .$HTML('...',$SINK) \n" + - pattern: "document.$HTML($SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (writeln|write) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: "$PROP. ... .$HTML('...',$SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (insertAdjacentHTML) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + message: Detection of $HTML from non-constant definition. This can inadvertently + expose users to cross-site scripting (XSS) attacks if this comes from user-provided + input. If you have to use $HTML, consider using a sanitization library such as + DOMPurify to sanitize your HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + category: security + confidence: MEDIUM + technology: + - react + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + shortlink: https://sg.run/70Zv + semgrep.dev: + rule: + r_id: 9782 + rv_id: 1263917 + rule_id: 3qUBl4 + version_id: RGT0Lln + url: https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + origin: community + languages: + - typescript + - javascript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + function ...({..., $X, ...}) { ... } + - pattern-inside: | + function ...(..., $X, ...) { ... } + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $BODY = $REACT.useRef(...) + ... + - pattern-inside: | + $BODY = useRef(...) + ... + - pattern-inside: | + $BODY = findDOMNode(...) + ... + - pattern-inside: | + $BODY = createRef(...) + ... + - pattern-inside: | + $BODY = $REACT.findDOMNode(...) + ... + - pattern-inside: | + $BODY = $REACT.createRef(...) + ... + - pattern-either: + - pattern: "$BODY. ... .$HTML = $SINK \n" + - pattern: "$BODY.$HTML = $SINK \n" + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: ReactDOM.findDOMNode(...).$HTML = $SINK + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + import * as $S from "underscore.string" + ... + - pattern-inside: | + import $S from "underscore.string" + ... + - pattern-inside: | + $S = require("underscore.string") + ... + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from "dompurify" + ... + - pattern-inside: | + import { ..., $S,... } from "dompurify" + ... + - pattern-inside: | + import * as $S from "dompurify" + ... + - pattern-inside: | + $S = require("dompurify") + ... + - pattern-inside: | + import $S from "isomorphic-dompurify" + ... + - pattern-inside: | + import * as $S from "isomorphic-dompurify" + ... + - pattern-inside: | + $S = require("isomorphic-dompurify") + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $S(...) + ... + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: | + $VALUE = $S.sanitize + ... + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'xss'; + ... + - pattern-inside: | + import * as $S from 'xss'; + ... + - pattern-inside: | + $S = require("xss") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + import $S from 'sanitize-html'; + ... + - pattern-inside: | + import * as $S from "sanitize-html"; + ... + - pattern-inside: | + $S = require("sanitize-html") + ... + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: | + $S = new Remarkable() + ... + - pattern: $S.render(...) +- id: ruby.lang.security.dangerous-exec.dangerous-exec + mode: taint + pattern-sources: + - patterns: + - pattern: | + def $F(...,$ARG,...) + ... + end + - focus-metavariable: $ARG + - pattern: params + - pattern: cookies + pattern-sinks: + - patterns: + - pattern: | + $EXEC(...) + - pattern-not: | + $EXEC("...","...","...",...) + - pattern-not: | + $EXEC(["...","...","...",...],...) + - pattern-not: | + $EXEC({...},"...","...","...",...) + - pattern-not: | + $EXEC({...},["...","...","...",...],...) + - metavariable-regex: + metavariable: $EXEC + regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ + message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If + unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - ruby + - rails + references: + - https://guides.rubyonrails.org/security.html#command-line-injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec + shortlink: https://sg.run/R8GY + semgrep.dev: + rule: + r_id: 9805 + rv_id: 1409405 + rule_id: WAUZOw + version_id: WrT7erb + url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec + origin: community + severity: WARNING + languages: + - ruby +- id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + message: Detected non-literal calls to Deno.run(). This could lead to a command + injection vulnerability. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - deno + references: + - https://deno.land/manual/examples/subprocess#simple-example + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + shortlink: https://sg.run/Nrrn + semgrep.dev: + rule: + r_id: 9927 + rv_id: 1409397 + rule_id: x8UWWg + version_id: PkTe7AP + url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: function ... (..., $ARG,...) {...} + - focus-metavariable: $ARG + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + Deno.run({cmd: [$INPUT,...]},...) + - pattern: | + Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...) + - patterns: + - pattern: | + Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" + ... + - focus-metavariable: $INPUT +- id: yaml.docker-compose.security.privileged-service.privileged-service + patterns: + - pattern-inside: | + version: ... + ... + services: + ... + $SERVICE: + ... + privileged: $TRUE + - focus-metavariable: $TRUE + - metavariable-regex: + metavariable: $TRUE + regex: (true) + fix: | + false + message: Service '$SERVICE' is running in privileged mode. This grants the container + the equivalent of root capabilities on the host machine. This can lead to container + escapes, privilege escalation, and other security concerns. Remove the 'privileged' + key to disable this capability. + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html + - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ + category: security + technology: + - docker-compose + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service + shortlink: https://sg.run/AlX0 + semgrep.dev: + rule: + r_id: 10006 + rv_id: 1263922 + rule_id: DbUW17 + version_id: 0bTKzXZ + url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - name: $CONTAINER + ... + - pattern: | + image: ... + ... + - pattern-inside: | + image: ... + ... + $SC: + ... + - metavariable-regex: + metavariable: $SC + regex: ^(securityContext)$ + - pattern-not-inside: | + image: ... + ... + securityContext: + ... + allowPrivilegeEscalation: $VAL + - focus-metavariable: $SC + fix: | + securityContext: + allowPrivilegeEscalation: false # + message: In Kubernetes, each pod runs in its own isolated environment with its own + set of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation` + parameter to your the `securityContext`, you can help to ensure that your containerized + applications are more secure and less vulnerable to privilege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + shortlink: https://sg.run/ljp6 + semgrep.dev: + rule: + r_id: 10057 + rv_id: 1263933 + rule_id: 6JUqEO + version_id: jQTn527 + url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + patterns: + - pattern-inside: | + containers: + ... + - pattern: | + image: ... + ... + securityContext: + ... + seccompProfile: unconfined + message: 'Container is explicitly disabling seccomp confinement. This runs the service + in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.' + metadata: + cwe: + - 'CWE-284: Improper Access Control' + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + category: security + technology: + - kubernetes + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + shortlink: https://sg.run/6rgY + semgrep.dev: + rule: + r_id: 10059 + rv_id: 1263941 + rule_id: zdUynw + version_id: w8TRoL3 + url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + pattern: | + cluster: + ... + insecure-skip-tls-verify: true + message: 'Cluster is disabling TLS certificate verification when communicating with + the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify: + true'' key to secure communication.' + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster + category: security + technology: + - kubernetes + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + shortlink: https://sg.run/okyn + semgrep.dev: + rule: + r_id: 10116 + rv_id: 1263943 + rule_id: zdUyWx + version_id: O9Tpxbo + url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + pattern: | + spec: + ... + insecureSkipTLSVerify: true + message: 'Service is disabling TLS certificate verification when communicating with + the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify: + true'' key to secure communication.' + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + references: + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io + category: security + technology: + - kubernetes + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + shortlink: https://sg.run/zk10 + semgrep.dev: + rule: + r_id: 10117 + rv_id: 1263944 + rule_id: pKUGXr + version_id: e1TyjnR + url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + origin: community + languages: + - yaml + severity: WARNING +- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + mode: taint + pattern-propagators: + - pattern: $X << $Y + from: $Y + to: $X + pattern-sources: + - pattern-either: + - pattern: | + params + - pattern: | + cookies + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $CON = PG.connect(...) + ... + - pattern-inside: | + $CON = PG::Connection.open(...) + ... + - pattern-inside: | + $CON = PG::Connection.new(...) + ... + - pattern-either: + - pattern: | + $CON.$METHOD($X,...) + - pattern: | + $CON.$METHOD $X, ... + - focus-metavariable: $X + - metavariable-regex: + metavariable: $METHOD + regex: ^(exec|exec_params)$ + languages: + - ruby + message: 'Detected string concatenation with a non-literal variable in a pg Ruby + SQL statement. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, use parameterized + queries or prepared statements instead. You can use parameterized queries like + so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And + you can use prepared statements with `exec_prepared`.' + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + shortlink: https://sg.run/kL0o + semgrep.dev: + rule: + r_id: 10328 + rv_id: 1263628 + rule_id: NbUAz7 + version_id: 2KTv2y2 + url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + origin: community + severity: WARNING +- id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + pattern: management.endpoints.web.exposure.include=* + message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints + such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless + you have Spring Security enabled or another means to protect these endpoints, + this functionality is available without authentication, causing a significant + security risk. + severity: ERROR + languages: + - generic + paths: + include: + - '*properties' + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + category: security + technology: + - spring + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + shortlink: https://sg.run/L0vY + semgrep.dev: + rule: + r_id: 10439 + rv_id: 1263077 + rule_id: EwU4vg + version_id: xyTjzwp + url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + origin: community +- id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + patterns: + - pattern-either: + - pattern: | + proxy_http_version 1.1 ...; + ... + proxy_set_header Upgrade ...; + ... + proxy_set_header Connection ...; + - pattern: | + proxy_set_header Upgrade ...; + ... + proxy_set_header Connection ...; + ... + proxy_http_version 1.1 ...; + - pattern: | + proxy_set_header Upgrade ...; + ... + proxy_http_version 1.1 ...; + ... + proxy_set_header Connection ...; + - pattern-inside: | + location ... { + ... + } + languages: + - generic + severity: WARNING + message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading + HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which + can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted + HTTP traffic directly to back-end servers. To mitigate: WebSocket support required: + Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket). + WebSocket support not required: Do not forward Upgrade headers.' + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + metadata: + cwe: + - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response + Smuggling'')' + references: + - https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c + category: security + technology: + - nginx + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + shortlink: https://sg.run/ploZ + semgrep.dev: + rule: + r_id: 10562 + rv_id: 1262679 + rule_id: 6JUq0Z + version_id: nWT2Lyp + url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + origin: community +- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + category: security + technology: + - .net + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + shortlink: https://sg.run/ZeXW + semgrep.dev: + rule: + r_id: 11135 + rv_id: 1262635 + rule_id: bwUOjK + version_id: nWT2LGp + url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + origin: community + message: The BinaryFormatter type is dangerous and is not recommended for data processing. + Applications should stop using BinaryFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. BinaryFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Binary; + ... + - pattern: | + new BinaryFormatter(); +- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + shortlink: https://sg.run/E5e5 + semgrep.dev: + rule: + r_id: 11137 + rv_id: 1262638 + rule_id: kxURnR + version_id: LjTkgPk + url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + origin: community + message: The FsPickler is dangerous and is not recommended for data processing. + Default configuration tend to insecure deserialization vulnerability. + patterns: + - pattern-inside: | + using MBrace.FsPickler.Json; + ... + - pattern: | + FsPickler.CreateJsonSerializer(); +- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + shortlink: https://sg.run/70pG + semgrep.dev: + rule: + r_id: 11138 + rv_id: 1262641 + rule_id: wdU87G + version_id: QkTGqnA + url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + origin: community + message: The LosFormatter type is dangerous and is not recommended for data processing. + Applications should stop using LosFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. LosFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Web.UI; + ... + - pattern: | + new LosFormatter(); +- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + shortlink: https://sg.run/L0AX + semgrep.dev: + rule: + r_id: 11139 + rv_id: 1262642 + rule_id: x8UW7x + version_id: 3ZT4X6b + url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + origin: community + message: The NetDataContractSerializer type is dangerous and is not recommended + for data processing. Applications should stop using NetDataContractSerializer + as soon as possible, even if they believe the data they're processing to be trustworthy. + NetDataContractSerializer is insecure and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization; + ... + - pattern: | + new NetDataContractSerializer(); +- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks + category: security + technology: + - .net + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + shortlink: https://sg.run/gJnR + semgrep.dev: + rule: + r_id: 11141 + rv_id: 1262644 + rule_id: eqUvND + version_id: PkTR30n + url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + origin: community + message: The SoapFormatter type is dangerous and is not recommended for data processing. + Applications should stop using SoapFormatter as soon as possible, even if they + believe the data they're processing to be trustworthy. SoapFormatter is insecure + and can't be made secure + patterns: + - pattern-inside: | + using System.Runtime.Serialization.Formatters.Soap; + ... + - pattern: | + new SoapFormatter(); +- id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + languages: + - hcl + message: AWS EC2 Instance allowing use of the IMDSv1 + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + references: + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options + category: security + technology: + - terraform + - aws + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + shortlink: https://sg.run/J3BQ + semgrep.dev: + rule: + r_id: 11302 + rv_id: 1263884 + rule_id: GdU0eA + version_id: w8TRooE + url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + origin: community + pattern-either: + - patterns: + - pattern: http_tokens = "optional" + - pattern-inside: | + metadata_options { ... } + - patterns: + - pattern: | + resource "aws_instance" "$NAME" { + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_tokens = "required" + ... + } + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_tokens = "optional" + ... + } + ... + } + - pattern-not: | + resource "aws_instance" "$NAME" { + ... + metadata_options { + ... + http_endpoint = "disabled" + ... + } + ... + } + severity: ERROR +- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + metadata: + functional-categories: + - crypto::search::randomness::javax.crypto + cwe: + - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' + category: security + source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM + technology: + - java + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + shortlink: https://sg.run/Dww2 + semgrep.dev: + rule: + r_id: 11908 + rv_id: 1263000 + rule_id: GdUZZ3 + version_id: 0bTKzGk + url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + origin: community + languages: + - java + message: 'GCM IV/nonce is reused: encryption can be totally useless' + patterns: + - pattern-either: + - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); + - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., + $NONCE, ...); + severity: ERROR +- id: csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + owasp: A01:2017 - Injection + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + - https://docs.microsoft.com/en-us/dotnet/standard/base-types/regular-expressions#regular-expression-examples + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + shortlink: https://sg.run/RPyY + semgrep.dev: + rule: + r_id: 12005 + rv_id: 945225 + rule_id: 4bU2gd + version_id: rxT6rjl + url: https://semgrep.dev/playground/r/rxT6rjl/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + origin: community + message: When using `System.Text.RegularExpressions` to process untrusted input, + pass a timeout. A malicious user can provide input to `RegularExpressions` that + abuses the backtracking behaviour of this regular expression engine. This will + lead to excessive CPU usage, causing a Denial-of-Service attack + patterns: + - pattern-inside: | + using System.Text.RegularExpressions; + ... + - pattern-either: + - pattern: | + public $T $F($X) + { + Regex $Y = new Regex($P); + ... + $Y.Match($X); + } + - pattern: | + public $T $F($X) + { + Regex $Y = new Regex($P, $O); + ... + $Y.Match($X); + } + - pattern: | + public $T $F($X) + { + ... Regex.Match($X, $P); + } + - pattern: | + public $T $F($X) + { + ... Regex.Match($X, $P, $O); + } +- id: javascript.express.security.express-vm-injection.express-vm-injection + message: Make sure that unverified user data can not reach `$VM`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection + shortlink: https://sg.run/jkqJ + semgrep.dev: + rule: + r_id: 12821 + rv_id: 1263170 + rule_id: DbUKPX + version_id: 1QTypXQ + url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + $VM = require('vm'); + ... + - pattern-either: + - pattern: | + $VM.runInContext(...) + - pattern: | + $VM.runInNewContext(...) + - pattern: | + $VM.compileFunction(...) + - pattern: | + $VM.runInThisContext(...) + - pattern: new $VM.Script(...) +- id: javascript.express.security.express-vm2-injection.express-vm2-injection + message: Make sure that unverified user data can not reach `vm2`. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - express + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection + shortlink: https://sg.run/1GWv + semgrep.dev: + rule: + r_id: 12822 + rv_id: 1263171 + rule_id: WAUPXJ + version_id: 9lT4bnX + url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-inside: | + require('vm2') + ... + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $VM = new VM(...) + ... + - pattern-inside: | + $VM = new NodeVM(...) + ... + - pattern: | + $VM.run(...) + - pattern: | + new VM(...).run(...) + - pattern: | + new NodeVM(...).run(...) + - pattern: | + new VMScript(...) + - pattern: | + new VM(...) + - pattern: new NodeVM(...) +- id: javascript.lang.security.audit.code-string-concat.code-string-concat + message: Found data from an Express or Next web request flowing to `eval`. If this + data is user-controllable this can lead to execution of arbitrary system commands + in the context of your application process. Avoid `eval` whenever possible. + options: + interfile: true + metadata: + interfile: true + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval + - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback + - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ + - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html + category: security + technology: + - node.js + - Express + - Next.js + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat + shortlink: https://sg.run/96Yk + semgrep.dev: + rule: + r_id: 13023 + rv_id: 1263192 + rule_id: DbUKEz + version_id: 44TEjYX + url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) + {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + import { ...,$IMPORT,... } from 'next/router' + ... + - pattern-inside: | + import $IMPORT from 'next/router'; + ... + - pattern-either: + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern-either: + - pattern-inside: | + const { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + var { ...,$PROPS,... } = $ROUTER.query + ... + - pattern-inside: | + let { ...,$PROPS,... } = $ROUTER.query + ... + - focus-metavariable: $PROPS + - patterns: + - pattern-inside: | + $ROUTER = $IMPORT() + ... + - pattern: "$ROUTER.query.$VALUE \n" + - patterns: + - pattern: $IMPORT().query.$VALUE + pattern-sinks: + - patterns: + - pattern: | + eval(...) +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `run:` step could allow an attacker to inject their own code into the runner. + This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate + environment variable with `env:` to store the data and use the environment variable + in the `run:` script. Be sure to use double-quotes the environment variable, like + this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + shortlink: https://sg.run/pkzk + semgrep.dev: + rule: + r_id: 13162 + rv_id: 1423395 + rule_id: v8UjQj + version_id: GxTl1DQ + url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `pull_request_target` and checks + out code from the incoming pull request. When using `pull_request_target`, the + Action runs in the context of the target repository, which includes access to + all repository secrets. Normally, this is safe because the Action only runs code + from the target repository, not the incoming PR. However, by checking out the + incoming PR code, you're now using the incoming code for the rest of the action. + You may be inadvertently executing arbitrary code from the incoming PR with access + to repository secrets, which would let an attacker steal repository secrets. This + normally happens by running build scripts (e.g., `npm build` and `make`) or dependency + installation scripts (e.g., `python setup.py install`). Audit your workflow file + to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + for additional mitigations. + metadata: + category: security + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + shortlink: https://sg.run/jkdn + semgrep.dev: + rule: + r_id: 13365 + rv_id: 1413423 + rule_id: d8Ulkd + version_id: O9TQ2nX + url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + origin: community + patterns: + - pattern-either: + - pattern-inside: | + on: + ... + pull_request_target: ... + ... + ... + - pattern-inside: | + on: [..., pull_request_target, ...] + ... + - pattern-inside: | + on: pull_request_target + ... + - pattern-inside: | + jobs: + ... + $JOBNAME: + ... + steps: + ... + - pattern: | + ... + uses: "$ACTION" + with: + ... + ref: $EXPR + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern-inside: ${{ ... }} + - pattern-either: + - pattern: github.event.pull_request ... + - pattern: github.head_ref ... + severity: ERROR +- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + languages: + - yaml + severity: WARNING + message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this + workflow permissions to use the `set-env` and `add-path` commands. There is a + vulnerability in these commands that could result in environment variables being + modified by an attacker. Depending on the use of the environment variable, this + could enable an attacker to, at worst, modify the system path to run a different + command than intended, resulting in arbitrary code execution. This could result + in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, + use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + for more information. + metadata: + cwe: + - 'CWE-749: Exposed Dangerous Method or Function' + owasp: A06:2017 - Security Misconfiguration + references: + - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ + - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w + - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + category: security + technology: + - github-actions + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + shortlink: https://sg.run/qq78 + semgrep.dev: + rule: + r_id: 13412 + rv_id: 947039 + rule_id: EwUQ9x + version_id: jQTzq34 + url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + origin: community + patterns: + - pattern-either: + - patterns: + - pattern-inside: '{env: ...}' + - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' +- id: json.aws.security.public-s3-bucket.public-s3-bucket + languages: + - json + message: Detected public S3 bucket. This policy allows anyone to have some kind + of access to the bucket. The exact level of access and types of actions allowed + will depend on the configuration of bucket policy and ACLs. Please review the + bucket configuration to make sure they are set with intended values. + metadata: + category: security + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html + technology: + - aws + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket + shortlink: https://sg.run/lxv5 + semgrep.dev: + rule: + r_id: 13413 + rv_id: 1263254 + rule_id: 7KUpLy + version_id: RGT0Ld0 + url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket + origin: community + patterns: + - pattern-inside: | + $BUCKETNAME: { + "Type": "AWS::S3::Bucket", + "Properties": { + ..., + }, + ..., + } + - pattern-either: + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "RestrictPublicBuckets": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "IgnorePublicAcls": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "BlockPublicAcls": false, + ..., + }, + - pattern: | + "PublicAccessBlockConfiguration": { + ..., + "BlockPublicPolicy": false, + ..., + }, + severity: WARNING +- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration + message: By letting user input control CORS parameters, there is a risk that software + does not properly verify that the source of data or communication is valid. Use + literal values for CORS settings. + metadata: + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-346: Origin Validation Error' + category: security + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS + technology: + - express + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration + shortlink: https://sg.run/nKXO + semgrep.dev: + rule: + r_id: 13580 + rv_id: 1263162 + rule_id: 5rULJQ + version_id: YDTZe8Y + url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, $X) + - pattern: $RES.header($HEADER, $X) + - pattern: $RES.setHeader($HEADER, $X) + - pattern: | + $RES.set({$HEADER: $X}, ...) + - pattern: | + $RES.writeHead($STATUS, {$HEADER: $X}, ...) + - focus-metavariable: $X + - metavariable-regex: + metavariable: $HEADER + regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* +- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + message: By letting user input control `X-Frame-Options` header, there is a risk + that software does not properly verify whether or not a browser should be allowed + to render a page in an `iframe`. + metadata: + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' + category: security + technology: + - express + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + shortlink: https://sg.run/EvjA + semgrep.dev: + rule: + r_id: 13581 + rv_id: 1263178 + rule_id: GdUrLy + version_id: xyTjz3D + url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, ...) + - pattern: $RES.header($HEADER, ...) + - pattern: $RES.setHeader($HEADER, ...) + - pattern: | + $RES.set({$HEADER: ...}, ...) + - pattern: | + $RES.writeHead($STATUS, {$HEADER: ...}, ...) + - metavariable-regex: + metavariable: $HEADER + regex: .*(X-Frame-Options|x-frame-options).* +- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + metadata: + shortDescription: Allowing an attacker to manipulate the session may lead to unintended + behavior. + tags: + - security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + references: + - https://brakemanscanner.org/docs/warning_types/session_manipulation/ + category: security + technology: + - rails + help: | + ## Remediation + Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior. + + ## References + [Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/) + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + shortlink: https://sg.run/86q7 + semgrep.dev: + rule: + r_id: 13584 + rv_id: 1263621 + rule_id: BYUdW6 + version_id: qkTR76G + url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + origin: community + message: This gets data from session using user inputs. A malicious user may be + able to retrieve information from your session that you didn't intend them to. + Do not use user input as a session key. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern: session[...] +- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + shortlink: https://sg.run/gYln + semgrep.dev: + rule: + r_id: 13585 + rv_id: 1263622 + rule_id: DbU1dr + version_id: l4TJRkk + url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - pattern: Dir.$X(...) + - pattern: File.$X(...) + - pattern: IO.$X(...) + - pattern: Kernel.$X(...) + - pattern: PStore.$X(...) + - pattern: Pathname.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + shortlink: https://sg.run/Q9gP + semgrep.dev: + rule: + r_id: 13586 + rv_id: 1263623 + rule_id: WAUyzp + version_id: YDTZeWL + url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - pattern: Net::FTP.$X(...) + - patterns: + - pattern-inside: | + $FTP = Net::FTP.$OPEN(...) + ... + $FTP.$METHOD(...) + - pattern: $FTP.$METHOD(...) +- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + metadata: + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + shortlink: https://sg.run/3rLb + semgrep.dev: + rule: + r_id: 13587 + rv_id: 1263624 + rule_id: 0oU2x3 + version_id: 6xT29nN + url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - pattern-either: + - patterns: + - pattern: Net::HTTP::$METHOD.new(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: Copy + - pattern: Delete + - pattern: Get + - pattern: Head + - pattern: Lock + - pattern: Mkcol + - pattern: Move + - pattern: Options + - pattern: Patch + - pattern: Post + - pattern: Propfind + - pattern: Proppatch + - pattern: Put + - pattern: Trace + - pattern: Unlock + - patterns: + - pattern: Net::HTTP.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: get + - pattern: get2 + - pattern: head + - pattern: head2 + - pattern: options + - pattern: patch + - pattern: post + - pattern: post2 + - pattern: post_form + - pattern: put + - pattern: request + - pattern: request_get + - pattern: request_head + - pattern: request_post + - pattern: send_request + - pattern: trace + - pattern: get_print + - pattern: get_response + - pattern: start +- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + shortlink: https://sg.run/4e8E + semgrep.dev: + rule: + r_id: 13588 + rv_id: 1263625 + rule_id: KxU72k + version_id: o5TbDq8 + url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + origin: community + message: Using user input when accessing files is potentially dangerous. A malicious + actor could use this to modify or access files they have no right to. + languages: + - ruby + severity: ERROR + mode: taint + pattern-sources: + - pattern-either: + - pattern: params[...] + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: Kernel.$X(...) + - patterns: + - pattern-either: + - pattern: Shell.$X(...) + - patterns: + - pattern-inside: | + $SHELL = Shell.$ANY(...) + ... + $SHELL.$X(...) + - pattern: $SHELL.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: cat + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: exec + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: system + - pattern: truncate + - pattern: unlink +- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://brakemanscanner.org/docs/warning_types/link_to/ + - https://brakemanscanner.org/docs/warning_types/link_to_href/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + shortlink: https://sg.run/JxXQ + semgrep.dev: + rule: + r_id: 13590 + rv_id: 1263632 + rule_id: lBU8Qj + version_id: 9lT4brj + url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + origin: community + message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` + is not escaped. This means that user input which reaches the body will be executed + when the HTML is rendered. Even in other versions, values starting with `javascript:` + or `data:` are not escaped. It is better to create and use a safer function which + checks the body argument. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern-either: + - pattern: $MODEL.url(...) + - pattern: $MODEL.uri(...) + - pattern: $MODEL.link(...) + - pattern: $MODEL.page(...) + - pattern: $MODEL.site(...) + pattern-sinks: + - pattern: link_to(...) + pattern-sanitizers: + - patterns: + - pattern: | + "...#{...}..." + - pattern-not: | + "#{...}..." +- id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + references: + - https://brakemanscanner.org/docs/warning_types/redirect/ + category: security + technology: + - rails + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + shortlink: https://sg.run/5DY3 + semgrep.dev: + rule: + r_id: 13591 + rv_id: 1263634 + rule_id: YGUDqJ + version_id: rxTAKdY + url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + origin: community + message: When a redirect uses user input, a malicious user can spoof a website under + a trusted URL or access restricted parts of a site. When using user-supplied values, + sanitize the value before using it for the redirect. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - patterns: + - pattern: $MODEL.$X(...) + - pattern-not: $MODEL.$X("...") + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: all + - pattern: create + - pattern: create! + - pattern: find + - pattern: find_by_sql + - pattern: first + - pattern: last + - pattern: new + - pattern: from + - pattern: group + - pattern: having + - pattern: joins + - pattern: lock + - pattern: order + - pattern: reorder + - pattern: select + - pattern: where + - pattern: find_by + - pattern: find_by! + - pattern: take + pattern-sinks: + - pattern: redirect_to(...) + pattern-sanitizers: + - pattern: params.merge(:only_path => true) + - pattern: params.merge(:host => ...) +- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + references: + - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ + category: security + technology: + - rails + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + shortlink: https://sg.run/GO2n + semgrep.dev: + rule: + r_id: 13592 + rv_id: 1263635 + rule_id: 6JU1bL + version_id: bZT53p0 + url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + origin: community + message: Avoid rendering user input. It may be possible for a malicious user to + input a path that lets them access a template they shouldn't. To prevent this, + check dynamic template paths against a predefined allowlist to make sure it's + an allowed template. + languages: + - ruby + severity: WARNING + mode: taint + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + pattern-sinks: + - patterns: + - pattern-inside: render($X => $INPUT, ...) + - pattern: $INPUT + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: action + - pattern: template + - pattern: partial + - pattern: file +- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + languages: + - python + severity: WARNING + metadata: + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-276: Incorrect Default Permissions' + technology: + - python + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + shortlink: https://sg.run/AXY4 + semgrep.dev: + rule: + r_id: 13594 + rv_id: 1263482 + rule_id: zdUYqR + version_id: O9Tpxqr + url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + origin: community + message: These permissions `$BITS` are widely permissive and grant access to more + people than may be necessary. A good default is `0o644` which gives read and write + access to yourself and read access to everyone else. + patterns: + - pattern-inside: os.$METHOD(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: chmod + - pattern: lchmod + - pattern: fchmod + - pattern-either: + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o650 and $BITS < 0o100000 + - patterns: + - pattern: os.$METHOD($FILE, $BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS >= 0o100650 + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-pattern: + metavariable: $BITS + patterns: + - pattern-either: + - pattern: <... stat.S_IWGRP ...> + - pattern: <... stat.S_IXGRP ...> + - pattern: <... stat.S_IWOTH ...> + - pattern: <... stat.S_IXOTH ...> + - pattern: <... stat.S_IRWXO ...> + - pattern: <... stat.S_IRWXG ...> + - patterns: + - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) + - metavariable-comparison: + metavariable: $MOD + comparison: $MOD == 0o111 +- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + languages: + - php + message: '`$QUERY` Detected string concatenation with a non-literal variable in + a Doctrine QueryBuilder method. This could lead to SQL injection if the variable + is user-controlled and not properly sanitized. In order to prevent SQL injection, + use parameterized queries or prepared statements instead.' + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + technology: + - doctrine + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + shortlink: https://sg.run/jwDJ + semgrep.dev: + rule: + r_id: 13965 + rv_id: 1263271 + rule_id: kxUw23 + version_id: 1QTypnG + url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + origin: community + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $QUERY->add(...,$SINK,...) + - pattern: $QUERY->select(...,$SINK,...) + - pattern: $QUERY->addSelect(...,$SINK,...) + - pattern: $QUERY->delete(...,$SINK,...) + - pattern: $QUERY->update(...,$SINK,...) + - pattern: $QUERY->insert(...,$SINK,...) + - pattern: $QUERY->from(...,$SINK,...) + - pattern: $QUERY->join(...,$SINK,...) + - pattern: $QUERY->innerJoin(...,$SINK,...) + - pattern: $QUERY->leftJoin(...,$SINK,...) + - pattern: $QUERY->rightJoin(...,$SINK,...) + - pattern: $QUERY->where(...,$SINK,...) + - pattern: $QUERY->andWhere(...,$SINK,...) + - pattern: $QUERY->orWhere(...,$SINK,...) + - pattern: $QUERY->groupBy(...,$SINK,...) + - pattern: $QUERY->addGroupBy(...,$SINK,...) + - pattern: $QUERY->having(...,$SINK,...) + - pattern: $QUERY->andHaving(...,$SINK,...) + - pattern: $QUERY->orHaving(...,$SINK,...) + - pattern: $QUERY->orderBy(...,$SINK,...) + - pattern: $QUERY->addOrderBy(...,$SINK,...) + - pattern: $QUERY->set($SINK,...) + - pattern: $QUERY->setValue($SINK,...) + - pattern-either: + - pattern-inside: | + $Q = $X->createQueryBuilder(); + ... + - pattern-inside: | + $Q = new QueryBuilder(...); + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: sprintf(...) + - pattern: | + "...".$SMTH + severity: WARNING +- id: python.django.security.injection.raw-html-format.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which + will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - django + references: + - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render + - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/oYj1 + semgrep.dev: + rule: + r_id: 14360 + rv_id: 1263397 + rule_id: 2ZUPER + version_id: 5PTo100 + url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: django.utils.html.escape(...) + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: python.flask.security.injection.raw-html-concat.raw-html-format + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates (`flask.render_template`) which will + safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format + shortlink: https://sg.run/Pb7e + semgrep.dev: + rule: + r_id: 14389 + rv_id: 1409401 + rule_id: GdUrJv + version_id: RGTEN1l + url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern: jinja2.escape(...) + - pattern: flask.escape(...) + - patterns: + - pattern: flask.render_template($TPL, ...) + - metavariable-regex: + metavariable: $TPL + regex: .*\.html + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can + lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing + sensitive data. It is recommend where possible to not allow user-input to craft + the base request, but to be treated as part of the path or query parameter. When + user-input is necessary to craft the request, it is recommended to follow OWASP + best practices to prevent abuse, including using an allowlist. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/5DjW + semgrep.dev: + rule: + r_id: 14391 + rv_id: 1262970 + rule_id: AbUQLr + version_id: yeTxpOj + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$URLSTR" + $INPUT + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + pattern-sinks: + - requires: INPUT and not CLEAN + patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $CLIENT := &http.Client{...} + ... + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: | + http.NewRequest("$METHOD", $URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + severity: WARNING +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `html/template` package which will + safely render HTML instead, or inspect that the HTML is rendered safely. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/3r1G + semgrep.dev: + rule: + r_id: 14443 + rv_id: 1262968 + rule_id: PeUonQ + version_id: 1QTyp2p + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: ruby.rails.security.injection.raw-html-format.raw-html-format + languages: + - ruby + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. Use the `render template` and make template + files which will safely render HTML instead, or inspect that the HTML is absolutely + rendered safely with a function like `sanitize`. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/ + - https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/b2JQ + semgrep.dev: + rule: + r_id: 14470 + rv_id: 1409408 + rule_id: kxUwZX + version_id: qkTvgYY + url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: sanitize(...) + - pattern: strip_tags(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $HTMLSTR + - pattern-regex: <\w+.* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$HTMLSTR", ...) + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR" % $EXPR + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... +- id: bash.curl.security.curl-eval.curl-eval + severity: WARNING + languages: + - bash + message: Data is being eval'd from a `curl` command. An attacker with control of + the server in the `curl` command could inject malicious code into the `eval`, + resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If + you must do this, consider checking the SHA sum of the content returned by the + server to verify its integrity. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + category: security + technology: + - bash + - curl + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval + shortlink: https://sg.run/0yqJ + semgrep.dev: + rule: + r_id: 14554 + rv_id: 1262601 + rule_id: KxU7Rq + version_id: JdTzxL2 + url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval + origin: community + mode: taint + pattern-sources: + - pattern: | + $(curl ...) + - pattern: | + `curl ...` + pattern-sinks: + - pattern: eval ... +- id: python.flask.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - flask + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RXpK + semgrep.dev: + rule: + r_id: 14649 + rv_id: 1409403 + rule_id: ReU3Wb + version_id: BjTy42w + url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: | + $URL = "$URLSTR" + ... + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + severity: WARNING +- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - go + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt` + package. + options: + interfile: true + metadata: + category: security + technology: + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://pkg.go.dev/golang.org/x/crypto/bcrypt + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/4eOE + semgrep.dev: + rule: + r_id: 14688 + rv_id: 1262938 + rule_id: 4bU1Wj + version_id: nWT2L9r + url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5.New + - pattern: md5.Sum + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) + or a safe library. + options: + interfile: true + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + category: security + technology: + - go + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/PbEq + semgrep.dev: + rule: + r_id: 14689 + rv_id: 1409388 + rule_id: PeUoqy + version_id: nWTQ5qD + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + severity: ERROR + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern-inside: | + var $SB strings.Builder + ... + - pattern-inside: | + $SB.WriteString("$SQLSTR") + ... + $SB.String(...) + - pattern: | + $SB.WriteString(...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) +- id: java.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - java + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use + `javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")` + or, if using Spring, `org.springframework.security.crypto.bcrypt`. + metadata: + category: security + technology: + - java + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory + - https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/JxEQ + semgrep.dev: + rule: + r_id: 14690 + rv_id: 1263029 + rule_id: JDULAW + version_id: bZT53QB + url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + $TYPE $MD = MessageDigest.getInstance("MD5"); + ... + - pattern: $MD.digest(...); + pattern-sinks: + - patterns: + - pattern: $MODEL.$METHOD(...); + - metavariable-regex: + metavariable: $METHOD + regex: (?i)(.*password.*) +- id: javascript.express.security.injection.raw-html-format.raw-html-format + message: User data flows into the host portion of this manually-constructed HTML. + This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from + user-provided input. Consider using a sanitization library such as DOMPurify to + sanitize the HTML within. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - express + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format + shortlink: https://sg.run/5DO3 + semgrep.dev: + rule: + r_id: 14691 + rv_id: 1263175 + rule_id: 5rUL0X + version_id: NdTzyQv + url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - label: EXPRESS + patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - label: EXPRESSTS + patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - label: CLEAN + by-side-effect: true + patterns: + - pattern-either: + - pattern: $A($SOURCE) + - pattern: $SANITIZE. ... .$A($SOURCE) + - pattern: $A. ... .$SANITIZE($SOURCE) + - focus-metavariable: $SOURCE + - metavariable-regex: + metavariable: $A + regex: (?i)(.*valid|.*sanitiz) + pattern-sinks: + - requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" + $EXPR' + - pattern: '"$HTMLSTR".concat(...)' + - pattern: util.format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...` + - pattern-regex: | + .*<\w+.* +- id: kotlin.lang.security.ecb-cipher.ecb-cipher + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher + shortlink: https://sg.run/DzLj + semgrep.dev: + rule: + r_id: 14696 + rv_id: 1263263 + rule_id: DbU1Zd + version_id: YDTZexg + url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher + origin: community + message: Cipher in ECB mode is detected. ECB mode produces the same output for the + same input each time which allows an attacker to intercept and replay the data. + Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + severity: WARNING + languages: + - kt + patterns: + - pattern-either: + - pattern: | + val $VAR : Cipher = $CIPHER.getInstance($MODE) + - pattern: | + var $VAR : Cipher = $CIPHER.getInstance($MODE) + - pattern: | + val $VAR = $CIPHER.getInstance($MODE) + - pattern: | + var $VAR = $CIPHER.getInstance($MODE) + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* +- id: kotlin.lang.security.no-null-cipher.no-null-cipher + pattern: NullCipher(...) + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher + shortlink: https://sg.run/0ywb + semgrep.dev: + rule: + r_id: 14698 + rv_id: 1263265 + rule_id: 0oU2Yy + version_id: o5TbDPj + url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - kt + - scala +- id: kotlin.lang.security.use-of-md5.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + languages: + - kt + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5 + shortlink: https://sg.run/4eQx + semgrep.dev: + rule: + r_id: 14700 + rv_id: 1263267 + rule_id: qNUXPj + version_id: pZT03Jd + url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5 + origin: community + pattern-either: + - pattern: | + java.security.MessageDigest.getInstance("MD5") + - pattern: | + org.apache.commons.codec.digest.DigestUtils.getMd5Digest() +- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as SQLAlchemy which will protect your queries. + metadata: + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column + category: security + technology: + - sqlalchemy + - flask + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/JxZj + semgrep.dev: + rule: + r_id: 14702 + rv_id: 1409402 + rule_id: YGUDKQ + version_id: A8TEvb4 + url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string + origin: community + severity: ERROR + languages: + - python + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* +- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`. + languages: + - python + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt + category: security + technology: + - pycryptodome + - hashlib + - md5 + subcategory: + - vuln + likelihood: HIGH + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/5DwD + semgrep.dev: + rule: + r_id: 14703 + rv_id: 1263504 + rule_id: 6JU1w1 + version_id: WrTqKDz + url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: hashlib.md5 + - pattern: hashlib.new(..., name="MD5", ...) + - pattern: Cryptodome.Hash.MD5 + - pattern: Crypto.Hash.MD5 + - pattern: cryptography.hazmat.primitives.hashes.MD5 + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: ruby.lang.security.md5-used-as-password.md5-used-as-password + languages: + - ruby + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Instead, use a suitable password hashing function such as bcrypt. You can use + the `bcrypt` gem. + metadata: + category: security + technology: + - md5 + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/GOZy + semgrep.dev: + rule: + r_id: 14704 + rv_id: 1263611 + rule_id: oqU4p2 + version_id: JdTzx0e + url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - pattern: Digest::MD5 + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...); + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: json.aws.security.wildcard-assume-role.wildcard-assume-role + patterns: + - pattern-inside: | + "Statement": [...] + - pattern-inside: | + {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} + - pattern: | + "Principal": {..., "AWS": "*", ...} + message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone + with your AWS account ID and the name of the role can assume the role. Instead, + limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - aws + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role + shortlink: https://sg.run/7YEZ + semgrep.dev: + rule: + r_id: 15138 + rv_id: 1263256 + rule_id: JDULx5 + version_id: BjTkZoy + url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role + origin: community + languages: + - json + severity: ERROR +- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host + languages: + - ruby + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction + with `SsrfFilter(...)`, or create an allowlist for approved hosts. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://github.com/arkadiyt/ssrf_filter + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/RX3g + semgrep.dev: + rule: + r_id: 14705 + rv_id: 1263668 + rule_id: zdUY0W + version_id: 6xT29BN + url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sanitizers: + - pattern: SsrfFilter + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $URLSTR + - pattern-regex: \w+:\/\/#{.*} + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$URLSTR", ...) + - pattern: | + "$URLSTR" + $EXPR + - pattern: | + "$URLSTR" % $EXPR + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME:// ... +- id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role + patterns: + - pattern-inside: | + resource "aws_iam_role" $NAME { + ... + } + - pattern: assume_role_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-inside: | + {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} + - pattern: | + "Principal": {..., "AWS": "*", ...} + message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone + with your AWS account ID and the name of the role can assume the role. Instead, + limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - aws + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + shortlink: https://sg.run/LXWr + semgrep.dev: + rule: + r_id: 15139 + rv_id: 1263749 + rule_id: 5rUL1P + version_id: LjTkg8D + url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0, + 1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0 + and TLS 1.1 are still supported for backward compatibility. This check will warn + if the minimum TLS is not set to TLS1_2.' + patterns: + - pattern-either: + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + min_tls_version = "$ANYTHING" + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + } + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + min_tls_version = "TLS1_2" + ... + } + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version + - https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + shortlink: https://sg.run/KXD7 + semgrep.dev: + rule: + r_id: 15155 + rv_id: 1263807 + rule_id: AbUQdL + version_id: WrTqKpv + url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + origin: community + languages: + - hcl + severity: ERROR +- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set + metadata: + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - scala + - cryptography + resources: + - https://blog.codacy.com/9-scala-security-issues/ + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + shortlink: https://sg.run/GO5p + semgrep.dev: + rule: + r_id: 15192 + rv_id: 1263677 + rule_id: 3qUj1Q + version_id: yeTxpoX + url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + origin: community + message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken + encryption. This could lead to sensitive data exposure. Instead, use RSA with + `OAEPWithMD5AndMGF1Padding` instead. + severity: WARNING + languages: + - scala + patterns: + - pattern: | + $VAR = $CIPHER.getInstance($MODE) + - metavariable-regex: + metavariable: $MODE + regex: .*RSA/.*/NoPadding.* +- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" + to the bucket props for Bucket construct $X' + metadata: + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + shortlink: https://sg.run/eowX + semgrep.dev: + rule: + r_id: 15276 + rv_id: 1263903 + rule_id: bwU8qz + version_id: GxTkeRx + url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + origin: community + languages: + - typescript + severity: ERROR + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3' + ... + - pattern: const $X = new Bucket(...) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...}) + - pattern-not: | + const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3' + ... + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...}) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...}) +- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + message: Bucket $X is not set to enforce encryption-in-transit, if not explictly + setting this on the bucket policy - the property "enforceSSL" should be set to + true + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + shortlink: https://sg.run/vqBX + semgrep.dev: + rule: + r_id: 15277 + rv_id: 1263904 + rule_id: NbUN8B + version_id: RGT0Llg + url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + origin: community + languages: + - ts + severity: ERROR + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3'; + ... + - pattern: const $X = new Bucket(...) + - pattern-not: | + const $X = new Bucket(..., {enforceSSL: true}, ...) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3'; + ... + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: | + const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...}) +- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" + or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption + at rest for the queue.' + metadata: + category: security + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + shortlink: https://sg.run/d23P + semgrep.dev: + rule: + r_id: 15278 + rv_id: 1263905 + rule_id: kxUwqO + version_id: A8Tgd2W + url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Queue} from '@aws-cdk/aws-sqs' + ... + - pattern: const $X = new Queue(...) + - pattern-not: | + const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-sqs' + ... + - pattern: const $X = new $Y.Queue(...) + - pattern-not: | + const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...}) + - pattern-not: | + const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...}) +- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + message: Using the GrantPublicAccess method on bucket contruct $X will make the + objects in the bucket world accessible. Verify if this is intentional. + metadata: + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + category: security + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + shortlink: https://sg.run/Z4p7 + semgrep.dev: + rule: + r_id: 15279 + rv_id: 1263906 + rule_id: wdUjZK + version_id: BjTkZA7 + url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Bucket} from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new Bucket(...) + ... + $X.grantPublicAccess(...) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-s3' + ... + - pattern: | + const $X = new $Y.Bucket(...) + ... + $X.grantPublicAccess(...) +- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + message: CodeBuild Project $X is set to have a public URL. This will make the build + results, logs, artifacts publically accessible, including builds prior to the + project being public. Ensure this is acceptable for the project. + metadata: + category: security + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + technology: + - AWS-CDK + references: + - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + shortlink: https://sg.run/nK7G + semgrep.dev: + rule: + r_id: 15280 + rv_id: 1263907 + rule_id: x8UxXZ + version_id: DkTRbj1 + url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + origin: community + languages: + - ts + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import {Project} from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new Project(..., {..., badge: true, ...}) + - patterns: + - pattern-inside: | + import * as $Y from '@aws-cdk/aws-codebuild' + ... + - pattern: | + const $X = new $Y.Project(..., {..., badge: true, ...}) +- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + mode: taint + pattern-sinks: + - pattern: | + sqlalchemy.text(...) + pattern-sources: + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X + $Y + - metavariable-type: + metavariable: $Y + type: string + - patterns: + - pattern: | + f"..." + - patterns: + - pattern: | + $X.format(...) + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: | + $X % $Y + - metavariable-type: + metavariable: $X + type: string + message: sqlalchemy.text passes the constructed SQL statement to the database mostly + unchanged. This means that the usual SQL injection protections are not applied + and this function is vulnerable to SQL injection if user input can reach here. + Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct + SQL. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - sqlalchemy + confidence: MEDIUM + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + shortlink: https://sg.run/yP1O + semgrep.dev: + rule: + r_id: 15824 + rv_id: 1263577 + rule_id: r6U2wE + version_id: rxTAKqq + url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + origin: community + languages: + - python + severity: ERROR +- id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + pattern-either: + - patterns: + - pattern: password = "..." + - pattern-inside: | + resource "aws_db_instance" "..." { + ... + } + - patterns: + - pattern: master_password = "..." + - pattern-inside: | + resource "aws_rds_cluster" "..." { + ... + } + languages: + - hcl + severity: WARNING + message: RDS instance or cluster with hardcoded credentials in source code. It is + recommended to pass the credentials at runtime, or generate random credentials + using the random_password resource. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password + - https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + category: security + technology: + - terraform + - aws + - secrets + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + shortlink: https://sg.run/x4qA + semgrep.dev: + rule: + r_id: 15830 + rv_id: 1263896 + rule_id: OrUl6W + version_id: gETB77b + url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + origin: community +- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - ci + confidence: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell + shortlink: https://sg.run/4l9l + semgrep.dev: + rule: + r_id: 16200 + rv_id: 1262664 + rule_id: gxUJrJ + version_id: jQTn5QE + url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell + origin: community + message: Semgrep found a bash reverse shell + severity: ERROR + languages: + - generic + pattern-either: + - pattern: | + sh -i >& /dev/udp/.../... 0>&1 + - pattern: | + <...>/dev/tcp/.../...; sh <&... >&... 2>& + - pattern: | + <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done + - pattern: | + sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& +- id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + patterns: + - pattern: a + - pattern: b + languages: + - hcl + severity: INFO + message: This rule has been deprecated, as all s3 buckets are encrypted by default + with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration + for more info. + metadata: + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + deprecated: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + shortlink: https://sg.run/Jezw + semgrep.dev: + rule: + r_id: 16202 + rv_id: 1263901 + rule_id: 3qU62L + version_id: JdTzxjN + url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + origin: community +- id: php.lang.security.injection.tainted-filename.tainted-filename + severity: WARNING + message: File name based on user input risks server-side request forgery. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename + shortlink: https://sg.run/Ayqp + semgrep.dev: + rule: + r_id: 16250 + rv_id: 1263287 + rule_id: 5rUpro + version_id: 7ZTE3J1 + url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: basename($PATH, ...) + - pattern-inside: linkinfo($PATH, ...) + - pattern-inside: readlink($PATH, ...) + - pattern-inside: realpath($PATH, ...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: opcache_compile_file($FILENAME, ...) + - pattern-inside: opcache_invalidate($FILENAME, ...) + - pattern-inside: opcache_is_script_cached($FILENAME, ...) + - pattern-inside: runkit7_import($FILENAME, ...) + - pattern-inside: readline_read_history($FILENAME, ...) + - pattern-inside: readline_write_history($FILENAME, ...) + - pattern-inside: rar_open($FILENAME, ...) + - pattern-inside: zip_open($FILENAME, ...) + - pattern-inside: gzfile($FILENAME, ...) + - pattern-inside: gzopen($FILENAME, ...) + - pattern-inside: readgzfile($FILENAME, ...) + - pattern-inside: hash_file($ALGO, $FILENAME, ...) + - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) + - pattern-inside: pg_trace($FILENAME, ...) + - pattern-inside: dio_open($FILENAME, ...) + - pattern-inside: finfo_file($FINFO, $FILENAME, ...) + - pattern-inside: mime_content_type($FILENAME, ...) + - pattern-inside: chgrp($FILENAME, ...) + - pattern-inside: chmod($FILENAME, ...) + - pattern-inside: chown($FILENAME, ...) + - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) + - pattern-inside: file_exists($FILENAME, ...) + - pattern-inside: file_get_contents($FILENAME, ...) + - pattern-inside: file_put_contents($FILENAME, ...) + - pattern-inside: file($FILENAME, ...) + - pattern-inside: fileatime($FILENAME, ...) + - pattern-inside: filectime($FILENAME, ...) + - pattern-inside: filegroup($FILENAME, ...) + - pattern-inside: fileinode($FILENAME, ...) + - pattern-inside: filemtime($FILENAME, ...) + - pattern-inside: fileowner($FILENAME, ...) + - pattern-inside: fileperms($FILENAME, ...) + - pattern-inside: filesize($FILENAME, ...) + - pattern-inside: filetype($FILENAME, ...) + - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) + - pattern-inside: fopen($FILENAME, ...) + - pattern-inside: is_dir($FILENAME, ...) + - pattern-inside: is_executable($FILENAME, ...) + - pattern-inside: is_file($FILENAME, ...) + - pattern-inside: is_link($FILENAME, ...) + - pattern-inside: is_readable($FILENAME, ...) + - pattern-inside: is_uploaded_file($FILENAME, ...) + - pattern-inside: is_writable($FILENAME, ...) + - pattern-inside: lchgrp($FILENAME, ...) + - pattern-inside: lchown($FILENAME, ...) + - pattern-inside: lstat($FILENAME, ...) + - pattern-inside: parse_ini_file($FILENAME, ...) + - pattern-inside: readfile($FILENAME, ...) + - pattern-inside: stat($FILENAME, ...) + - pattern-inside: touch($FILENAME, ...) + - pattern-inside: unlink($FILENAME, ...) + - pattern-inside: xattr_get($FILENAME, ...) + - pattern-inside: xattr_list($FILENAME, ...) + - pattern-inside: xattr_remove($FILENAME, ...) + - pattern-inside: xattr_set($FILENAME, ...) + - pattern-inside: xattr_supported($FILENAME, ...) + - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) + - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_new_personal($FILENAME, ...) + - pattern-inside: exif_imagetype($FILENAME, ...) + - pattern-inside: getimagesize($FILENAME, ...) + - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) + - pattern-inside: imagecreatefromavif($FILENAME, ...) + - pattern-inside: imagecreatefrombmp($FILENAME, ...) + - pattern-inside: imagecreatefromgd2($FILENAME, ...) + - pattern-inside: imagecreatefromgd2part($FILENAME, ...) + - pattern-inside: imagecreatefromgd($FILENAME, ...) + - pattern-inside: imagecreatefromgif($FILENAME, ...) + - pattern-inside: imagecreatefromjpeg($FILENAME, ...) + - pattern-inside: imagecreatefrompng($FILENAME, ...) + - pattern-inside: imagecreatefromtga($FILENAME, ...) + - pattern-inside: imagecreatefromwbmp($FILENAME, ...) + - pattern-inside: imagecreatefromwebp($FILENAME, ...) + - pattern-inside: imagecreatefromxbm($FILENAME, ...) + - pattern-inside: imagecreatefromxpm($FILENAME, ...) + - pattern-inside: imageloadfont($FILENAME, ...) + - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) + - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, + ...) + - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) + - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) + - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) + - pattern-inside: fdf_open($FILENAME, ...) + - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) + - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) + - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, + ...) + - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) + - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) + - pattern-inside: posix_access($FILENAME, ...) + - pattern-inside: posix_mkfifo($FILENAME, ...) + - pattern-inside: posix_mknod($FILENAME, ...) + - pattern-inside: ftok($FILENAME, ...) + - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) + - pattern-inside: fann_read_train_from_file($FILENAME, ...) + - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) + - pattern-inside: highlight_file($FILENAME, ...) + - pattern-inside: php_strip_whitespace($FILENAME, ...) + - pattern-inside: stream_resolve_include_path($FILENAME, ...) + - pattern-inside: swoole_async_read($FILENAME, ...) + - pattern-inside: swoole_async_readfile($FILENAME, ...) + - pattern-inside: swoole_async_write($FILENAME, ...) + - pattern-inside: swoole_async_writefile($FILENAME, ...) + - pattern-inside: swoole_load_module($FILENAME, ...) + - pattern-inside: tidy_parse_file($FILENAME, ...) + - pattern-inside: tidy_repair_file($FILENAME, ...) + - pattern-inside: get_meta_tags($FILENAME, ...) + - pattern-inside: yaml_emit_file($FILENAME, ...) + - pattern-inside: yaml_parse_file($FILENAME, ...) + - pattern-inside: curl_file_create($FILENAME, ...) + - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) + - pattern-inside: ftp_delete($FTP, $FILENAME, ...) + - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) + - pattern-inside: ftp_size($FTP, $FILENAME, ...) + - pattern-inside: rrd_create($FILENAME, ...) + - pattern-inside: rrd_fetch($FILENAME, ...) + - pattern-inside: rrd_graph($FILENAME, ...) + - pattern-inside: rrd_info($FILENAME, ...) + - pattern-inside: rrd_last($FILENAME, ...) + - pattern-inside: rrd_lastupdate($FILENAME, ...) + - pattern-inside: rrd_tune($FILENAME, ...) + - pattern-inside: rrd_update($FILENAME, ...) + - pattern-inside: snmp_read_mib($FILENAME, ...) + - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) + - pattern-inside: apache_lookup_uri($FILENAME, ...) + - pattern-inside: md5_file($FILENAME, ...) + - pattern-inside: sha1_file($FILENAME, ...) + - pattern-inside: simplexml_load_file($FILENAME, ...) + - pattern: $FILENAME +- id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + languages: + - php + severity: WARNING + message: <- A new object is created where the class name is based on user input. + This could lead to remote code execution, as it allows to instantiate any class + in the application. + metadata: + cwe: + - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe + Reflection'')' + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + shortlink: https://sg.run/7ndw + semgrep.dev: + rule: + r_id: 16438 + rv_id: 1263288 + rule_id: v8U4DA + version_id: LjTkgLy + url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: new $SINK(...) + - pattern: $SINK +- id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + patterns: + - pattern-inside: | + provider "aws" { + ... + secret_key = "$SECRET" + } + - focus-metavariable: $SECRET + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + languages: + - hcl + severity: WARNING + metadata: + technology: + - secrets + - aws + - terraform + category: security + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + shortlink: https://sg.run/L3kn + semgrep.dev: + rule: + r_id: 16439 + rv_id: 1263735 + rule_id: d8U4n0 + version_id: rxTAK76 + url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials + origin: community +- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + category: security + technology: + - laravel + references: + - https://laravel.com/docs/8.x/queries + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection + shortlink: https://sg.run/x40p + semgrep.dev: + rule: + r_id: 16830 + rv_id: 1263313 + rule_id: j2UQdp + version_id: BjTkZ45 + url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection + origin: community + severity: WARNING + message: Detected a SQL query based on user input. This could lead to SQL injection, + which could potentially result in sensitive data being exfiltrated by attackers. + Instead, use parameterized queries and prepared statements. + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $SQL + - pattern-either: + - pattern-inside: DB::table(...)->whereRaw($SQL, ...) + - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) + - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) + - pattern-inside: DB::table(...)->havingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) + - patterns: + - pattern: $EXPRESSION + - pattern-either: + - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) + - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) + - patterns: + - pattern: $COLUMNS + - pattern-either: + - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereNull($COLUMN) + - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->find($ID, $COLUMNS) + - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) + - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) + - pattern-inside: DB::table(...)->select($COLUMNS) + - pattern-inside: DB::table(...)->get($COLUMNS) + - pattern-inside: DB::table(...)->count($COLUMNS) + - patterns: + - pattern: $COLUMN + - pattern-either: + - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) + - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->having($COLUMN, ...) + - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) + - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) + - pattern-inside: DB::table(...)->orderByDesc($COLUMN) + - pattern-inside: DB::table(...)->latest($COLUMN) + - pattern-inside: DB::table(...)->oldest($COLUMN) + - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->value($COLUMN) + - pattern-inside: DB::table(...)->pluck($COLUMN, ...) + - pattern-inside: DB::table(...)->implode($COLUMN, ...) + - pattern-inside: DB::table(...)->min($COLUMN) + - pattern-inside: DB::table(...)->max($COLUMN) + - pattern-inside: DB::table(...)->sum($COLUMN) + - pattern-inside: DB::table(...)->avg($COLUMN) + - pattern-inside: DB::table(...)->average($COLUMN) + - pattern-inside: DB::table(...)->increment($COLUMN, ...) + - pattern-inside: DB::table(...)->decrement($COLUMN, ...) + - pattern-inside: DB::table(...)->where($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) + - pattern-inside: DB::table(...)->addSelect($COLUMN) + - patterns: + - pattern: $QUERY + - pattern-inside: DB::unprepared($QUERY) +- id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::java.security + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + shortlink: https://sg.run/ryJn + semgrep.dev: + rule: + r_id: 17325 + rv_id: 1263013 + rule_id: KxU5lW + version_id: 0bTKzGX + url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + origin: community + patterns: + - pattern: | + java.security.MessageDigest.getInstance($ALGO, ...); + - metavariable-regex: + metavariable: $ALGO + regex: (?i)(.MD5.) + - focus-metavariable: $ALGO + fix: | + "SHA-512" +- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/bXNp + semgrep.dev: + rule: + r_id: 17326 + rv_id: 1263016 + rule_id: qNUWNn + version_id: l4TJRpL + url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + origin: community + pattern-either: + - patterns: + - pattern: | + java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: | + $DU.getSha1Digest().digest(...) +- id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + patterns: + - pattern: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2018" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2019" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2021" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.2_2025" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_cloudfront_distribution" $ANYTHING { + ... + viewer_certificate { + ... + minimum_protocol_version = "TLSv1.3_2025" + ... + } + ... + } + message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS + versions less than 1.2 are considered insecure because they can be broken. To + fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019", + "TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + shortlink: https://sg.run/Q6o4 + semgrep.dev: + rule: + r_id: 17342 + rv_id: 1263700 + rule_id: kxU6A8 + version_id: 5PTo1bY + url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + patterns: + - pattern: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_cloudwatch_log_group" $ANYTHING { + ... + retention_in_days = ... + ... + } + message: The AWS CloudWatch Log Group has no retention. Missing retention in log + groups can cause losing important event information. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + shortlink: https://sg.run/4lwl + semgrep.dev: + rule: + r_id: 17344 + rv_id: 946665 + rule_id: x8UGBG + version_id: BjT1N2B + url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + origin: community +- id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + patterns: + - pattern: | + resource "aws_codebuild_project" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_codebuild_project" $ANYTHING { + ... + encryption_key = ... + ... + } + message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects + projects in the CodeBuild. To create your own, create a aws_kms_key resource or + use the ARN string of a key in your account. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + shortlink: https://sg.run/5yxA + semgrep.dev: + rule: + r_id: 17347 + rv_id: 946669 + rule_id: v8U4kG + version_id: K3TJbNr + url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + origin: community +- id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + patterns: + - pattern: | + resource "aws_db_instance" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_db_instance" $ANYTHING { + ... + enabled_cloudwatch_logs_exports = [$SOMETHING, ...] + ... + } + message: Database instance has no logging. Missing logs can cause missing important + event information. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + shortlink: https://sg.run/GyAp + semgrep.dev: + rule: + r_id: 17348 + rv_id: 1263704 + rule_id: d8U4RA + version_id: BjTkZ6j + url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + origin: community +- id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + patterns: + - pattern: | + resource "aws_dynamodb_table" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_dynamodb_table" $ANYTHING { + ... + server_side_encryption { + enabled = true + kms_key_arn = ... + } + ... + } + message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However, + for added security, it's recommended to configure your own AWS KMS encryption + key to protect your data in the DynamoDB table. You can either create a new aws_kms_key + resource or use the ARN of an existing key in your AWS account to do so. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + shortlink: https://sg.run/Ay4p + semgrep.dev: + rule: + r_id: 17350 + rv_id: 1263707 + rule_id: nJUGe2 + version_id: 0bTKzj8 + url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + origin: community +- id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_ebs_snapshot_copy" $ANYTHING { + ... + encrypted = true + ... + } + - pattern-not-inside: | + resource "aws_ebs_snapshot_copy" $ANYTHING { + ... + encrypted = true + kms_key_id = ... + ... + } + message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you + control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + shortlink: https://sg.run/ByPW + semgrep.dev: + rule: + r_id: 17351 + rv_id: 946677 + rule_id: EwUqko + version_id: A8TJzb0 + url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + patterns: + - pattern: | + resource "aws_ebs_encryption_by_default" $ANYTHING { + ... + enabled = false + ... + } + message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the + EBS. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + shortlink: https://sg.run/Dy5Y + semgrep.dev: + rule: + r_id: 17352 + rv_id: 946678 + rule_id: 7KUW7K + version_id: BjT1N2v + url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + origin: community +- id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + patterns: + - pattern-either: + - pattern: | + resource "aws_instance" $ANYTHING { + ... + associate_public_ip_address = true + ... + } + - pattern: | + resource "aws_launch_template" $ANYTHING { + ... + network_interfaces { + ... + associate_public_ip_address = true + ... + } + ... + } + message: EC2 instances should not have a public IP address attached in order to + block public access to the instances. To fix this, set your `associate_public_ip_address` + to `"false"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + shortlink: https://sg.run/08rv + semgrep.dev: + rule: + r_id: 17354 + rv_id: 1263709 + rule_id: 8GUA2n + version_id: qkTR73G + url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + patterns: + - pattern: | + resource "aws_efs_file_system" $ANYTHING { + ... + encrypted = true + ... + } + - pattern-not-inside: | + resource "aws_efs_file_system" $ANYTHING { + ... + encrypted = true + kms_key_id = ... + ... + } + message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you + control over the encryption key in terms of access and rotation. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + shortlink: https://sg.run/Kk07 + semgrep.dev: + rule: + r_id: 17355 + rv_id: 946690 + rule_id: gxUJ4n + version_id: 2KTYbWy + url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + patterns: + - pattern-either: + - pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + node_to_node_encryption { + ... + enabled = false + ... + } + ... + } + - pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + cluster_config { + ... + instance_count = $COUNT + ... + } + } + - pattern-not-inside: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + cluster_config { + ... + instance_count = $COUNT + ... + } + node_to_node_encryption { + ... + enabled = true + ... + } + } + - metavariable-comparison: + metavariable: $COUNT + comparison: $COUNT > 1 + message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t" + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + shortlink: https://sg.run/lp3y + semgrep.dev: + rule: + r_id: 17357 + rv_id: 1263719 + rule_id: 3qU6J7 + version_id: WrTqK0v + url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + patterns: + - pattern-inside: | + resource "aws_glacier_vault" $ANYTHING { + ... + } + - pattern: access_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-inside: | + {..., "Effect": "Allow", ...} + - pattern-either: + - pattern: | + "Principal": "*" + - pattern: | + "Principal": {..., "AWS": "*", ...} + - pattern-inside: | + "Principal": {..., "AWS": ..., ...} + - pattern-regex: | + (^\"arn:aws:iam::\*:(.*)\"$) + message: 'Detected wildcard access granted to Glacier Vault. This means anyone within + your AWS account ID can perform actions on Glacier resources. Instead, limit to + a specific identity in your account, like this: `arn:aws:iam:::`.' + metadata: + category: security + technology: + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + shortlink: https://sg.run/XN9K + semgrep.dev: + rule: + r_id: 17364 + rv_id: 1263723 + rule_id: AbUeYK + version_id: l4TJRGB + url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + patterns: + - pattern-inside: | + resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING { + ... + } + - pattern: inline_policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} + - pattern: | + {..., "Action": "*", "Resource": "*", ...} + - pattern: | + {..., "Action": "*", "Resource": [...], ...} + - pattern: | + {..., "Action": [...], "Resource": "*", ...} + message: Detected admin access granted in your policy. This means anyone with this + policy can perform administrative actions. Instead, limit actions and resources + to what you need according to least privilege. + metadata: + category: security + technology: + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + shortlink: https://sg.run/jzgY + semgrep.dev: + rule: + r_id: 17365 + rv_id: 1263724 + rule_id: BYUzY5 + version_id: YDTZe9q + url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + patterns: + - pattern-inside: | + resource "aws_iam_policy" $ANYTHING { + ... + } + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} + - pattern: | + {..., "Action": "*", "Resource": "*", ...} + - pattern: | + {..., "Action": "*", "Resource": [...], ...} + - pattern: | + {..., "Action": [...], "Resource": "*", ...} + message: Detected admin access granted in your policy. This means anyone with this + policy can perform administrative actions. Instead, limit actions and resources + to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + shortlink: https://sg.run/1zbw + semgrep.dev: + rule: + r_id: 17366 + rv_id: 1263725 + rule_id: DbUx8l + version_id: 6xT29Pv + url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + patterns: + - pattern: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + parameter { + name = "require_ssl" + value = "true" + } + ... + } + - pattern-not-inside: | + resource "aws_redshift_parameter_group" $ANYTHING { + ... + parameter { + name = "require_ssl" + value = true + } + ... + } + message: Detected an AWS Redshift configuration with a SSL disabled. To fix this, + set your `require_ssl` to `"true"`. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + shortlink: https://sg.run/yPYx + semgrep.dev: + rule: + r_id: 17368 + rv_id: 1263727 + rule_id: 0oUrOj + version_id: zyTb27A + url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + patterns: + - pattern-inside: | + resource "aws_kms_key" $ANYTHING { + ... + } + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + metavariable: $STATEMENT + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...} + message: Detected wildcard access granted in your KMS key. This means anyone with + this policy can perform administrative actions over the keys. Instead, limit principals, + actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + shortlink: https://sg.run/Nwlp + semgrep.dev: + rule: + r_id: 17371 + rv_id: 1263729 + rule_id: lBUWPD + version_id: 2KTv2J4 + url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + patterns: + - pattern-either: + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + enable_key_rotation = false + ... + } + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + customer_master_key_spec = "SYMMETRIC_DEFAULT" + enable_key_rotation = false + ... + } + - pattern: | + resource "aws_kms_key" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_kms_key" $ANYTHING { + ... + enable_key_rotation = true + ... + } + - pattern-not-inside: | + resource "aws_kms_key" $ANYTHING { + ... + customer_master_key_spec = "RSA_2096" + ... + } + message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be + used by attackers. To fix this, set a `enable_key_rotation`. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + technology: + - aws + - terraform + category: security + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + shortlink: https://sg.run/kz47 + semgrep.dev: + rule: + r_id: 17372 + rv_id: 1263730 + rule_id: PeU0L3 + version_id: X0Tzy67 + url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + origin: community +- id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials + patterns: + - pattern-inside: | + resource "$ANYTING" $ANYTHING { + ... + environment { + variables = { + ... + } + } + ... + } + - pattern-either: + - pattern-inside: | + AWS_ACCESS_KEY_ID = "$Y" + - pattern-regex: | + (? + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern: | + File.$METHOD($X,...) + - metavariable-regex: + metavariable: $METHOD + regex: (?i)^(read|write) + pattern-sanitizers: + - pattern: | + Path.GetFileName(...) + - patterns: + - pattern-inside: | + $X = Path.GetFileName(...); + ... + - pattern: $X + - patterns: + - pattern: $X + - pattern-inside: | + if(<... Path.GetFileName($X) != $X ...>){ + ... + throw new $EXCEPTION(...); + } + ... + message: String argument $A is used to read or write data from a file via Path.Combine + without direct sanitization via Path.GetFileName. If the path is user-supplied + data this can lead to path traversal. + languages: + - csharp + severity: WARNING + metadata: + category: security + confidence: MEDIUM + references: + - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ + - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks + technology: + - .net + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + shortlink: https://sg.run/1RvG + semgrep.dev: + rule: + r_id: 18222 + rv_id: 1262632 + rule_id: 3qU3bE + version_id: vdT0644 + url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + origin: community +- id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0 + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + shortlink: https://sg.run/9LJr + semgrep.dev: + rule: + r_id: 18223 + rv_id: 1262633 + rule_id: 4bUQ81 + version_id: d6Tyx4K + url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + origin: community + message: The top level wildcard bindings $PREFIX leaves your application open to + security vulnerabilities and give attackers more control over where traffic is + routed. If you must use wildcards, consider using subdomain wildcard binding. + For example, you can use "*.asdf.gov" if you own all of "asdf.gov". + patterns: + - pattern-inside: | + using System.Net; + ... + - pattern: $LISTENER.Prefixes.Add("$PREFIX") + - metavariable-regex: + metavariable: $PREFIX + regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+ +- id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + severity: WARNING + languages: + - C# + metadata: + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + owasp: A01:2017 - Injection + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0 + category: security + technology: + - .net + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + shortlink: https://sg.run/NgRy + semgrep.dev: + rule: + r_id: 18227 + rv_id: 945224 + rule_id: GdUDBP + version_id: yeT0nDq + url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + origin: community + message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based + Denial of Service (DoS) attack. Consider setting the timeout to a short amount + of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double + check that your context meets the conditions outlined in the "Notes to Callers" + section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0' + patterns: + - pattern-inside: | + using System.Text.RegularExpressions; + ... + - pattern-either: + - pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout) + - patterns: + - pattern: new Regex(..., TimeSpan.FromSeconds($TIME)) + - metavariable-comparison: + metavariable: $TIME + comparison: $TIME > 5 + - pattern: new Regex(..., TimeSpan.FromMinutes(...)) + - pattern: new Regex(..., TimeSpan.FromHours(...)) +- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $XMLDOCUMENT.$METHOD(...) + - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver + = new XmlUrlResolver(...);\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + shortlink: https://sg.run/k98P + semgrep.dev: + rule: + r_id: 18228 + rv_id: 1262654 + rule_id: ReUK9k + version_id: K3TKk5E + url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + XmlReader $READER = XmlReader.Create(...,$RS,...); + - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing + = DtdProcessing.Parse;\n... \n" + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + shortlink: https://sg.run/wXjA + semgrep.dev: + rule: + r_id: 18229 + rv_id: 1262655 + rule_id: AbU3pX + version_id: qkTR7WD + url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + origin: community +- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + public $T $M(...,string $ARG,...){...} + pattern-sinks: + - patterns: + - pattern: | + $READER.$METHOD(...) + - pattern-not-inside: | + $READER.DtdProcessing = DtdProcessing.Prohibit; + ... + - pattern-inside: | + XmlTextReader $READER = new XmlTextReader(...); + ... + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling + a string argument from a public method. Enabling Document Type Definition (DTD) + parsing may cause XML External Entity (XXE) injection if supplied with user-controllable + data. + languages: + - csharp + severity: WARNING + metadata: + category: security + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + technology: + - .net + - xml + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + shortlink: https://sg.run/xXjL + semgrep.dev: + rule: + r_id: 18230 + rv_id: 1262656 + rule_id: BYUevk + version_id: l4TJRWG + url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + origin: community +- id: go.aws-lambda.security.database-sqli.database-sqli + languages: + - go + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' + calls. + mode: taint + metadata: + references: + - https://pkg.go.dev/database/sql#DB.Query + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - database + - sql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli + shortlink: https://sg.run/e5e8 + semgrep.dev: + rule: + r_id: 18232 + rv_id: 1262909 + rule_id: WAUdJ7 + version_id: BjTkZkQ + url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.Exec($QUERY,...) + - pattern: $DB.ExecContent($QUERY,...) + - pattern: $DB.Query($QUERY,...) + - pattern: $DB.QueryContext($QUERY,...) + - pattern: $DB.QueryRow($QUERY,...) + - pattern: $DB.QueryRowContext($QUERY,...) + - pattern-inside: | + import "database/sql" + ... + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + severity: WARNING +- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - go + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/vX3Y + semgrep.dev: + rule: + r_id: 18233 + rv_id: 1262910 + rule_id: 0oUwqg + version_id: DkTRbRL + url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} + ... + lambda.Start($HANDLER, ...) + - patterns: + - pattern-inside: | + func $HANDLER($EVENT $TYPE) {...} + ... + lambda.Start($HANDLER, ...) + - pattern-not-inside: | + func $HANDLER($EVENT context.Context) {...} + ... + lambda.Start($HANDLER, ...) + - focus-metavariable: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "$SQLSTR" + ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + - pattern-not-inside: | + log.$PRINT(...) + pattern-sanitizers: + - pattern: strconv.Atoi(...) +- id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + message: '`Clean` is not intended to sanitize against path traversal attacks. This + function is for finding the shortest path name equivalent to the given input. + Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix + this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package + `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + severity: ERROR + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sanitizers: + - pattern-either: + - pattern: | + "/" + ... + fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + options: + interfile: true + metadata: + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - go + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + shortlink: https://sg.run/ZKzw + semgrep.dev: + rule: + r_id: 18235 + rv_id: 1262967 + rule_id: qNUQJe + version_id: jQTn5Bj + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + origin: community +- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + options: + interfile: true + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EBYN + semgrep.dev: + rule: + r_id: 18237 + rv_id: 1262977 + rule_id: YGUl4z + version_id: O9TpxQN + url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - pattern-not-inside: | + System.out.$PRINTLN(...) +- id: java.aws-lambda.security.tainted-sqli.tainted-sqli + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead + to SQL injection if variables in the SQL statement are not properly sanitized. + Use parameterized SQL queries or properly sanitize user input instead. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: | + $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + - pattern: | + $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) + options: + interfile: true + metadata: + category: security + technology: + - sql + - java + - aws-lambda + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli + shortlink: https://sg.run/7942 + semgrep.dev: + rule: + r_id: 18238 + rv_id: 1262978 + rule_id: 6JUDWk + version_id: e1Tyj4g + url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli + origin: community +- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + message: Detected input from a HTTPServletRequest going into a SQL sink or statement. + This could lead to SQL injection if variables in the SQL statement are not properly + sanitized. Use parameterized SQL queries or properly sanitize user input instead. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://owasp.org/www-community/attacks/SQL_Injection + subcategory: + - vuln + technology: + - sql + - java + - servlets + - spring + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/Lg56 + semgrep.dev: + rule: + r_id: 18239 + rv_id: 1409390 + rule_id: oqUBJG + version_id: 7ZTKJNj + url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + languages: + - java + mode: taint + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ).$REQFUNC(...) + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: | + (java.sql.Statement $STMT) = ...; + ... + $OUTPUT = $STMT.$FUNC(...); + - pattern: | + (java.sql.PreparedStatement $STMT) = ...; + - pattern: | + $VAR = $CONN.prepareStatement(...) + - pattern: | + $PATH.queryForObject(...); + - pattern: | + (java.util.Map $STMT) = $PATH.queryForMap(...); + - pattern: | + (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; + - pattern: | + (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) + - patterns: + - pattern-inside: | + (String $SQL) = "$SQLSTR" + ...; + ... + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) +- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' + or 'exec' command. This could lead to command injection if variables passed into + the exec commands are not properly sanitized. Instead, avoid using these OS commands + with user-supplied input, or, if you must use these commands, use a whitelist + of specific values. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (ProcessBuilder $PB) = ...; + - patterns: + - pattern: | + (Process $P) = ...; + - pattern-not: | + (Process $P) = (java.lang.Runtime $R).exec(...); + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, ...); + - focus-metavariable: $CMD + - patterns: + - pattern-either: + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n...\n$PB.command($ARGLIST);\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder + $PB) = ...;\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process + $P) = ...;\n" + - pattern: | + $ARGLIST.add(...); + metadata: + category: security + technology: + - java + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + shortlink: https://sg.run/8zPN + semgrep.dev: + rule: + r_id: 18240 + rv_id: 1263042 + rule_id: zdUWrg + version_id: LjTkg9J + url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + origin: community +- id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + message: Detected input from a HTTPServletRequest going into an LDAP query. This + could lead to LDAP injection if the input is not properly sanitized, which could + result in attackers modifying objects in the LDAP tree structure. Ensure data + passed to an LDAP query is not controllable or properly sanitize the data. + metadata: + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection + category: security + technology: + - java + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + shortlink: https://sg.run/gRg0 + semgrep.dev: + rule: + r_id: 18241 + rv_id: 1409392 + rule_id: pKUXAv + version_id: 8KT3Pe6 + url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + origin: community + severity: WARNING + languages: + - java + mode: taint + pattern-sources: + - patterns: + - pattern: (HttpServletRequest $REQ) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (javax.naming.directory.InitialDirContext $IDC).search(...) + - pattern: | + (javax.naming.directory.DirContext $CTX).search(...) + - pattern-not: | + (javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...) + - pattern-not: | + (javax.naming.directory.DirContext $CTX).search($Y, "...", ...) +- id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + message: Detected input from a HTTPServletRequest going into a session command, + like `setAttribute`. User input into such a command could lead to an attacker + inputting malicious code into your session parameters, blurring the line between + what's trusted and untrusted, and therefore leading to a trust boundary violation. + This could lead to programmers trusting unvalidated data. Instead, thoroughly + sanitize user input before passing it into such function calls. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: | + (HttpServletRequest $REQ).$FUNC(...) + - pattern-not: | + (HttpServletRequest $REQ).getSession() + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... ); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + - patterns: + - pattern-inside: | + $HEADERS = (HttpServletRequest $REQ).getHeaders(...); + ... + $PARAM = $HEADERS.$FUNC(...); + ... + - pattern: | + java.net.URLDecoder.decode($PARAM, ...) + pattern-sinks: + - patterns: + - pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE); + - metavariable-regex: + metavariable: $FUNC + regex: ^(putValue|setAttribute)$ + - focus-metavariable: $VALUE + options: + interfile: true + metadata: + category: security + technology: + - java + cwe: + - 'CWE-501: Trust Boundary Violation' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + shortlink: https://sg.run/QbDZ + semgrep.dev: + rule: + r_id: 18242 + rv_id: 1409393 + rule_id: 2ZU7Eo + version_id: gETrv9j + url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + origin: community +- id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + message: Detected input from a HTTPServletRequest going into a XPath evaluate or + compile command. This could lead to xpath injection if variables passed into the + evaluate or compile commands are not properly sanitized. Xpath injection could + lead to unauthorized access to sensitive information in XML documents. Instead, + thoroughly sanitize user input or use parameterized xpath queries if you can. + languages: + - java + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: | + (HttpServletRequest $REQ).$FUNC(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (javax.xml.xpath.XPath $XP).evaluate(...) + - pattern: | + (javax.xml.xpath.XPath $XP).compile(...).evaluate(...) + metadata: + category: security + technology: + - java + cwe: + - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath + Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XPath Injection + source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + shortlink: https://sg.run/3BvK + semgrep.dev: + rule: + r_id: 18243 + rv_id: 1409394 + rule_id: X5U5nj + version_id: QkTERKP + url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + origin: community +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + shortlink: https://sg.run/4Dv5 + semgrep.dev: + rule: + r_id: 18244 + rv_id: 1263057 + rule_id: j2UrJ8 + version_id: 0bTKzgX + url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + origin: community + message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external + entity declarations, this is vulnerable to XML external entity attacks. Disable + this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + false); + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + } + - pattern-not-inside: | + $RETURNTYPE $METHOD(...){ + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); + ... + $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/PYBz + semgrep.dev: + rule: + r_id: 18245 + rv_id: 1263058 + rule_id: 10UPQB + version_id: K3TKk80 + url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This + is vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, + allow DOCTYPE declarations and only prohibit external entities declarations. This + can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = DocumentBuilderFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = DocumentBuilderFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newDocumentBuilder(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newDocumentBuilder(); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + shortlink: https://sg.run/JgPy + semgrep.dev: + rule: + r_id: 18246 + rv_id: 1263059 + rule_id: 9AUJ6r + version_id: qkTR7Lk + url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", + false); + languages: + - java +- id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + shortlink: https://sg.run/5Lv0 + semgrep.dev: + rule: + r_id: 18247 + rv_id: 1263060 + rule_id: yyUNeo + version_id: l4TJRoL + url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + origin: community + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML + external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" + to false. + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + true); + fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", + false); + languages: + - java +- id: javascript.aws-lambda.security.detect-child-process.detect-child-process + message: Allowing spawning arbitrary programs or running shell processes with arbitrary + arguments may end up in a command injection vulnerability. Try to avoid non-literal + values for the command string. If it is not possible, then do not let running + arbitrary commands, use a white list for inputs. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process + shortlink: https://sg.run/Ggoq + semgrep.dev: + rule: + r_id: 18248 + rv_id: 1263105 + rule_id: r6UDNQ + version_id: YDTZe4o + url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: exec($CMD,...) + - pattern: execSync($CMD,...) + - pattern: spawn($CMD,...) + - pattern: spawnSync($CMD,...) + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-either: + - pattern-inside: | + require('child_process') + ... + - pattern-inside: | + import 'child_process' + ... +- id: javascript.aws-lambda.security.knex-sqli.knex-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from + table'', [userinput])`' + metadata: + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli + shortlink: https://sg.run/RgWq + semgrep.dev: + rule: + r_id: 18249 + rv_id: 1263106 + rule_id: bwUBlj + version_id: JdTzxKg + url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $KNEX.fromRaw($QUERY, ...) + - pattern: $KNEX.whereRaw($QUERY, ...) + - pattern: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... +- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://www.npmjs.com/package/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/A502 + semgrep.dev: + rule: + r_id: 18250 + rv_id: 1263107 + rule_id: NbUBJ2 + version_id: 5PTo1En + url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $POOL.query($QUERY, ...) + - pattern: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('mysql') + ... + - pattern-inside: | + require('mysql2') + ... + - pattern-inside: | + require('mysql2/promise') + ... + - pattern-inside: | + import 'mysql' + ... + - pattern-inside: | + import 'mysql2' + ... + - pattern-inside: | + import 'mysql2/promise' + ... +- id: javascript.aws-lambda.security.pg-sqli.pg-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query(''SELECT + $1 from table'', [userinput])`' + metadata: + references: + - https://node-postgres.com/features/queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/BGKA + semgrep.dev: + rule: + r_id: 18251 + rv_id: 1263108 + rule_id: kxU25P + version_id: GxTkeJL + url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('pg') + ... + - pattern-inside: | + import 'pg' + ... +- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + message: 'Detected SQL statement that is tainted by `$EVENT` object. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `sequelize.query(''SELECT + * FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT + });`' + metadata: + references: + - https://sequelize.org/master/manual/raw-queries.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequelize + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + shortlink: https://sg.run/DAlP + semgrep.dev: + rule: + r_id: 18252 + rv_id: 1263109 + rule_id: wdUA5o + version_id: RGT0LrD + url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('sequelize') + ... + - pattern-inside: | + import 'sequelize' + ... +- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/0Gvj + semgrep.dev: + rule: + r_id: 18254 + rv_id: 1263111 + rule_id: OrUJBY + version_id: BjTkZ8D + url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - focus-metavariable: $BODY + - pattern-inside: | + {..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... } +- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + message: The `vm` module enables compiling and running code within V8 Virtual Machine + contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted + code. If code passed to `vm` functions is controlled by user input it could result + in command injection. Do not let user input in `vm` functions. + metadata: + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + category: security + technology: + - javascript + - aws-lambda + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + shortlink: https://sg.run/q9w7 + semgrep.dev: + rule: + r_id: 18256 + rv_id: 1263114 + rule_id: v8UOdZ + version_id: 0bTKz9J + url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + require('vm'); + ... + - pattern-inside: | + import 'vm' + ... + - pattern-either: + - pattern: $VM.runInContext($X,...) + - pattern: $VM.runInNewContext($X,...) + - pattern: $VM.runInThisContext($X,...) + - pattern: $VM.compileFunction($X,...) + - pattern: new $VM.Script($X,...) + - pattern: new $VM.SourceTextModule($X,...) + - pattern: runInContext($X,...) + - pattern: runInNewContext($X,...) + - pattern: runInThisContext($X,...) + - pattern: compileFunction($X,...) + - pattern: new Script($X,...) + - pattern: new SourceTextModule($X,...) +- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT + $1 from table'', [userinput])` can help prevent SQLi.' + metadata: + confidence: MEDIUM + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - express + - nodejs + - knex + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + shortlink: https://sg.run/l9eE + semgrep.dev: + rule: + r_id: 18257 + rv_id: 1263205 + rule_id: d8UKLD + version_id: l4TJRey + url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $KNEX.fromRaw($QUERY, ...) + - pattern-inside: $KNEX.whereRaw($QUERY, ...) + - pattern-inside: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: | + require('knex') + ... + - pattern-inside: | + import 'knex' + ... + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) +- id: php.lang.security.deserialization.extract-user-data + mode: taint + pattern-sources: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_FILES[...] + - pattern: $_POST[...] + pattern-sinks: + - pattern: extract(...) + pattern-sanitizers: + - pattern: extract($VAR, EXTR_SKIP,...) + message: Do not call 'extract()' on user-controllable data. If you must, then you + must also provide the EXTR_SKIP flag to prevent overwriting existing variables. + languages: + - php + metadata: + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + technology: + - php + references: + - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data + shortlink: https://sg.run/6bv1 + semgrep.dev: + rule: + r_id: 18259 + rv_id: 1263278 + rule_id: nJUykq + version_id: w8TRovw + url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data + origin: community + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected 'create_subprocess_exec' function with argument tainted by `event` + object. If this data can be controlled by a malicious actor, it may be an instance + of command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + shortlink: https://sg.run/oyv0 + semgrep.dev: + rule: + r_id: 18260 + rv_id: 1263331 + rule_id: EwUrX8 + version_id: rxTAKgo + url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", $CMD, ...], ...) + message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted + by `event` object. If this data can be controlled by a malicious actor, it may + be an instance of command injection. Audit the use of this call to ensure it is + not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + shortlink: https://sg.run/z14d + semgrep.dev: + rule: + r_id: 18261 + rv_id: 1263332 + rule_id: 7KUxXg + version_id: bZT53Ww + url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern: asyncio.create_subprocess_shell($CMD, ...) + message: Detected asyncio subprocess function with argument tainted by `event` object. + If this data can be controlled by a malicious actor, it may be an instance of + command injection. Audit the use of this call to ensure it is not controllable + by an external resource. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + shortlink: https://sg.run/p9vZ + semgrep.dev: + rule: + r_id: 18262 + rv_id: 1263333 + rule_id: L1UEl7 + version_id: NdTzyWA + url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + origin: community + languages: + - python + severity: ERROR +- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Ensure no external data reaches here. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/2AjL + semgrep.dev: + rule: + r_id: 18263 + rv_id: 1263334 + rule_id: 8GUGBq + version_id: kbTzGv8 + url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - patterns: + - pattern: os.$METHOD($MODE, $CMD, ...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) +- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + message: Detected subprocess function with argument tainted by an `event` object. If + this data can be controlled by a malicious actor, it may be an instance of command + injection. The default option for `shell` is False, and this is secure by default. + Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` + means you have to split the command string into an array of strings for the command + and its arguments. You may consider using 'shlex.split()' for this purpose. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/XZ7B + semgrep.dev: + rule: + r_id: 18264 + rv_id: 1263335 + rule_id: gxUyn1 + version_id: w8TRogj + url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: subprocess.$FUNC(..., shell=True, ...) + pattern-sanitizers: + - pattern: shlex.split(...) + - pattern: pipes.quote(...) + - pattern: shlex.quote(...) +- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call + mode: taint + message: Detected `os` function with argument tainted by `event` object. This is + dangerous if external data can reach this function call because it allows a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/jDvN + semgrep.dev: + rule: + r_id: 18265 + rv_id: 1263336 + rule_id: QrUkg6 + version_id: xyTjzbG + url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: os.system($CMD,...) + - pattern: os.popen($CMD,...) + - pattern: os.popen2($CMD,...) + - pattern: os.popen3($CMD,...) + - pattern: os.popen4($CMD,...) +- id: python.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli + shortlink: https://sg.run/1RjG + semgrep.dev: + rule: + r_id: 18266 + rv_id: 1263337 + rule_id: 3qU3eE + version_id: O9TpxLJ + url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern-either: + - pattern-inside: | + import mysql + ... + - pattern-inside: | + import mysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://www.psycopg.org/docs/cursor.html#cursor.execute + - https://www.psycopg.org/docs/cursor.html#cursor.executemany + - https://www.psycopg.org/docs/cursor.html#cursor.mogrify + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - psycopg + - psycopg2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + shortlink: https://sg.run/9L8r + semgrep.dev: + rule: + r_id: 18267 + rv_id: 1263338 + rule_id: 4bUQG1 + version_id: e1TyjPZ + url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern: $CURSOR.mogrify($QUERY,...) + - pattern-inside: | + import psycopg2 + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', ''active'')`' + mode: taint + metadata: + references: + - https://pypi.org/project/pymssql/ + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymssql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + shortlink: https://sg.run/yXvP + semgrep.dev: + rule: + r_id: 18268 + rv_id: 1263339 + rule_id: PeUxO0 + version_id: vdT06bG + url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import pymssql + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = %s'', (''active''))`' + mode: taint + metadata: + references: + - https://pypi.org/project/PyMySQL/#id4 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - pymysql + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + shortlink: https://sg.run/reve + semgrep.dev: + rule: + r_id: 18269 + rv_id: 1263340 + rule_id: JDUlel + version_id: d6TyxNA + url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-either: + - pattern-inside: | + import pymysql + ... + - pattern-inside: | + import pymysql.cursors + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + languages: + - python + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute(''SELECT + * FROM projects WHERE status = ?'', ''active'')`' + mode: taint + metadata: + references: + - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sqlalchemy + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + shortlink: https://sg.run/b48W + semgrep.dev: + rule: + r_id: 18270 + rv_id: 1263341 + rule_id: 5rUy3N + version_id: ZRTKARp + url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + origin: community + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: | + import sqlalchemy + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: WARNING +- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval($CODE, ...) + - pattern: exec($CODE, ...) + message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate + dynamic content. If this content can be input from outside the program, this may + be a code injection vulnerability. Ensure evaluated content is not definable by + external sources. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + shortlink: https://sg.run/Ng7y + semgrep.dev: + rule: + r_id: 18271 + rv_id: 1263342 + rule_id: GdUDJP + version_id: nWT2LD2 + url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + origin: community + languages: + - python + severity: WARNING +- id: python.aws-lambda.security.tainted-html-response.tainted-html-response + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern: $BODY + - pattern-inside: | + {..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... } + message: Detected user input flowing into an HTML response. You may be accidentally + bypassing secure methods of rendering HTML by manually constructing HTML and this + could create a cross-site scripting vulnerability, which could let attackers steal + sensitive user data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/k9vP + semgrep.dev: + rule: + r_id: 18272 + rv_id: 1263343 + rule_id: ReUKrk + version_id: ExTEx5o + url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response + origin: community + languages: + - python + severity: WARNING +- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/wXvA + semgrep.dev: + rule: + r_id: 18273 + rv_id: 1263346 + rule_id: AbU3LX + version_id: 8KT5ron + url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR" % ... + - pattern: | + "$SQLSTR".format(...) + - pattern: | + f"$SQLSTR{...}..." + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= + - pattern-not-inside: | + print(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + severity: ERROR +- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT + title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`' + mode: taint + metadata: + references: + - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - active-record + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + shortlink: https://sg.run/vXvY + semgrep.dev: + rule: + r_id: 18277 + rv_id: 1263581 + rule_id: 0oUw9g + version_id: w8TRor7 + url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: ActiveRecord::Base.connection.execute($QUERY,...) + - pattern: $MODEL.find_by_sql($QUERY,...) + - pattern: $MODEL.select_all($QUERY,...) + - pattern-inside: | + require 'active_record' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' + mode: taint + metadata: + references: + - https://github.com/brianmario/mysql2 + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - mysql2 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + shortlink: https://sg.run/dJLE + semgrep.dev: + rule: + r_id: 18278 + rv_id: 1263582 + rule_id: KxUrQ3 + version_id: xyTjzOe + url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CLIENT.query($QUERY,...) + - pattern: $CLIENT.prepare($QUERY,...) + - pattern-inside: | + require 'mysql2' + ... + pattern-sanitizers: + - pattern: $CLIENT.escape(...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.pg-sqli.pg-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `conn.exec_params(''SELECT + $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`' + mode: taint + metadata: + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - postgres + - pg + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli + shortlink: https://sg.run/ZKww + semgrep.dev: + rule: + r_id: 18279 + rv_id: 1263583 + rule_id: qNUQee + version_id: O9Tpxz7 + url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CONN.exec($QUERY,...) + - pattern: $CONN.exec_params($QUERY,...) + - pattern: $CONN.exec_prepared($QUERY,...) + - pattern: $CONN.async_exec($QUERY,...) + - pattern: $CONN.async_exec_params($QUERY,...) + - pattern: $CONN.async_exec_prepared($QUERY,...) + - pattern-inside: | + require 'pg' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead + to SQL injection if the variable is user-controlled and not properly sanitized. + In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `DB[''select * from items + where name = ?'', name]`' + mode: taint + metadata: + references: + - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + - sequel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + shortlink: https://sg.run/n9vY + semgrep.dev: + rule: + r_id: 18280 + rv_id: 1263584 + rule_id: lBUy2N + version_id: e1Tyj5j + url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + origin: community + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: DB[$QUERY,...] + - pattern: DB.run($QUERY,...) + - pattern-inside: | + require 'sequel' + ... + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as Sequelize which will protect your queries. + metadata: + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + category: security + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/EB7N + semgrep.dev: + rule: + r_id: 18281 + rv_id: 1263586 + rule_id: PeUxOE + version_id: d6Tyx1Z + url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + "...#{...}..." + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", ...) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - pattern-not-inside: | + puts(...) +- id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + patterns: + - pattern: secure = false + - pattern-inside: | + session = { + ... + } + message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag + for cookies prevents the client from transmitting the cookie over insecure channels + such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration + file. + languages: + - generic + severity: WARNING + paths: + include: + - '*.conf' + metadata: + category: security + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security + - https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration + technology: + - play + - scala + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + shortlink: https://sg.run/8z8N + semgrep.dev: + rule: + r_id: 18284 + rv_id: 1263685 + rule_id: GdUDJO + version_id: e1TyjJv + url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + origin: community +- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli + mode: taint + metadata: + references: + - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values + - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - slick + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + shortlink: https://sg.run/k9K2 + semgrep.dev: + rule: + r_id: 18328 + rv_id: 1263687 + rule_id: GdUDWO + version_id: d6TyxJe + url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + origin: community + message: Detected a tainted SQL statement. This could lead to SQL injection if variables + in the SQL statement are not properly sanitized. Avoid using using user input + for generating SQL strings. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.overrideSql(...) + - pattern: sql"..." + - pattern-inside: | + import slick.$DEPS + ... + severity: ERROR + languages: + - scala +- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + patterns: + - pattern-inside: | + import ("github.com/gorilla/websocket") + ... + - patterns: + - pattern-not-inside: | + $UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...} + ... + - pattern-not-inside: | + $UPGRADER.CheckOrigin = $FN2 + ... + - pattern: | + $UPGRADER.Upgrade(...) + message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee + that the connection accepted by the WebSocket is from a trusted origin domain. + Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" + documentation: "A CheckOrigin function should carefully validate the request origin + to prevent cross-site request forgery."' + languages: + - go + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader + technology: + - gorilla + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + shortlink: https://sg.run/xXpz + semgrep.dev: + rule: + r_id: 18430 + rv_id: 1262914 + rule_id: ReUKdz + version_id: qkTR7RP + url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + origin: community +- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/Lgqr + semgrep.dev: + rule: + r_id: 18483 + rv_id: 1263112 + rule_id: PeUxwW + version_id: DkTRbvp + url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern: $EVENT + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + $EXPR + - pattern: | + "$HTMLSTR".concat(...) + - pattern: $UTIL.format($HTMLSTR, ...) + - pattern: format($HTMLSTR, ...) + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - patterns: + - pattern: | + `...${...}...` + - pattern-regex: | + .*<\w+.* + - pattern-not-inside: | + console.$LOG(...) +- id: python.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - python + severity: WARNING + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. Otherwise, use templates which will safely render HTML instead. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - aws-lambda + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string + shortlink: https://sg.run/8zNy + semgrep.dev: + rule: + r_id: 18484 + rv_id: 1263344 + rule_id: JDUlwy + version_id: 7ZTE36K + url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: | + $HTML = "$HTMLSTR" + ... + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + metavariable: $HTMLSTR + language: generic + pattern: <$TAG ... + - pattern-not-inside: | + print(...) +- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf + patterns: + - pattern-either: + - pattern: Source.fromURL($URL,...) + - pattern: Source.fromURI($URL,...) + - pattern-inside: | + import scala.io.$SOURCE + ... + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + message: A parameter being passed directly into `fromURL` most likely lead to SSRF. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data sent with this request. They could also probe internal servers + or other resources that the server running this code can access. Do not allow + arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode + the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource + category: security + technology: + - scala + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + shortlink: https://sg.run/Qbz4 + semgrep.dev: + rule: + r_id: 18486 + rv_id: 1263675 + rule_id: GdUDOZ + version_id: 1QTypG9 + url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + origin: community + languages: + - scala + severity: WARNING +- id: scala.lang.security.audit.scalac-debug.scalac-debug + patterns: + - pattern-either: + - pattern: scalacOptions ... "-Vdebug" + - pattern: scalacOptions ... "-Ydebug" + message: Scala applications built with `debug` set to true in production may leak + debug information to attackers. Debug mode also affects performance and reliability. + Remove it from configuration. + languages: + - generic + severity: WARNING + paths: + include: + - '*.sbt*' + metadata: + category: security + cwe: + - 'CWE-489: Active Debug Code' + owasp: A05:2021 - Security Misconfiguration + technology: + - scala + - sbt + references: + - https://docs.scala-lang.org/overviews/compiler-options/index.html + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug + shortlink: https://sg.run/QbGd + semgrep.dev: + rule: + r_id: 18686 + rv_id: 946569 + rule_id: JDUlE0 + version_id: qkT4j0N + url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug + origin: community +- id: scala.play.security.tainted-html-response.tainted-html-response + mode: taint + metadata: + category: security + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - scala + - play + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response + shortlink: https://sg.run/BG96 + semgrep.dev: + rule: + r_id: 18795 + rv_id: 1263686 + rule_id: 0oUwn2 + version_id: vdT06yj + url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response + origin: community + message: Detected a request with potential user-input going into an `Ok()` response. + This bypasses any view or template environments, including HTML escaping, which + may expose this application to cross-site scripting (XSS) vulnerabilities. Consider + using a view technology such as Twirl which automatically escapes HTML views. + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sanitizers: + - pattern-either: + - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) + - pattern: org.owasp.encoder.Encode.forHtml(...) + pattern-sinks: + - pattern-either: + - pattern: Html.apply(...) + - pattern: Ok(...).as(HTML) + - pattern: Ok(...).as(ContentTypes.HTML) + - patterns: + - pattern: Ok(...).as($CTYPE) + - metavariable-regex: + metavariable: $CTYPE + regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' + - patterns: + - pattern: Ok(...).as($CTYPE) + - pattern-not: Ok(...).as("...") + - pattern-either: + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = $A { + ... + } + - pattern-inside: | + def $FUNC(..., $URL: $T, ...) = { + ... + } + severity: WARNING + languages: + - scala +- id: terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + patterns: + - pattern-either: + - pattern: | + resource "aws_api_gateway_domain_name" $ANYTHING { + ... + security_policy = "..." + ... + } + - pattern: | + resource "aws_apigatewayv2_domain_name" $ANYTHING { + ... + domain_name_configuration {...} + ... + } + - pattern-not: | + resource "aws_api_gateway_domain_name" $ANYTHING { + ... + security_policy = "TLS_1_2" + ... + } + - pattern-not: | + resource "aws_apigatewayv2_domain_name" $ANYTHING { + ... + domain_name_configuration { + ... + security_policy = "TLS_1_2" + ... + } + } + message: Detected AWS API Gateway to be using an insecure version of TLS. To fix + this issue make sure to set "security_policy" equal to "TLS_1_2". + languages: + - terraform + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - aws + - terraform + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + shortlink: https://sg.run/p98J + semgrep.dev: + rule: + r_id: 18818 + rv_id: 1263726 + rule_id: v8UOle + version_id: o5TbD8k + url: https://semgrep.dev/playground/r/o5TbD8k/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + origin: community +- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + patterns: + - pattern-either: + - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); + - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); + - metavariable-comparison: + metavariable: $M + comparison: re.match(".*-CBC",$M) + message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext + attacks against encrypted data. + languages: + - php + severity: ERROR + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + references: + - https://csrc.nist.gov/publications/detail/sp/800-38a/final + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + technology: + - php + - openssl + category: security + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + shortlink: https://sg.run/LgWJ + semgrep.dev: + rule: + r_id: 19039 + rv_id: 1263295 + rule_id: DbUGbE + version_id: JdTzxOD + url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + origin: community +- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + patterns: + - pattern-inside: | + import pdi.jwt.$DEPS + ... + - pattern-either: + - pattern: $JWT.encode($X, "...", ...) + - pattern: $JWT.decode($X, "...", ...) + - pattern: $JWT.decodeRawAll($X, "...", ...) + - pattern: $JWT.decodeRaw($X, "...", ...) + - pattern: $JWT.decodeAll($X, "...", ...) + - pattern: $JWT.validate($X, "...", ...) + - pattern: $JWT.isValid($X, "...", ...) + - pattern: $JWT.decodeJson($X, "...", ...) + - pattern: $JWT.decodeJsonAll($X, "...", ...) + - patterns: + - pattern-either: + - pattern: $JWT.encode($X, $KEY, ...) + - pattern: $JWT.decode($X, $KEY, ...) + - pattern: $JWT.decodeRawAll($X, $KEY, ...) + - pattern: $JWT.decodeRaw($X, $KEY, ...) + - pattern: $JWT.decodeAll($X, $KEY, ...) + - pattern: $JWT.validate($X, $KEY, ...) + - pattern: $JWT.isValid($X, $KEY, ...) + - pattern: $JWT.decodeJson($X, $KEY, ...) + - pattern: $JWT.decodeJsonAll($X, $KEY, ...) + - pattern: $JWT.encode($X, this.$KEY, ...) + - pattern: $JWT.decode($X, this.$KEY, ...) + - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) + - pattern: $JWT.decodeRaw($X, this.$KEY, ...) + - pattern: $JWT.decodeAll($X, this.$KEY, ...) + - pattern: $JWT.validate($X, this.$KEY, ...) + - pattern: $JWT.isValid($X, this.$KEY, ...) + - pattern: $JWT.decodeJson($X, this.$KEY, ...) + - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) + - pattern-either: + - pattern-inside: | + class $CL { + ... + $KEY = "..." + ... + } + - pattern-inside: | + object $CL { + ... + $KEY = "..." + ... + } + - metavariable-pattern: + metavariable: $JWT + patterns: + - pattern-either: + - pattern: Jwt + - pattern: JwtArgonaut + - pattern: JwtCirce + - pattern: JwtJson4s + - pattern: JwtJson + - pattern: JwtUpickle + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + languages: + - scala + severity: WARNING + metadata: + references: + - https://jwt-scala.github.io/jwt-scala/ + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - scala + confidence: HIGH + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + shortlink: https://sg.run/8zE7 + semgrep.dev: + rule: + r_id: 19040 + rv_id: 1263669 + rule_id: WAUdK0 + version_id: o5TbDA8 + url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + origin: community +- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + patterns: + - pattern-either: + - pattern: | + $DF = DocumentBuilderFactory.newInstance(...) + ... + $DB = $DF.newDocumentBuilder(...) + - patterns: + - pattern: $DB = DocumentBuilderFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $DB.newDocumentBuilder(...) + - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $DB.setXIncludeAware(true) + ... + $DB.setNamespaceAware(true) + ... + $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: Document Builder being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + shortlink: https://sg.run/gRQn + semgrep.dev: + rule: + r_id: 19041 + rv_id: 1263673 + rule_id: 0oUwzP + version_id: X0TzyRq + url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + origin: community +- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + patterns: + - pattern-either: + - pattern: $SR = new SAXReader(...) + - pattern: | + $SF = SAXParserFactory.newInstance(...) + ... + $SR = $SF.newSAXParser(...) + - patterns: + - pattern: $SR = SAXParserFactory.newInstance(...) + - pattern-not-inside: | + ... + $X = $SR.newSAXParser(...) + - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) + - pattern: $SR = new SAXBuilder(...) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + - pattern-not-inside: | + ... + $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) + ... + $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) + ... + $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + message: XML processor being instantiated without calling the `setFeature` functions + that are generally used for disabling entity processing. User controlled data + in XML Parsers can result in XML Internal Entity Processing vulnerabilities like + the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + shortlink: https://sg.run/QbYP + semgrep.dev: + rule: + r_id: 19042 + rv_id: 1263678 + rule_id: KxUrkq + version_id: rxTAKWY + url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + origin: community +- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + patterns: + - pattern-not-inside: | + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) + - pattern-either: + - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) + - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) + - pattern: $XMLFACTORY = new XMLInputFactory(...) + message: XMLInputFactory being instantiated without calling the setProperty functions + that are generally used for disabling entity processing. User controlled data + in XML Document builder can result in XML Internal Entity Processing vulnerabilities + like the disclosure of confidential data, denial of service, Server Side Request + Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. + languages: + - scala + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - scala + confidence: HIGH + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + shortlink: https://sg.run/3BEb + semgrep.dev: + rule: + r_id: 19043 + rv_id: 1263683 + rule_id: qNUQ7w + version_id: xyTjzkA + url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + origin: community +- id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + patterns: + - pattern-either: + - pattern: X-Requested-With = "*" + - pattern: Csrf-Token = "..." + - pattern-inside: | + bypassHeaders {... + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."application/x-www-form-urlencoded"..."multipart/form-data"..."text/plain"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."application/x-www-form-urlencoded"..."text/plain"..."multipart/form-data"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."multipart/form-data"..."application/x-www-form-urlencoded"..."text/plain"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."multipart/form-data"..."text/plain"..."application/x-www-form-urlencoded"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."text/plain"..."application/x-www-form-urlencoded"..."multipart/form-data"...] + ... + ...} + - pattern-not-inside: | + {... + ... + ...blackList = [..."text/plain"..."multipart/form-data"..."application/x-www-form-urlencoded"...] + ... + ...} + message: "Possibly bypassable CSRF configuration found. CSRF is an attack that forces + an end user to execute unwanted actions on a web application in which they\u2019re + currently authenticated. Make sure that Content-Type black list is configured + and CORS filter is turned on." + languages: + - generic + severity: ERROR + paths: + include: + - '*.conf' + metadata: + references: + - https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes + - https://owasp.org/www-community/attacks/csrf + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - scala + - play + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + shortlink: https://sg.run/4DEE + semgrep.dev: + rule: + r_id: 19044 + rv_id: 1263684 + rule_id: lBUyRR + version_id: O9Tpx53 + url: https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + origin: community +- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + pattern: | + resource "aws_elasticsearch_domain" $ANYTHING { + ... + domain_endpoint_options { + ... + enforce_https = true + tls_security_policy = "Policy-Min-TLS-1-0-2019-07" + ... + } + ... + } + message: Detected an AWS Elasticsearch domain using an insecure version of TLS. + To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07". + languages: + - terraform + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - aws + - terraform + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + shortlink: https://sg.run/PYlq + semgrep.dev: + rule: + r_id: 19045 + rv_id: 1263718 + rule_id: YGUle7 + version_id: DkTRbA5 + url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + origin: community +- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + message: User data from `$REQ` is being compiled into the template, which can lead + to a Server Side Template Injection (SSTI) vulnerability. + options: + interfile: true + metadata: + interfile: true + category: security + cwe: + - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + technology: + - javascript + - typescript + - express + - pug + - jade + - dot + - ejs + - nunjucks + - lodash + - handlbars + - mustache + - hogan.js + - eta + - squirrelly + source_rule_url: + - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + shortlink: https://sg.run/b49v + semgrep.dev: + rule: + r_id: 19226 + rv_id: 1263165 + rule_id: EwUr9k + version_id: zyTb2eD + url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-propagators: + - pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) + from: $E + to: $S + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('pug') + ... + - pattern-inside: | + import * as $PUG from 'pug' + ... + - pattern-inside: | + $PUG = require('jade') + ... + - pattern-inside: | + import * as $PUG from 'jade' + ... + - pattern-either: + - pattern: $PUG.compile(...) + - pattern: $PUG.compileClient(...) + - pattern: $PUG.compileClientWithDependenciesTracked(...) + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('dot') + ... + - pattern-inside: | + import * as $PUG from 'dot' + ... + - pattern-either: + - pattern: $PUG.template(...) + - pattern: $PUG.compile(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('ejs') + ... + - pattern-inside: | + import * as $PUG from 'ejs' + ... + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('nunjucks') + ... + - pattern-inside: | + import * as $PUG from 'nunjucks' + ... + - pattern-either: + - pattern: $PUG.renderString(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('lodash') + ... + - pattern-inside: | + import * as $PUG from 'lodash' + ... + - pattern-either: + - pattern: $PUG.template(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('mustache') + ... + - pattern-inside: | + import * as $PUG from 'mustache' + ... + - pattern-inside: | + $PUG = require('eta') + ... + - pattern-inside: | + import * as $PUG from 'eta' + ... + - pattern-inside: | + $PUG = require('squirrelly') + ... + - pattern-inside: | + import * as $PUG from 'squirrelly' + ... + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: | + $PUG = require('hogan.js') + ... + - pattern-inside: | + import * as $PUG from 'hogan.js' + ... + - pattern-inside: | + $PUG = require('handlebars') + ... + - pattern-inside: | + import * as $PUG from 'handlebars' + ... + - pattern-either: + - pattern: $PUG.compile(...) +- id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + patterns: + - pattern: jinja2.Environment(... , autoescape=$VAL, ...) + - pattern-not: jinja2.Environment(... , autoescape=True, ...) + - pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...), + ...) + - focus-metavariable: $VAL + fix: | + True + message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous + if you are rendering to a browser because this allows for cross-site scripting + (XSS) attacks. If you are in a web context, enable 'autoescaping' by setting 'autoescape=True.' + You may also consider using 'jinja2.select_autoescape()' to only enable automatic + escaping for certain file extensions. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + category: security + technology: + - jinja2 + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Encoding + source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + shortlink: https://sg.run/L2L7 + semgrep.dev: + rule: + r_id: 20039 + rv_id: 1263448 + rule_id: QrU1Xg + version_id: gETB7oN + url: https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + origin: community + languages: + - python + severity: WARNING +- id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + patterns: + - pattern-not: jinja2.Environment(..., autoescape=$VAL, ...) + - pattern: jinja2.Environment(...) + fix-regex: + regex: (.*)\) + replacement: \1, autoescape=True) + message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape + by default. This is dangerous if you are rendering to a browser because this allows + for cross-site scripting (XSS) attacks. If you are in a web context, enable autoescaping + by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' + to only enable automatic escaping for certain file extensions. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + category: security + technology: + - jinja2 + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Encoding + source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + shortlink: https://sg.run/8kY4 + semgrep.dev: + rule: + r_id: 20040 + rv_id: 1263449 + rule_id: 3qULRx + version_id: QkTGqje + url: https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + origin: community + languages: + - python + severity: WARNING +- id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + mode: search + paths: + include: + - '*.erb' + patterns: + - pattern: | + params[...] + - pattern-inside: | + render :file => ... + message: Found request parameters in a call to `render` in a dynamic context. This + can allow end users to request arbitrary local files which may result in leaking + sensitive information persisted on disk. + languages: + - generic + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + shortlink: https://sg.run/3QWl + semgrep.dev: + rule: + r_id: 20043 + rv_id: 1263651 + rule_id: JDUokO + version_id: QkTGq9X + url: https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + origin: community +- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + mode: taint + pattern-sources: + - patterns: + - pattern: params[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + render ..., file: $X + - pattern: | + render ..., inline: $X + - pattern: | + render ..., template: $X + - pattern: | + render ..., action: $X + - pattern: | + render $X, ... + - focus-metavariable: $X + pattern-sanitizers: + - patterns: + - pattern: $MAP[...] + - metavariable-pattern: + metavariable: $MAP + patterns: + - pattern-not-regex: params + - pattern: File.basename(...) + message: Found request parameters in a call to `render`. This can allow end users + to request arbitrary local files which may result in leaking sensitive information + persisted on disk. Where possible, avoid letting users specify template paths + for `render`. If you must allow user input, use an allow-list of known templates + or normalize the user-supplied value with `File.basename(...)`. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + vulnerability_class: + - Path Traversal + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + shortlink: https://sg.run/Jw8Z + semgrep.dev: + rule: + r_id: 20046 + rv_id: 1409407 + rule_id: ReU2pZ + version_id: K3TgANN + url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + origin: community +- id: ruby.rails.security.brakeman.check-secrets.check-secrets + patterns: + - pattern: $VAR = "$VALUE" + - metavariable-regex: + metavariable: $VAR + regex: (?i)password|secret|(rest_auth_site|api)_key$ + - metavariable-regex: + metavariable: $VALUE + regex: .+ + message: Found a Brakeman-style secret - a variable with the name password/secret/api_key/rest_auth_site_key + and a non-empty string literal value. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - rails + category: security + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_secrets.rb + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://github.com/presidentbeef/brakeman/blob/3f5d5d5f00864cdf7769c50f5bd26f1769a4ba75/test/apps/rails3.1/app/controllers/users_controller.rb + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-secrets.check-secrets + shortlink: https://sg.run/5ZKl + semgrep.dev: + rule: + r_id: 20047 + rv_id: 1263659 + rule_id: AbUNqO + version_id: A8TgdBv + url: https://semgrep.dev/playground/r/A8TgdBv/ruby.rails.security.brakeman.check-secrets.check-secrets + origin: community +- id: ruby.rails.security.brakeman.check-send-file.check-send-file + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: | + send_file ... + message: Allowing user input to `send_file` allows a malicious user to potentially + read arbitrary files from the server. Avoid accepting user input in `send_file` + or normalize with `File.basename(...)` + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb + category: security + cwe: + - 'CWE-73: External Control of File Name or Path' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/Path_Traversal + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file + shortlink: https://sg.run/GbY1 + semgrep.dev: + rule: + r_id: 20048 + rv_id: 1263660 + rule_id: BYUKbl + version_id: BjTkZRj + url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file + origin: community +- id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/ALD6 + semgrep.dev: + rule: + r_id: 20050 + rv_id: 1263682 + rule_id: WAUY8B + version_id: w8TRoO6 + url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + origin: community + pattern-sources: + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = $A { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: s"..." + - pattern: f"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) + - pattern-not-inside: throw new $EXCEPTION(...) + pattern-sanitizers: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $LOGGER.$METHOD(...) + - pattern: $LOGGER(...) + - metavariable-regex: + metavariable: $LOGGER + regex: (i?)log.* + - patterns: + - pattern: $LOGGER.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (i?)(trace|info|warn|warning|warnToError|error|debug) +- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - scala + severity: ERROR + mode: taint + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - scala + - play + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + shortlink: https://sg.run/BeW9 + semgrep.dev: + rule: + r_id: 20051 + rv_id: 1263688 + rule_id: 0oUpon + version_id: ZRTKAoG + url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + origin: community + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { + ... + } + - pattern-inside: | + def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { + ... + } + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".format(...) + - patterns: + - pattern-inside: | + $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR" + ... + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern: s"..." + - pattern-regex: | + .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* + - pattern-not-inside: println(...) +- id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + patterns: + - pattern: | + $KEY: $VALUE + - pattern-inside: | + data: ... + - pattern-inside: | + kind: Secret + ... + - metavariable-regex: + metavariable: $VALUE + regex: (?i)^[aA-zZ0-9+/]+={0,2}$ + - metavariable-analysis: + analyzer: entropy + metavariable: $VALUE + message: 'Secrets ($VALUE) should not be stored in infrastructure as code files. + Use an alternative such as Bitnami Sealed Secrets or KSOPS to encrypt Kubernetes + Secrets. ' + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + category: security + technology: + - kubernetes + references: + - https://kubernetes.io/docs/concepts/configuration/secret/ + - https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF + - https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html + - https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/ + - https://github.com/bitnami-labs/sealed-secrets + - https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/ + - https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/ + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + shortlink: https://sg.run/KyL6 + semgrep.dev: + rule: + r_id: 20055 + rv_id: 1263942 + rule_id: YGUYEb + version_id: xyTjz5B + url: https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + origin: community + languages: + - yaml + severity: WARNING +- id: dockerfile.security.last-user-is-root.last-user-is-root + patterns: + - pattern: USER root + - pattern-not-inside: + patterns: + - pattern: | + USER root + ... + USER $X + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: root + message: The last user in the container is 'root'. This is a security hazard because + if an attacker gains control of the container they will have root access. Switch + back to another user after running commands as 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 + references: + - https://github.com/hadolint/hadolint/wiki/DL3002 + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root + shortlink: https://sg.run/5Z43 + semgrep.dev: + rule: + r_id: 20147 + rv_id: 1262658 + rule_id: ReU2n5 + version_id: 6xT29Eg + url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root + origin: community +- id: dockerfile.security.missing-user.missing-user + patterns: + - pattern: | + CMD $...VARS + - pattern-not-inside: | + USER $USER + ... + - pattern-not-inside: | + HEALTHCHECK ... CMD ... + fix: | + USER non-root + CMD $...VARS + message: By not specifying a USER, a program in the container may run as 'root'. + This is a security hazard. If an attacker can control a process running as root, + they may have control over the container. Ensure that the last USER in a Dockerfile + is a USER other than 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user + shortlink: https://sg.run/Gbvn + semgrep.dev: + rule: + r_id: 20148 + rv_id: 1262660 + rule_id: AbUN06 + version_id: zyTb2n2 + url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user + origin: community +- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends + selecting Argon2id unless you can guarantee an adversary has no direct access + to the computing environment. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + - https://eprint.iacr.org/2016/759.pdf + - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf + - https://datatracker.ietf.org/doc/html/rfc9106#section-4 + category: security + cwe: + - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' + technology: + - argon2 + - cryptography + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + impact: LOW + likelihood: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + shortlink: https://sg.run/ALq4 + semgrep.dev: + rule: + r_id: 20150 + rv_id: 1263103 + rule_id: DbU2X8 + version_id: qkTR7Jk + url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + $ARGON = require('argon2'); + ... + - pattern: | + {type: ...} + pattern-sinks: + - patterns: + - pattern: | + $Y + - pattern-inside: | + $ARGON.hash(...,$Y) + pattern-sanitizers: + - patterns: + - pattern: '{type: $ARGON.argon2id}' +- id: ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + patterns: + - pattern-either: + - patterns: + - pattern: | + :$KEY => "$LITERAL" + - pattern-inside: | + ActionController::Base.session = {...} + - pattern: | + $RAILS::Application.config.$KEY = "$LITERAL" + - pattern: | + Rails.application.config.$KEY = "$LITERAL" + - metavariable-regex: + metavariable: $KEY + regex: ^secret(_(token|key_base))?$ + message: Found a string literal assignment to a Rails session secret `$KEY`. Do + not commit secret values to source control! Any user in possession of this value + may falsify arbitrary session data in your application. Read this value from an + environment variable, KMS, or file on disk outside of source control. + languages: + - ruby + severity: WARNING + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_session_settings.rb + category: security + cwe: + - 'CWE-540: Inclusion of Sensitive Information in Source Code' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - ruby + - rails + references: + - https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/02-Testing_for_Cookies_Attributes + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails4_with_engines/config/initializers/secret_token.rb + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3/config/initializers/secret_token.rb + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + shortlink: https://sg.run/KyJd + semgrep.dev: + rule: + r_id: 20155 + rv_id: 1263656 + rule_id: lBUX1r + version_id: 5PTo1ZY + url: https://semgrep.dev/playground/r/5PTo1ZY/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + origin: community +- id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + - patterns: + - pattern: $Y + - pattern-either: + - pattern-inside: | + $RECORD.read_attribute($Y) + - pattern-inside: | + $RECORD[$Y] + - metavariable-regex: + metavariable: $RECORD + regex: '[A-Z][a-z]+' + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $Y + - pattern-inside: | + /...#{...}.../ + - patterns: + - pattern: $Y + - pattern-inside: | + Regexp.new(...) + message: Found a potentially user-controllable argument in the construction of a + regular expressions. This may result in excessive resource consumption when applied + to certain inputs, or when the user is allowed to control the match target. Avoid + allowing users to specify regular expressions processed by the server. If you + must support user-controllable input in a regular expression, use an allow-list + to restrict the expressions users may supply to limit catastrophic backtracking. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb + category: security + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + owasp: + - A03:2017 - Sensitive Data Exposure + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + shortlink: https://sg.run/qZwx + semgrep.dev: + rule: + r_id: 20156 + rv_id: 1409406 + rule_id: YGUY4R + version_id: 0bTG0WO + url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + origin: community +- id: ruby.rails.security.brakeman.check-before-filter.check-before-filter + mode: search + patterns: + - pattern-either: + - pattern: | + skip_filter ..., :except => $ARGS + - pattern: | + skip_before_filter ..., :except => $ARGS + - pattern: | + skip_before_action ..., :except => $ARGS + message: 'Disabled-by-default Rails controller checks make it much easier to introduce + access control mistakes. Prefer an allowlist approach with `:only => [...]` rather + than `except: => [...]`' + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_skip_before_filter.rb + category: security + cwe: + - 'CWE-284: Improper Access Control' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - ruby + - rails + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-before-filter.check-before-filter + shortlink: https://sg.run/O4Zn + semgrep.dev: + rule: + r_id: 20531 + rv_id: 1263649 + rule_id: wdUkBP + version_id: 8KT5rDy + url: https://semgrep.dev/playground/r/8KT5rDy/ruby.rails.security.brakeman.check-before-filter.check-before-filter + origin: community +- id: ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + mode: search + patterns: + - pattern: | + if request.get? + ... + else + ... + end + - pattern-not-inside: | + if ... + elsif ... + ... + end + message: Found an improperly constructed control flow block with `request.get?`. + Rails will route HEAD requests as GET requests but they will fail the `request.get?` + check, potentially causing unexpected behavior unless an `elif` condition is used. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_verb_confusion.rb + category: security + cwe: + - 'CWE-650: Trusting HTTP Permission Methods on the Server Side' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/accounts_controller.rb + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + shortlink: https://sg.run/eJ6y + semgrep.dev: + rule: + r_id: 20532 + rv_id: 1263652 + rule_id: x8UdDE + version_id: 3ZT4X82 + url: https://semgrep.dev/playground/r/3ZT4X82/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + origin: community +- id: ruby.rails.security.brakeman.check-sql.check-sql + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + :$KEY => $X + - pattern-inside: | + ["...",$X,...] + - pattern: | + params[...].to_i + - pattern: | + params[...].to_f + - patterns: + - pattern: | + params[...] ? $A : $B + - metavariable-pattern: + metavariable: $A + patterns: + - pattern-not: | + params[...] + - metavariable-pattern: + metavariable: $B + patterns: + - pattern-not: | + params[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-not-inside: | + $P.where("...",...) + - pattern-not-inside: | + $P.where(:$KEY => $VAL,...) + - pattern-either: + - pattern-inside: | + $P.$M(...) + - pattern-inside: | + $P.$M("...",...) + - pattern-inside: | + class $P < ActiveRecord::Base + ... + end + - metavariable-regex: + metavariable: $M + regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) + message: Found potential SQL injection due to unsafe SQL query construction via + $X. Where possible, prefer parameterized queries. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://owasp.org/www-community/attacks/SQL_Injection + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql + shortlink: https://sg.run/vpgb + semgrep.dev: + rule: + r_id: 20533 + rv_id: 1263661 + rule_id: OrUv2z + version_id: DkTRbE4 + url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql + origin: community +- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X. ... .to_proc + - patterns: + - pattern-inside: | + $Y.method($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap($Z) + - focus-metavariable: $Z + - patterns: + - pattern-inside: | + $Y.tap{ |$ANY| $Z } + - focus-metavariable: $Z + message: Found user-controllable input to a reflection method. This may allow a + user to alter program behavior and potentially execute arbitrary instructions + in the context of the process. Do not provide arbitrary user input to `tap`, `method`, + or `to_proc` + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + shortlink: https://sg.run/dPYd + semgrep.dev: + rule: + r_id: 20534 + rv_id: 1263662 + rule_id: eqUZ2Q + version_id: WrTqKLA + url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + origin: community +- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + message: Found the use of an hardcoded passphrase for RSA. The passphrase can be + easily discovered, and therefore should not be stored in source-code. It is recommended + to remove the passphrase from source-code, and use system environment variables + or a restricted configuration file. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + - secrets + category: security + references: + - https://cwe.mitre.org/data/definitions/522.html + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + shortlink: https://sg.run/xPEe + semgrep.dev: + rule: + r_id: 20730 + rv_id: 1263607 + rule_id: bwULyN + version_id: K3TKkEo + url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') + - patterns: + - pattern-inside: | + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + - pattern-either: + - pattern: | + $OPENSSL.export(...,'...') + - pattern: | + $OPENSSL.to_pem(...,'...') + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + end + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: | + $ASSIGN = '...' + ... + def $METHOD(...) + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + $ASSIGN = '...' + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = '...' + ... + end + ... + def $METHOD2(...) + ... + $OPENSSL = OpenSSL::PKey::RSA.new(...) + ... + end + ... + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) +- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended + to use a key length of 2048 or higher. + languages: + - ruby + severity: WARNING + metadata: + technology: + - ruby + category: security + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + shortlink: https://sg.run/O4Re + semgrep.dev: + rule: + r_id: 20731 + rv_id: 1263608 + rule_id: NbUe4N + version_id: qkTR76v + url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + origin: community + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) + - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $ASSIGN = $SIZE + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - patterns: + - pattern-inside: | + def $METHOD1(...) + ... + $ASSIGN = $SIZE + ... + end + ... + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - metavariable-comparison: + metavariable: $SIZE + comparison: $SIZE < 2048 +- id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern: url_for(params[...],...,:only_path => false,...) + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $F(...) + - metavariable-pattern: + metavariable: $F + patterns: + - pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to) + - pattern: | + params.merge! :only_path => true + ... + - pattern: | + params.slice(...) + ... + - pattern: | + redirect_to [...] + - patterns: + - pattern: | + $MODEL. ... .$M(...) + ... + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\w+' + - metavariable-regex: + metavariable: $M + regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take) + - patterns: + - pattern: | + params.$UNSAFE_HASH.merge(...,:only_path => true,...) + ... + - metavariable-regex: + metavariable: $UNSAFE_HASH + regex: to_unsafe_h(ash)? + - patterns: + - pattern: params.permit(...,$X,...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not-regex: (host|port|(sub)?domain) + pattern-sinks: + - patterns: + - pattern: $X + - pattern-inside: | + redirect_to $X, ... + - pattern-not-regex: params\.\w+(? true` hash value. + languages: + - ruby + severity: WARNING + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb + category: security + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + technology: + - ruby + - rails + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + shortlink: https://sg.run/eJNX + semgrep.dev: + rule: + r_id: 20732 + rv_id: 1263657 + rule_id: kxUOJ6 + version_id: GxTke14 + url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + origin: community +- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: | + $X.constantize + - pattern-inside: | + $X. ... .safe_constantize + - pattern-inside: | + const_get(...) + - pattern-inside: | + qualified_const_get(...) + message: Found user-controllable input to Ruby reflection functionality. This allows + a remote user to influence runtime behavior, up to and including arbitrary remote + code execution. Do not provide user-controllable input to reflection functionality. + Do not call symbol conversion on user-controllable input. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - ruby + - rails + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + shortlink: https://sg.run/vpEX + semgrep.dev: + rule: + r_id: 20733 + rv_id: 1263663 + rule_id: wdUkYA + version_id: 0bTKzn8 + url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + origin: community +- id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + mode: taint + pattern-sources: + - pattern-either: + - pattern: | + cookies[...] + - patterns: + - pattern: | + cookies. ... .$PROPERTY[...] + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: | + params[...] + - pattern: | + request.env[...] + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.find(...) + - pattern: $MODEL.find_by_id(...) + - pattern: $MODEL.find_by_id!(...) + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\S+' + message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord + model being searched against is sensitive, this may lead to Insecure Direct Object + Reference (IDOR) behavior and allow users to read arbitrary records. Scope the + find to the current user, e.g. `current_user.accounts.find(params[:id])`. + languages: + - ruby + severity: WARNING + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb + category: security + cwe: + - 'CWE-639: Authorization Bypass Through User-Controlled Key' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - ruby + - rails + references: + - https://brakemanscanner.org/docs/warning_types/unscoped_find/ + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + shortlink: https://sg.run/dPbP + semgrep.dev: + rule: + r_id: 20734 + rv_id: 1263664 + rule_id: x8Ud6d + version_id: K3TKkxZ + url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + origin: community +- id: ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + mode: search + patterns: + - pattern-either: + - pattern: | + validates ..., :format => <... $V ...>,... + - pattern: | + validates_format_of ..., :with => <... $V ...>,... + - metavariable-regex: + metavariable: $V + regex: /(.{2}(? ...`. Ruby regex behavior is multiline by default and + lines should be terminated by `\A` for beginning of line and `\Z` for end of line, + respectively. + languages: + - ruby + severity: ERROR + metadata: + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_validation_regex.rb + category: security + cwe: + - 'CWE-185: Incorrect Regular Expression' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + technology: + - ruby + - rails + references: + - https://brakemanscanner.org/docs/warning_types/format_validation/ + - https://github.com/presidentbeef/brakeman/blob/aef6253a8b7bcb97116f2af1ed2a561a6ae35bd5/test/apps/rails3/app/models/account.rb + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/account.rb + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + shortlink: https://sg.run/ZPo7 + semgrep.dev: + rule: + r_id: 20735 + rv_id: 1263665 + rule_id: OrUv1X + version_id: qkTR7DG + url: https://semgrep.dev/playground/r/qkTR7DG/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + origin: community +- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + message: 'Detected usage of ''http.FileServer'' as handler: this allows directory + listing and an attacker could navigate through directories looking for sensitive + files. Be sure to disable directory listing or restrict access to specific directories/files.' + severity: WARNING + languages: + - go + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $FS := http.FileServer(...) + ... + - pattern-either: + - pattern: | + http.ListenAndServe(..., $FS) + - pattern: | + http.ListenAndServeTLS(..., $FS) + - pattern: | + http.Handle(..., $FS) + - pattern: | + http.HandleFunc(..., $FS) + - patterns: + - pattern: | + http.$FN(..., http.FileServer(...)) + - metavariable-regex: + metavariable: $FN + regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc) + metadata: + category: security + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/OWASP/Go-SCP + - https://cwe.mitre.org/data/definitions/548.html + confidence: MEDIUM + technology: + - go + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + shortlink: https://sg.run/4R8x + semgrep.dev: + rule: + r_id: 21300 + rv_id: 1262944 + rule_id: 5rU9JO + version_id: QkTGqX0 + url: https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + origin: community +- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + message: Detected DynamoDB query params that are tainted by `$EVENT` object. This + could lead to NoSQL injection if the variable is user-controlled and not properly + sanitized. Explicitly assign query params instead of passing data from `$EVENT` + directly to DynamoDB client. + metadata: + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + owasp: + - A01:2017 - Injection + category: security + technology: + - javascript + - aws-lambda + - dynamodb + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + shortlink: https://sg.run/X1e4 + semgrep.dev: + rule: + r_id: 21320 + rv_id: 945766 + rule_id: 0oU1xk + version_id: GxTP7gN + url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: | + exports.handler = function ($EVENT, ...) { + ... + } + - pattern-inside: | + function $FUNC ($EVENT, ...) {...} + ... + exports.handler = $FUNC + - pattern-inside: | + $FUNC = function ($EVENT, ...) {...} + ... + exports.handler = $FUNC + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern: | + $DC.$METHOD($SINK, ...) + - metavariable-regex: + metavariable: $METHOD + regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) + - pattern-either: + - pattern-inside: | + $DC = new $AWS.DocumentClient(...); + ... + - pattern-inside: | + $DC = new $AWS.DynamoDB(...); + ... + - pattern-inside: | + $DC = new DynamoDBClient(...); + ... + - pattern-inside: | + $DC = DynamoDBDocumentClient.from(...); + ... + pattern-sanitizers: + - patterns: + - pattern: | + {...} +- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + mode: taint + metadata: + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + owasp: + - A01:2017 - Injection + category: security + technology: + - python + - boto3 + - aws-lambda + - dynamodb + references: + - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + shortlink: https://sg.run/jjrl + semgrep.dev: + rule: + r_id: 21321 + rv_id: 946088 + rule_id: KxUJ2B + version_id: 9lTy1rQ + url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + origin: community + message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This + could lead to NoSQL injection if the variable is user-controlled and not properly + sanitized. Explicitly assign query params instead of passing data from `$EVENT` + directly to DynamoDB client. + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sanitizers: + - patterns: + - pattern: | + {...} + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) + - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) + - pattern-either: + - patterns: + - pattern-inside: | + $TABLE = $DB.Table(...) + ... + - pattern-inside: | + $DB = boto3.resource('dynamodb', ...) + ... + - pattern-inside: | + $TABLE = boto3.client('dynamodb', ...) + ... + severity: ERROR + languages: + - python +- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + patterns: + - pattern: pyramid.authentication.$FUNC($...PARAMS) + - metavariable-pattern: + metavariable: $FUNC + pattern-either: + - pattern: AuthTktCookieHelper + - pattern: AuthTktAuthenticationPolicy + - pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...) + - pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...) + - focus-metavariable: $...PARAMS + fix: | + $...PARAMS, httponly=True + message: Found a Pyramid Authentication Ticket cookie without the httponly option + correctly set. Pyramid cookies should be handled securely by setting httponly=True. + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + shortlink: https://sg.run/EprB + semgrep.dev: + rule: + r_id: 21437 + rv_id: 1263557 + rule_id: bwUXKB + version_id: RGT0L7K + url: https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY, + ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY, + ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: | + False + fix: | + True + message: Found a Pyramid Authentication Ticket cookie without the httponly option + correctly set. Pyramid cookies should be handled securely by setting httponly=True. + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + shortlink: https://sg.run/7DgQ + semgrep.dev: + rule: + r_id: 21438 + rv_id: 1263558 + rule_id: NbUq9e + version_id: A8Tgd8N + url: https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + patterns: + - pattern-either: + - pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE, + ...) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE, + ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + fix: | + 'Lax' + message: Found a Pyramid Authentication Ticket without the samesite option correctly + set. Pyramid cookies should be handled securely by setting samesite='Lax'. If + this parameter is not properly set, your cookies are not properly protected and + are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + shortlink: https://sg.run/LYrY + semgrep.dev: + rule: + r_id: 21439 + rv_id: 1263559 + rule_id: kxUYjY + version_id: BjTkZ51 + url: https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, + ...) + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, + ...) + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...) + fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + message: Found a Pyramid Authentication Ticket cookie using an unsafe default for + the secure option. Pyramid cookies should be handled securely by setting secure=True. + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + shortlink: https://sg.run/8WxQ + semgrep.dev: + rule: + r_id: 21440 + rv_id: 1263560 + rule_id: wdUKzn + version_id: DkTRbJn + url: https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, + ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: | + False + fix: | + True + message: Found a Pyramid Authentication Ticket cookie without the secure option + correctly set. Pyramid cookies should be handled securely by setting secure=True. + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + shortlink: https://sg.run/gjp5 + semgrep.dev: + rule: + r_id: 21441 + rv_id: 1263561 + rule_id: x8UqAp + version_id: WrTqK93 + url: https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + patterns: + - pattern-inside: | + $CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...) + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + metavariable: $CHECK_ORIGIN + comparison: $CHECK_ORIGIN == False + message: Automatic check of the referrer for cross-site request forgery tokens has + been explicitly disabled globally, which might leave views unprotected when an + unsafe CSRF storage policy is used. Use 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)' + to turn the automatic check for all unsafe methods (per RFC2616). + languages: + - python + severity: ERROR + fix: | + True + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + shortlink: https://sg.run/3GeW + semgrep.dev: + rule: + r_id: 21443 + rv_id: 1263563 + rule_id: eqU9Le + version_id: K3TKkeo + url: https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + origin: community +- id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + message: Origin check for the CSRF token is disabled for this view. This might represent + a security risk if the CSRF storage policy is not known to be secure. + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + asvs: + section: V4 Access Control + control_id: 4.2.2 CSRF + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + version: '4' + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + shortlink: https://sg.run/4RB9 + semgrep.dev: + rule: + r_id: 21444 + rv_id: 1263564 + rule_id: v8UGpL + version_id: qkTR7Gv + url: https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern-inside: | + from pyramid.view import view_config + ... + @view_config(..., check_origin=$CHECK_ORIGIN, ...) + def $VIEW(...): + ... + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + metavariable: $CHECK_ORIGIN + comparison: $CHECK_ORIGIN == False + fix: | + True +- id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + fix-regex: + regex: (.*)\) + replacement: \1, httponly=True) + message: Found a Pyramid cookie using an unsafe default for the httponly option. + Pyramid cookies should be handled securely by setting httponly=True in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + shortlink: https://sg.run/P19v + semgrep.dev: + rule: + r_id: 21445 + rv_id: 1263565 + rule_id: d8UPQ7 + version_id: l4TJRbo + url: https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: | + False + fix: | + True + message: Found a Pyramid cookie without the httponly option correctly set. Pyramid + cookies should be handled securely by setting httponly=True in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/www-community/controls/SecureCookieAttribute + - https://owasp.org/www-community/HttpOnly + - https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute + category: security + technology: + - pyramid + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + shortlink: https://sg.run/JbqP + semgrep.dev: + rule: + r_id: 21446 + rv_id: 1263566 + rule_id: ZqU37W + version_id: YDTZe54 + url: https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + fix-regex: + regex: (.*)\) + replacement: \1, samesite='Lax') + message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid + cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + shortlink: https://sg.run/5AWj + semgrep.dev: + rule: + r_id: 21447 + rv_id: 1263567 + rule_id: nJUp80 + version_id: 6xT293z + url: https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + fix: | + 'Lax' + message: Found a Pyramid cookie without the samesite option correctly set. Pyramid + cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + shortlink: https://sg.run/GXR6 + semgrep.dev: + rule: + r_id: 21448 + rv_id: 1263568 + rule_id: EwUgpY + version_id: o5TbDv5 + url: https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid + cookies should be handled securely by setting secure=True in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + shortlink: https://sg.run/RbrN + semgrep.dev: + rule: + r_id: 21449 + rv_id: 1263569 + rule_id: 7KUr15 + version_id: zyTb2dX + url: https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + patterns: + - pattern-either: + - pattern-inside: | + @pyramid.view.view_config(...) + def $VIEW($REQUEST): + ... + $RESPONSE = $REQUEST.response + ... + - pattern-inside: | + def $VIEW(...): + ... + $RESPONSE = pyramid.httpexceptions.HTTPFound(...) + ... + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: | + False + fix: | + True + message: Found a Pyramid cookie without the secure option correctly set. Pyramid + cookies should be handled securely by setting secure=True in response.set_cookie(...). + If this parameter is not properly set, your cookies are not properly protected + and are at risk of being stolen by an attacker. + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + shortlink: https://sg.run/AzjB + semgrep.dev: + rule: + r_id: 21450 + rv_id: 1263570 + rule_id: L1UX2J + version_id: pZT03oJ + url: https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + origin: community + languages: + - python + severity: WARNING +- id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + patterns: + - pattern-inside: | + $CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...) + - pattern: $REQUIRE_CSRF + - metavariable-comparison: + metavariable: $REQUIRE_CSRF + comparison: $REQUIRE_CSRF == False + message: Automatic check of cross-site request forgery tokens has been explicitly + disabled globally, which might leave views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)' + to turn the automatic check for all unsafe methods (per RFC2616). + languages: + - python + severity: ERROR + fix: | + True + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + shortlink: https://sg.run/Bx2R + semgrep.dev: + rule: + r_id: 21451 + rv_id: 1263571 + rule_id: 8GUKqP + version_id: 2KTv2en + url: https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + origin: community +- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + message: Detected data rendered directly to the end user via 'Response'. This bypasses + Pyramid's built-in cross-site scripting (XSS) defenses and could result in an + XSS vulnerability. Use Pyramid's template engines to safely render HTML. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - pyramid + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + shortlink: https://sg.run/DX8G + semgrep.dev: + rule: + r_id: 21452 + rv_id: 1263572 + rule_id: gxUeA8 + version_id: X0TzyEe + url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + origin: community + languages: + - python + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + pyramid.request.Response.text($SINK) + - pattern: | + pyramid.request.Response($SINK) + - pattern: | + $REQ.response.body = $SINK + - pattern: | + $REQ.response.text = $SINK + - pattern: | + $REQ.response.ubody = $SINK + - pattern: | + $REQ.response.unicode_body = $SINK + - pattern: $SINK +- id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause + sql injections if the developer inputs raw SQL into the before-mentioned clauses. + This pattern captures relevant cases in which the developer inputs raw SQL into + the distinct, having, group_by, order_by or filter clauses and injects user-input + into the raw SQL with any function besides "bindparams". Use bindParams to securely + bind user-input to SQL statements. + languages: + - python + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data + technology: + - pyramid + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + shortlink: https://sg.run/W7eE + semgrep.dev: + rule: + r_id: 21453 + rv_id: 1263573 + rule_id: QrUZ7l + version_id: jQTn5WA + url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + from pyramid.view import view_config + ... + @view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-inside: | + $QUERY = $REQ.dbsession.query(...) + ... + - pattern-either: + - pattern: | + $QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: | + $QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) + - pattern: $SINK + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + fix-regex: + regex: format + replacement: bindparams +- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + message: Use of angular.element can lead to XSS if user-input is treated as part + of the HTML element within `$SINK`. It is recommended to contextually output encode + user-input, before inserting into `$SINK`. If the HTML needs to be preserved it + is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + confidence: MEDIUM + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + category: security + technology: + - angularjs + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + shortlink: https://sg.run/5AQ0 + semgrep.dev: + rule: + r_id: 21503 + rv_id: 1263091 + rule_id: GdUP71 + version_id: 44TEj8L + url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: window.location.search + - pattern: window.document.location.search + - pattern: document.location.search + - pattern: location.search + - pattern: $location.search(...) + - patterns: + - pattern-either: + - pattern: $DECODE(<... location.hash ...>) + - pattern: $DECODE(<... window.location.hash ...>) + - pattern: $DECODE(<... document.location.hash ...>) + - pattern: $DECODE(<... location.href ...>) + - pattern: $DECODE(<... window.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.URL ...>) + - pattern: $DECODE(<... window.document.URL ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... $location.absUrl() ...>) + - pattern: $DECODE(<... $location.url() ...>) + - pattern: $DECODE(<... $location.hash() ...>) + - metavariable-regex: + metavariable: $DECODE + regex: ^(unescape|decodeURI|decodeURIComponent)$ + - patterns: + - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|delete|head|jsonp|post|put|patch) + - pattern: $RES.data + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + angular.element(...). ... .$SINK($QUERY) + - pattern-inside: | + $ANGULAR = angular.element(...) + ... + $ANGULAR. ... .$SINK($QUERY) + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) +- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + mode: taint + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context): + ... + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: pickle.load($SINK,...) + - pattern: pickle.loads($SINK,...) + - pattern: _pickle.load($SINK,...) + - pattern: _pickle.loads($SINK,...) + - pattern: cPickle.load($SINK,...) + - pattern: cPickle.loads($SINK,...) + - pattern: dill.load($SINK,...) + - pattern: dill.loads($SINK,...) + - pattern: shelve.open($SINK,...) + message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. + When unpickling, the serialized data could be manipulated to run arbitrary code. + Instead, consider serializing the relevant data as JSON or a similar text-based + serialization format. + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://docs.python.org/3/library/pickle.html + - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ + category: security + technology: + - python + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + shortlink: https://sg.run/JbjW + semgrep.dev: + rule: + r_id: 21602 + rv_id: 1263345 + rule_id: JDUDQg + version_id: LjTkgd9 + url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + origin: community + languages: + - python + severity: WARNING +- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + mode: taint + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: | + Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...}) + pattern-sanitizers: + - patterns: + - pattern: | + DB::raw("...",[...]) + pattern-sinks: + - patterns: + - pattern: | + DB::raw(...) + message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL + injection via string concatenation or unsafe interpolation. + languages: + - php + severity: WARNING + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md + technology: + - php + - laravel + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + shortlink: https://sg.run/x94g + semgrep.dev: + rule: + r_id: 21674 + rv_id: 1263305 + rule_id: zdUln0 + version_id: qkTR7A9 + url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + origin: community +- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + mode: taint + pattern-sources: + - patterns: + - pattern: | + public function $F(...,Request $R,...){...} + - focus-metavariable: $R + - patterns: + - pattern-either: + - pattern: | + $this->$PROPERTY + - pattern: | + $this->$PROPERTY->$GET + - metavariable-pattern: + metavariable: $PROPERTY + patterns: + - pattern-either: + - pattern: query + - pattern: request + - pattern: headers + - pattern: cookies + - pattern: cookie + - pattern: files + - pattern: file + - pattern: allFiles + - pattern: input + - pattern: all + - pattern: post + - pattern: json + - pattern-either: + - pattern-inside: | + class $CL extends Illuminate\Http\Request {...} + - pattern-inside: | + class $CL extends Illuminate\Foundation\Http\FormRequest {...} + pattern-sinks: + - patterns: + - pattern: | + Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...) + - focus-metavariable: $IGNORE + message: Found a request argument passed to an `ignore()` definition in a Rule constraint. + This can lead to SQL injection. + languages: + - php + severity: ERROR + metadata: + category: security + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - php + - laravel + references: + - https://laravel.com/docs/9.x/validation#rule-unique + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + shortlink: https://sg.run/vkeb + semgrep.dev: + rule: + r_id: 21677 + rv_id: 1263314 + rule_id: X5ULgE + version_id: DkTRbBl + url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + origin: community +- id: java.spring.security.injection.tainted-file-path.tainted-file-path + languages: + - java + severity: ERROR + message: Detected user input controlling a file path. An attacker could control + the location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + options: + interfile: true + metadata: + cwe: + - 'CWE-23: Relative Path Traversal' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + category: security + technology: + - java + - spring + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path + shortlink: https://sg.run/x9o0 + semgrep.dev: + rule: + r_id: 22074 + rv_id: 1263084 + rule_id: lBUxok + version_id: ExTEx6Y + url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new File(...) + - pattern: new java.io.File(...) + - pattern: new FileReader(...) + - pattern: new java.io.FileReader(...) + - pattern: new FileInputStream(...) + - pattern: new java.io.FileInputStream(...) + - pattern: (Paths $PATHS).get(...) + - patterns: + - pattern: | + $CLASS.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(getResourceAsStream|getResource)$ + - patterns: + - pattern-either: + - pattern: new ClassPathResource($FILE, ...) + - pattern: ResourceUtils.getFile($FILE, ...) + - pattern: new FileOutputStream($FILE, ...) + - pattern: new java.io.FileOutputStream($FILE, ...) + - pattern: new StreamSource($FILE, ...) + - pattern: new javax.xml.transform.StreamSource($FILE, ...) + - pattern: FileUtils.openOutputStream($FILE, ...) + - focus-metavariable: $FILE + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) +- id: java.spring.security.injection.tainted-html-string.tainted-html-string + languages: + - java + severity: ERROR + message: Detected user input flowing into a manually constructed HTML string. You + may be accidentally bypassing secure methods of rendering HTML by manually constructing + HTML and this could create a cross-site scripting vulnerability, which could let + attackers steal sensitive user data. To be sure this is safe, check that the HTML + is rendered safely. You can use the OWASP ESAPI encoder if you must render user + data. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string + shortlink: https://sg.run/ObdR + semgrep.dev: + rule: + r_id: 22075 + rv_id: 1409395 + rule_id: YGUvkL + version_id: 3ZT2598 + url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string + origin: community + mode: taint + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + - label: CONCAT + by-side-effect: true + requires: INPUT + patterns: + - pattern-either: + - pattern: | + "$HTMLSTR" + ... + - pattern: | + "$HTMLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$HTMLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$HTMLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$HTMLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$HTMLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $HTMLSTR + regex: ^<\w+ + pattern-propagators: + - pattern: (StringBuilder $SB).append($...TAINTED) + from: $...TAINTED + to: $SB + - pattern: $VAR += $...TAINTED + from: $...TAINTED + to: $VAR + pattern-sinks: + - requires: CONCAT + patterns: + - pattern-either: + - pattern: new ResponseEntity<>($PAYLOAD, ...) + - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) + - pattern: ResponseEntity. ... .body($PAYLOAD) + - patterns: + - pattern: | + ResponseEntity.$RESPFUNC($PAYLOAD). ... + - metavariable-regex: + metavariable: $RESPFUNC + regex: ^(ok|of)$ + - focus-metavariable: $PAYLOAD + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) +- id: java.spring.security.injection.tainted-system-command.tainted-system-command + languages: + - java + severity: ERROR + mode: taint + pattern-propagators: + - pattern: (StringBuilder $STRB).append($INPUT) + from: $INPUT + to: $STRB + label: CONCAT + requires: INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $SOURCE + - pattern: $SOURCE + $Y + - pattern: String.format("...", ..., $SOURCE, ...) + - pattern: String.join("...", ..., $SOURCE, ...) + - pattern: (String $STR).concat($SOURCE) + - pattern: $SOURCE.concat(...) + - pattern: $X += $SOURCE + - pattern: $SOURCE += $X + label: CONCAT + requires: INPUT + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (Process $P) = new Process(...); + - pattern: | + (ProcessBuilder $PB).command(...); + - patterns: + - pattern-either: + - pattern: | + (Runtime $R).$EXEC(...); + - pattern: | + Runtime.getRuntime(...).$EXEC(...); + - metavariable-regex: + metavariable: $EXEC + regex: (exec|loadLibrary|load) + - patterns: + - pattern: | + (ProcessBuilder $PB).command(...).$ADD(...); + - metavariable-regex: + metavariable: $ADD + regex: (add|addAll) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: | + $BUILDER = new ProcessBuilder(...); + ... + - pattern: $BUILDER.start(...) + - pattern: | + new ProcessBuilder(...). ... .start(...); + requires: CONCAT + message: 'Detected user input entering a method which executes a system command. + This could result in a command injection vulnerability, which allows an attacker + to inject an arbitrary system command onto the server. The attacker could download + malware onto or steal data from the server. Instead, use ProcessBuilder, separating + the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", + targetDirectory)`. Further, make sure you hardcode or allowlist the actual command + so that attackers can''t run arbitrary commands.' + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - java + - spring + confidence: HIGH + references: + - https://www.stackhawk.com/blog/command-injection-java/ + - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html + - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command + shortlink: https://sg.run/epY0 + semgrep.dev: + rule: + r_id: 22076 + rv_id: 1263087 + rule_id: 6JUxGN + version_id: 8KT5rnP + url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command + origin: community +- id: java.spring.security.injection.tainted-url-host.tainted-url-host + languages: + - java + severity: ERROR + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode + the correct host, or ensure that the user data can only affect the path or parameters. + options: + interfile: true + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - java + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/vkYn + semgrep.dev: + rule: + r_id: 22077 + rv_id: 1263088 + rule_id: oqUZo8 + version_id: gETB708 + url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + pattern-sinks: + - pattern-either: + - pattern: new URL($ONEARG) + - patterns: + - pattern-either: + - pattern: | + "$URLSTR" + ... + - pattern: | + "$URLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$URLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$URLSTR"; + ... + - pattern: $VAR += ... + - patterns: + - pattern: String.format("$URLSTR", ...) + - pattern-not: String.format("$URLSTR", "...", ...) + - patterns: + - pattern-inside: | + String $VAR = "$URLSTR"; + ... + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: http(s?)://%(v|s|q).* +- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + mode: taint + languages: + - ruby + message: Deserialization of a string tainted by `event` object found. Objects in + Ruby can be serialized into strings, then later loaded from strings. However, + uses of `load` can cause remote code execution. Loading user input with MARSHAL, + YAML or CSV can potentially be dangerous. If you need to deserialize untrusted + data, you should use JSON as it is only capable of returning 'primitive' types + such as strings, arrays, hashes, numbers and nil. + metadata: + references: + - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + category: security + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + technology: + - ruby + - aws-lambda + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + shortlink: https://sg.run/dplX + semgrep.dev: + rule: + r_id: 22078 + rv_id: 1263585 + rule_id: zdUlNJ + version_id: vdT06gR + url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + origin: community + pattern-sinks: + - patterns: + - pattern: $SINK + - pattern-either: + - pattern-inside: | + YAML.load($SINK,...) + - pattern-inside: | + CSV.load($SINK,...) + - pattern-inside: | + Marshal.load($SINK,...) + - pattern-inside: | + Marshal.restore($SINK,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: | + def $HANDLER(event, context) + ... + end + severity: WARNING +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + message: The libxml library processes user-input with the `noent` attribute is set + to `true` which can lead to being vulnerable to XML External Entities (XXE) type + attacks. It is recommended to set `noent` to `false` when using this feature to + ensure you are protected. + options: + interfile: true + metadata: + interfile: true + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + shortlink: https://sg.run/Z75x + semgrep.dev: + rule: + r_id: 22079 + rv_id: 1263138 + rule_id: pKUNeD + version_id: d6TyxpX + url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $XML = require('$IMPORT') + ... + - pattern-inside: | + import $XML from '$IMPORT' + ... + - pattern-inside: | + import * as $XML from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-open-redirect.express-open-redirect + message: The application redirects to a URL specified by user-supplied input `$REQ` + that is not validated. This could redirect users to malicious locations. Consider + using an allow-list approach to validate URLs, or warn users they are being redirected + to a third-party website. + metadata: + technology: + - express + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + category: security + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect + shortlink: https://sg.run/EpoP + semgrep.dev: + rule: + r_id: 22081 + rv_id: 1263140 + rule_id: X5ULkq + version_id: nWT2L0v + url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect + origin: community + languages: + - javascript + - typescript + severity: WARNING + options: + taint_unify_mvars: true + symbolic_propagation: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $HTTP + regex: ^https?:\/\/$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ. ... .$VALUE) + - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ.$VALUE['...']) + - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) + - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) + - pattern: $REQ.$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ.$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" + - pattern-either: + - pattern: $RES.redirect($ASSIGN) + - pattern: $RES.redirect($ASSIGN + $...FOO) + - pattern: $RES.redirect(`${$ASSIGN}...`) + - focus-metavariable: $ASSIGN +- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile + message: The application processes user-input, this is passed to res.sendFile which + can allow an attacker to arbitrarily read files on the system through path traversal. + It is recommended to perform input validation in addition to canonicalizing the + path. This allows you to validate the path against the intended directory it should + be accessing. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html + technology: + - express + category: security + cwe: + - 'CWE-73: External Control of File Name or Path' + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + shortlink: https://sg.run/7DJk + semgrep.dev: + rule: + r_id: 22082 + rv_id: 1263142 + rule_id: j2UzDx + version_id: 7ZTE3X9 + url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + function ... (...,$REQ: $TYPE, ...) {...} + - metavariable-regex: + metavariable: $TYPE + regex: ^(string|String) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.$METH($QUERY,...) + - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) + - metavariable-regex: + metavariable: $METH + regex: ^(sendfile|sendFile)$ + - focus-metavariable: $QUERY +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - express + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + shortlink: https://sg.run/LYvG + semgrep.dev: + rule: + r_id: 22083 + rv_id: 1263143 + rule_id: 10Uo39 + version_id: LjTkgle + url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: | + $SESSION = require('express-session'); + ... + - pattern-inside: | + import $SESSION from 'express-session' + ... + - pattern-inside: | + import {..., $SESSION, ...} from 'express-session' + ... + - pattern-inside: | + import * as $SESSION from 'express-session' + ... + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: | + $SECRET = $VALUE + ... + $APP.use($SESSION($SECRET)) + - pattern: | + secret: '$Y' +- id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + message: The following function call $SER.$FUNC accepts user controlled data which + can result in Remote Code Execution (RCE) through Object Deserialization. It is + recommended to use secure data processing alternatives such as JSON.parse() and + Buffer.from(). + options: + interfile: true + metadata: + interfile: true + technology: + - express + category: security + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + shortlink: https://sg.run/8W5j + semgrep.dev: + rule: + r_id: 22084 + rv_id: 1263145 + rule_id: 9AUyqj + version_id: gETB7nD + url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + $SER = require('$IMPORT') + ... + - pattern-inside: | + import $SER from '$IMPORT' + ... + - pattern-inside: | + import * as $SER from '$IMPORT' + ... + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + message: Detected a sequelize statement that is tainted by user-input. This could + lead to SQL injection if the variable is user-controlled and is not properly sanitized. + In order to prevent SQL injection, it is recommended to use parameterized queries + or prepared statements. + options: + interfile: true + metadata: + interfile: true + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + category: security + technology: + - express + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + shortlink: https://sg.run/gjoe + semgrep.dev: + rule: + r_id: 22085 + rv_id: 1263241 + rule_id: yyU0GX + version_id: nWT2Llx + url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => + {...} + - pattern-inside: | + ({ $REQ }: Request,$RES: Response) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) +- id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + message: Directory listing/indexing is enabled, which may lead to disclosure of + sensitive directories and files. It is recommended to disable directory listing + unless it is a public resource. If you need directory listing, ensure that sensitive + files are inaccessible when querying the resource. + options: + interfile: true + metadata: + interfile: true + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + category: security + technology: + - express + references: + - https://www.npmjs.com/package/serve-index + - https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/ + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + shortlink: https://sg.run/DX2G + semgrep.dev: + rule: + r_id: 22552 + rv_id: 1263129 + rule_id: x8UqEb + version_id: rxTAKGb + url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $APP.use(require('serve-index')(...)) + - patterns: + - pattern-either: + - pattern-inside: | + $SERVEINDEX = require('serve-index') + ... + - pattern-inside: | + import $SERVEINDEX from 'serve-index' + ... + - pattern-inside: | + import * as $SERVEINDEX from 'serve-index' + ... + - pattern-either: + - patterns: + - pattern-inside: | + $VALUE = $SERVEINDEX(...) + ... + - pattern: | + $VALUE(...) + - pattern: | + $APP.use(..., $SERVEINDEX(...), ...) +- id: javascript.express.security.audit.express-ssrf.express-ssrf + message: 'The following request $REQUEST.$METHOD() was found to be crafted from + user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities. + It is recommended where possible to not allow user-input to craft the base request, + but to be treated as part of the path or query parameter. When user-input is necessary + to craft the request, it is recommeneded to follow OWASP best practices to prevent + abuse. ' + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + technology: + - express + category: security + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf + shortlink: https://sg.run/0PNw + semgrep.dev: + rule: + r_id: 22554 + rv_id: 1263144 + rule_id: eqU9l2 + version_id: 8KT5rBr + url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + options: + taint_unify_mvars: true + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, ...) {...} + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: | + ({ $REQ }: Request,...) => + {...} + - pattern-inside: | + ({ $REQ }: $EXPRESS.Request,...) => {...} + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) + - pattern: $REQ. ... .$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) + - pattern: $REQ.$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: | + $REQUEST = require('request') + ... + - pattern-inside: | + import * as $REQUEST from 'request' + ... + - pattern-inside: | + import $REQUEST from 'request' + ... + - pattern-either: + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE['...'] + ... + - pattern-inside: | + $ASSIGN = $REQ. ... .$VALUE + $...A + ... + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" + - pattern-inside: | + $ASSIGN = `${$REQ. ... .$VALUE}...` + ... + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" + - patterns: + - pattern-either: + - pattern-inside: | + $ASSIGN = "$HTTP"+ $REQ. ... .$VALUE + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + ... + - pattern-inside: | + $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A + ... + - pattern-inside: | + $ASSIGN = `$HTTP${$REQ.$VALUE[...]}...` + ... + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQUEST.$METHOD($ASSIGN,...) + - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) + - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) + - patterns: + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) + - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern: $ASSIGN + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ +- id: terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + message: Ensure that App service enables detailed error messages + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + logs { + ... + detailed_error_messages_enabled = true + ... + } + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + metadata: + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + shortlink: https://sg.run/pA1g + semgrep.dev: + rule: + r_id: 23962 + rv_id: 1263762 + rule_id: bwU1Eg + version_id: DkTRbr5 + url: https://semgrep.dev/playground/r/DkTRbr5/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + message: Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service + Slot + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + https_only = true + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + shortlink: https://sg.run/1g9w + semgrep.dev: + rule: + r_id: 23966 + rv_id: 1263766 + rule_id: x8UZRP + version_id: qkTR78q + url: https://semgrep.dev/playground/r/qkTR78q/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + message: Ensure web app is using the latest version of TLS encryption + patterns: + - pattern-either: + - pattern: | + "1.0" + - pattern: | + "1.1" + - pattern-inside: min_tls_version = ... + - pattern-inside: | + $RESOURCE "azurerm_app_service" "..." { + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + shortlink: https://sg.run/rDwn + semgrep.dev: + rule: + r_id: 23969 + rv_id: 1263769 + rule_id: v8UNL7 + version_id: 6xT29gv + url: https://semgrep.dev/playground/r/6xT29gv/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + message: Ensure that the expiration date is set on all keys + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_key_vault_key" "..." { + ... + expiration_date = "..." + ... + } + - pattern-inside: | + resource "azurerm_key_vault_key" "..." { + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + shortlink: https://sg.run/J1vw + semgrep.dev: + rule: + r_id: 23990 + rv_id: 946834 + rule_id: 0oUlgp + version_id: pZTNGkl + url: https://semgrep.dev/playground/r/pZTNGkl/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + message: Ensure MSSQL is using the latest version of TLS encryption + patterns: + - pattern-either: + - pattern: | + "1.0" + - pattern: | + "1.1" + - pattern-inside: minimum_tls_version = ... + - pattern-inside: | + $RESOURCE "azurerm_mssql_server" "..." { + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + shortlink: https://sg.run/B1lW + semgrep.dev: + rule: + r_id: 23995 + rv_id: 1263784 + rule_id: 6JUJG8 + version_id: xyTjzeR + url: https://semgrep.dev/playground/r/xyTjzeR/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + message: Ensure that MySQL server enables infrastructure encryption + patterns: + - pattern: resource + - pattern-inside: | + resource "azurerm_mysql_server" "..." { + ... + } + - pattern-not-inside: | + resource "azurerm_mysql_server" "..." { + ... + infrastructure_encryption_enabled = true + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + shortlink: https://sg.run/Dd6Y + semgrep.dev: + rule: + r_id: 23996 + rv_id: 946840 + rule_id: oqUloL + version_id: yeT0vBn + url: https://semgrep.dev/playground/r/yeT0vBn/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + message: Ensure MySQL is using the latest version of TLS encryption + patterns: + - pattern-either: + - pattern: | + "TLS1_0" + - pattern: | + "TLS1_1" + - pattern-inside: ssl_minimal_tls_version_enforced = ... + - pattern-inside: | + $RESOURCE "azurerm_mysql_server" "..." { + ... + } + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + shortlink: https://sg.run/WR44 + semgrep.dev: + rule: + r_id: 23997 + rv_id: 1263785 + rule_id: zdU8NN + version_id: O9TpxWE + url: https://semgrep.dev/playground/r/O9TpxWE/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + origin: community + languages: + - hcl + severity: WARNING +- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + message: Detected usage of dangerous method $METHOD which does not escape inputs + (see link in references). If the argument is user-controlled, this can lead to + SQL injection. When using $METHOD function, do not trust user-submitted data and + only allow approved list of input (possibly, use an allowlist approach). + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + ($REQUEST : http.Request).$ANYTHING + - pattern: | + ($REQUEST : *http.Request).$ANYTHING + - metavariable-regex: + metavariable: $ANYTHING + regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + pattern-sinks: + - patterns: + - pattern-inside: | + import ("gorm.io/gorm") + ... + - patterns: + - pattern-inside: | + func $VAL(..., $GORM *gorm.DB,... ) { + ... + } + - pattern-either: + - pattern: | + $GORM. ... .$METHOD($VALUE) + - pattern: | + $DB := $GORM. ... .$ANYTHING(...) + ... + $DB. ... .$METHOD($VALUE) + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: | + ($X: bool) + options: + interfile: true + metadata: + category: security + technology: + - gorm + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://gorm.io/docs/security.html#SQL-injection-Methods + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + shortlink: https://sg.run/R4qg + semgrep.dev: + rule: + r_id: 24693 + rv_id: 1262915 + rule_id: AbU5o3 + version_id: l4TJRJK + url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + origin: community +- id: yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + patterns: + - pattern-either: + - pattern: | + spec: + ... + securityContext: + ... + runAsNonRoot: $VALUE + - patterns: + - pattern-inside: | + containers: + ... + - pattern: | + image: ... + ... + securityContext: + ... + runAsNonRoot: $VALUE + - metavariable-pattern: + metavariable: $VALUE + pattern: | + false + - focus-metavariable: $VALUE + fix: | + true + message: When running containers in Kubernetes, it's important to ensure that they are + properly secured to prevent privilege escalation attacks. One potential vulnerability + is when a container is allowed to run applications as the root user, which could + allow an attacker to gain access to sensitive resources. To mitigate this risk, + it's recommended to add a `securityContext` to the container, with the parameter + `runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root + user, limiting the damage that could be caused by any potential attacks. By adding + a `securityContext` to the container in your Kubernetes pod, you can help to + ensure that your containerized applications are more secure and less vulnerable + to privilege escalation attacks. + metadata: + references: + - https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/ + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - kubernetes + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + shortlink: https://sg.run/D9No + semgrep.dev: + rule: + r_id: 26096 + rv_id: 1263939 + rule_id: L1UAxy + version_id: NdTzyj8 + url: https://semgrep.dev/playground/r/NdTzyj8/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + origin: community + languages: + - yaml + severity: INFO +- id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + message: Anonymous access shouldn't be allowed unless explicit by design. Access + control checks are missing and potentially can be bypassed. This finding violates + the principle of least privilege or deny by default, where access should only + be permitted for a specific set of roles or conforms to a custom policy or users. + severity: INFO + metadata: + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-862: Missing Authorization' + cwe2021-top25: true + cwe2022-top25: true + cwe2023-top25: true + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://cwe.mitre.org/data/definitions/862.html + - https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0 + subcategory: + - vuln + technology: + - .net + - mvc + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + shortlink: https://sg.run/Z8GA + semgrep.dev: + rule: + r_id: 26335 + rv_id: 1262615 + rule_id: eqU32Y + version_id: o5TbD41 + url: https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + origin: community + languages: + - csharp + patterns: + - pattern: | + public class $CLASS : Controller { + ... + } + - pattern-inside: | + using Microsoft.AspNetCore.Mvc; + ... + - pattern-not: | + [AllowAnonymous] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize(Roles = ...)] + public class $CLASS : Controller { + ... + } + - pattern-not: | + [Authorize(Policy = ...)] + public class $CLASS : Controller { + ... + } +- id: csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + message: An open directory listing is potentially exposed, potentially revealing + sensitive information to attackers. + severity: INFO + metadata: + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cwe.mitre.org/data/definitions/548.html + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ + - https://docs.microsoft.com/en-us/aspnet/core/fundamentals/static-files?view=aspnetcore-7.0#directory-browsing + subcategory: + - vuln + technology: + - .net + - mvc + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + shortlink: https://sg.run/n0y1 + semgrep.dev: + rule: + r_id: 26336 + rv_id: 1262616 + rule_id: v8U8Ab + version_id: zyTb2Y2 + url: https://semgrep.dev/playground/r/zyTb2Y2/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + origin: community + languages: + - csharp + patterns: + - pattern-either: + - pattern: (IApplicationBuilder $APP).UseDirectoryBrowser(...); + - pattern: $BUILDER.Services.AddDirectoryBrowser(...); + - pattern-inside: | + public void Configure(...) { + ... + } +- id: csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + patterns: + - pattern: RequireSignedTokens = false + - pattern-inside: | + new TokenValidationParameters { + ... + } + fix: RequireSignedTokens = true + message: Accepting unsigned security tokens as valid security tokens allows an attacker + to remove its signature and potentially forge an identity. As a fix, set RequireSignedTokens + to be true. + metadata: + category: security + technology: + - csharp + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-347: Improper Verification of Cryptographic Signature' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + - https://cwe.mitre.org/data/definitions/347 + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + shortlink: https://sg.run/pqzN + semgrep.dev: + rule: + r_id: 26718 + rv_id: 1262631 + rule_id: KxUGLw + version_id: e1Tyjrz + url: https://semgrep.dev/playground/r/e1Tyjrz/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + origin: community + languages: + - csharp + severity: ERROR +- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + patterns: + - pattern: $APP.UseDeveloperExceptionPage(...); + - pattern-not-inside: | + if ($ENV.IsDevelopment(...)) { + ... + } + - pattern-not-inside: | + if ($ENV.EnvironmentName == "Development") { + ... + } + message: Stacktrace information is displayed in a non-Development environment. Accidentally + disclosing sensitive stack trace information in a production environment aids + an attacker in reconnaissance and information gathering. + metadata: + category: security + technology: + - csharp + owasp: + - A06:2017 - Security Misconfiguration + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-209: Generation of Error Message Containing Sensitive Information' + references: + - https://cwe.mitre.org/data/definitions/209.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + shortlink: https://sg.run/XvkA + semgrep.dev: + rule: + r_id: 26720 + rv_id: 1262653 + rule_id: lBU6Dv + version_id: 0bTKzrB + url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + origin: community + languages: + - csharp + severity: WARNING +- id: csharp.dotnet.security.audit.mass-assignment.mass-assignment + message: Mass assignment or Autobinding vulnerability in code allows an attacker + to execute over-posting attacks, which could create a new parameter in the binding + request and manipulate the underlying object in the application. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object + Attributes' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/915.html + - https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mass Assignment + source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment + shortlink: https://sg.run/7B3e + semgrep.dev: + rule: + r_id: 26838 + rv_id: 1262613 + rule_id: x8Up5B + version_id: YDTZeD9 + url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + public IActionResult $METHOD(..., $TYPE $ARG, ...){ + ... + } + - pattern: | + public ActionResult $METHOD(..., $TYPE $ARG, ...){ + ... + } + - pattern-inside: | + using Microsoft.AspNetCore.Mvc; + ... + - pattern-not: | + public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ + ... + } + - pattern-not: | + public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ + ... + } + - focus-metavariable: $ARG + pattern-sinks: + - pattern: View(...) +- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - pattern-either: + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...) + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...) + - pattern: $LOOP.subprocess_exec(...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", "...", ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c",...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", "...", ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", + "-c", ...], ...) + message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled + data. You may consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + shortlink: https://sg.run/Apjp + semgrep.dev: + rule: + r_id: 27250 + rv_id: 1263460 + rule_id: 7KUE1E + version_id: WrTqKXz + url: https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern-inside: asyncio.create_subprocess_shell($CMD, ...) + - focus-metavariable: $CMD + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...") + - pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...) + - pattern-not: asyncio.create_subprocess_shell("...", ...) + message: Detected asyncio subprocess function with user controlled data. You may + consider using 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + shortlink: https://sg.run/Dx8Y + semgrep.dev: + rule: + r_id: 27252 + rv_id: 1263462 + rule_id: 8GU5q3 + version_id: K3TKkDn + url: https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $X = code.InteractiveConsole(...) + ... + - pattern-inside: | + $X = code.InteractiveInterpreter(...) + ... + - pattern-either: + - pattern-inside: | + $X.push($PAYLOAD,...) + - pattern-inside: | + $X.runsource($PAYLOAD,...) + - pattern-inside: | + $X.runcode(code.compile_command($PAYLOAD),...) + - pattern-inside: | + $PL = code.compile_command($PAYLOAD,...) + ... + $X.runcode($PL,...) + - pattern: $PAYLOAD + - pattern-not: | + $X.push("...",...) + - pattern-not: | + $X.runsource("...",...) + - pattern-not: | + $X.runcode(code.compile_command("..."),...) + - pattern-not: | + $PL = code.compile_command("...",...) + ... + $X.runcode($PL,...) + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter + method. This is dangerous if external data can reach this function call because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + shortlink: https://sg.run/0Bgv + semgrep.dev: + rule: + r_id: 27254 + rv_id: 1263464 + rule_id: QrUG72 + version_id: l4TJRK9 + url: https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + confidence: MEDIUM + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + shortlink: https://sg.run/qL6z + semgrep.dev: + rule: + r_id: 27256 + rv_id: 1263466 + rule_id: 4bUEAY + version_id: 6xT29l6 + url: https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + shortlink: https://sg.run/Y3Ke + semgrep.dev: + rule: + r_id: 27258 + rv_id: 1263468 + rule_id: JDUz34 + version_id: zyTb2wn + url: https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-inside: | + _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) + - pattern-not: | + _xxsubinterpreters.run_string($ID, "...", ...) + - pattern: $PAYLOAD + message: Found user controlled content in `run_string`. This is dangerous because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + shortlink: https://sg.run/oLl9 + semgrep.dev: + rule: + r_id: 27260 + rv_id: 1409404 + rule_id: GdUkxO + version_id: DkTwBzO + url: https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - pattern: shlex.quote(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], + ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), + ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + message: Detected subprocess function '$FUNC' with user controlled data. A malicious + actor could leverage this to perform command injection. You may consider using + 'shlex.quote()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + shortlink: https://sg.run/pLGg + semgrep.dev: + rule: + r_id: 27262 + rv_id: 1263472 + rule_id: AbUgrZ + version_id: jQTn54Y + url: https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: | + $X = __import__("os") + ... + $X.system(...) + - pattern: | + $X = __import__("os") + ... + getattr($X, "system")(...) + - pattern: | + $X = getattr(os, "system") + ... + $X(...) + - pattern: | + $X = __import__("os") + ... + $Y = getattr($X, "system") + ... + $Y(...) + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + message: Found user-controlled data used in a system call. This could allow a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + shortlink: https://sg.run/XR2K + semgrep.dev: + rule: + r_id: 27264 + rv_id: 1263474 + rule_id: DbUR9g + version_id: 9lT4bG4 + url: https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + _testcapi.run_in_subinterp($PAYLOAD, ...) + - pattern-inside: | + test.support.run_in_subinterp($PAYLOAD, ...) + - pattern: $PAYLOAD + - pattern-not: | + _testcapi.run_in_subinterp("...", ...) + - pattern-not: | + test.support.run_in_subinterp("...", ...) + message: Found user controlled content in `run_in_subinterp`. This is dangerous + because it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + shortlink: https://sg.run/1DLw + semgrep.dev: + rule: + r_id: 27266 + rv_id: 1263476 + rule_id: 0oUK7N + version_id: rxTAKpn + url: https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $X = code.InteractiveConsole(...) + ... + - pattern-inside: | + $X = code.InteractiveInterpreter(...) + ... + - pattern-either: + - pattern: | + $X.push($PAYLOAD,...) + - pattern: | + $X.runsource($PAYLOAD,...) + - pattern: | + $X.runcode(code.compile_command($PAYLOAD),...) + - pattern: | + $PL = code.compile_command($PAYLOAD,...) + ... + $X.runcode($PL,...) + - focus-metavariable: $PAYLOAD + - pattern-not: | + $X.push("...",...) + - pattern-not: | + $X.runsource("...",...) + - pattern-not: | + $X.runcode(code.compile_command("..."),...) + - pattern-not: | + $PL = code.compile_command("...",...) + ... + $X.runcode($PL,...) + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter + method. This is dangerous if external data can reach this function call because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + shortlink: https://sg.run/9pRY + semgrep.dev: + rule: + r_id: 27267 + rv_id: 1263521 + rule_id: KxUKzx + version_id: l4TJRgo + url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.dangerous-os-exec.dangerous-os-exec + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + confidence: MEDIUM + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec + shortlink: https://sg.run/yL9x + semgrep.dev: + rule: + r_id: 27268 + rv_id: 1263523 + rule_id: qNUR13 + version_id: 6xT29rz + url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - pattern: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + - patterns: + - pattern-either: + - pattern: os.environ['$ANYTHING'] + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb['$ANYTHING'] + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv[...] + - pattern: sys.orig_argv[...] + - patterns: + - pattern-inside: | + $PARSER = argparse.ArgumentParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: | + $PARSER = optparse.OptionParser(...) + ... + - pattern-inside: | + $ARGS = $PARSER.parse_args() + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: | + $OPTS, $ARGS = getopt.getopt(...) + ... + - pattern-inside: | + $OPTS, $ARGS = getopt.gnu_getopt(...) + ... + - pattern-either: + - patterns: + - pattern-inside: | + for $O, $A in $OPTS: + ... + - pattern: $A + - pattern: $ARGS + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + message: Found user controlled content when spawning a process. This is dangerous + because it allows a malicious actor to execute commands. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + shortlink: https://sg.run/r8Zn + semgrep.dev: + rule: + r_id: 27269 + rv_id: 1263524 + rule_id: lBUJrn + version_id: o5TbDO5 + url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern: | + _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) + - pattern-not: | + _xxsubinterpreters.run_string($ID, "...", ...) + - focus-metavariable: $PAYLOAD + message: Found user controlled content in `run_string`. This is dangerous because + it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + shortlink: https://sg.run/bPop + semgrep.dev: + rule: + r_id: 27270 + rv_id: 1263525 + rule_id: PeURWr + version_id: zyTb2OX + url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + origin: community + severity: WARNING + languages: + - python +- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], + ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), + ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + message: Detected subprocess function '$FUNC' with user controlled data. A malicious + actor could leverage this to perform command injection. You may consider using + 'shlex.escape()'. + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.8 OS Command Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + shortlink: https://sg.run/NWxp + semgrep.dev: + rule: + r_id: 27271 + rv_id: 1263526 + rule_id: JDUz3R + version_id: pZT038J + url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-system-call.dangerous-system-call + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: getattr(os, "system")(...) + - pattern: __import__("os").system(...) + - pattern: getattr(__import__("os"), "system")(...) + - pattern: | + $X = __import__("os") + ... + $X.system(...) + - pattern: | + $X = __import__("os") + ... + getattr($X, "system")(...) + - pattern: | + $X = getattr(os, "system") + ... + $X(...) + - pattern: | + $X = __import__("os") + ... + $Y = getattr($X, "system") + ... + $Y(...) + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + message: Found user-controlled data used in a system call. This could allow a malicious + actor to execute commands. Use the 'subprocess' module instead, which is easier + to use without accidentally exposing a command injection vulnerability. + metadata: + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + version: '4' + category: security + technology: + - python + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call + shortlink: https://sg.run/k0W7 + semgrep.dev: + rule: + r_id: 27272 + rv_id: 1263527 + rule_id: 5rUoP1 + version_id: 2KTv2Zn + url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call + origin: community + languages: + - python + severity: ERROR +- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route(...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: | + def $FUNC(request, ...): + ... + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: | + @rest_framework.decorators.api_view(...) + def $FUNC($REQ, ...): + ... + - patterns: + - pattern-either: + - pattern-inside: | + class $VIEW(..., rest_framework.views.APIView, ...): + ... + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, + ...):\n ... \n" + - pattern-inside: | + def $METHOD(self, $REQ, ...): + ... + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: | + class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.StreamRequestHandler, ...): + ... + - pattern-inside: | + class $SERVER(..., http.server.DatagramRequestHandler, ...): + ... + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: | + @pyramid.view.view_config( ... ) + def $VIEW($REQ): + ... + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + _testcapi.run_in_subinterp($PAYLOAD, ...) + - pattern: | + test.support.run_in_subinterp($PAYLOAD, ...) + - focus-metavariable: $PAYLOAD + - pattern-not: | + _testcapi.run_in_subinterp("...", ...) + - pattern-not: | + test.support.run_in_subinterp("...", ...) + message: Found user controlled content in `run_in_subinterp`. This is dangerous + because it allows a malicious actor to run arbitrary Python code. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + category: security + technology: + - python + confidence: MEDIUM + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + shortlink: https://sg.run/wLpY + semgrep.dev: + rule: + r_id: 27273 + rv_id: 1263528 + rule_id: GdUkxR + version_id: X0Tzy1e + url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + origin: community + severity: WARNING + languages: + - python +- id: csharp.dotnet.security.audit.xpath-injection.xpath-injection + message: XPath queries are constructed dynamically on user-controlled input. This + vulnerability in code could lead to an XPath Injection exploitation. + severity: ERROR + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath + Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection/ + - https://cwe.mitre.org/data/definitions/643.html + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XPath Injection + source: https://semgrep.dev/r/csharp.dotnet.security.audit.xpath-injection.xpath-injection + shortlink: https://sg.run/4KP7 + semgrep.dev: + rule: + r_id: 27400 + rv_id: 1262618 + rule_id: x8Uj2k + version_id: 2KTv2Pq + url: https://semgrep.dev/playground/r/2KTv2Pq/csharp.dotnet.security.audit.xpath-injection.xpath-injection + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - pattern-either: + - pattern: $T $M($INPUT,...) {...} + - pattern: | + $T $M(...) { + ... + string $INPUT; + } + pattern-sinks: + - pattern-either: + - pattern: XPathExpression $EXPR = $NAV.Compile("..." + $INPUT + "..."); + - pattern: var $EXPR = $NAV.Compile("..." + $INPUT + "..."); + - pattern: XPathNodeIterator $NODE = $NAV.Select("..." + $INPUT + "..."); + - pattern: var $NODE = $NAV.Select("..." + $INPUT + "..."); + - pattern: Object $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); + - pattern: var $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); +- id: csharp.dotnet.security.audit.ldap-injection.ldap-injection + message: LDAP queries are constructed dynamically on user-controlled input. This + vulnerability in code could lead to an arbitrary LDAP query execution. + severity: ERROR + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection/ + - https://cwe.mitre.org/data/definitions/90 + - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#safe-c-sharp-net-tba-example + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection + shortlink: https://sg.run/GJ9z + semgrep.dev: + rule: + r_id: 27692 + rv_id: 1262612 + rule_id: 2ZUv3R + version_id: l4TJR8G + url: https://semgrep.dev/playground/r/l4TJR8G/csharp.dotnet.security.audit.ldap-injection.ldap-injection + origin: community + languages: + - csharp + mode: taint + options: + taint_unify_mvars: true + pattern-sources: + - patterns: + - focus-metavariable: $INPUT + - pattern-inside: $T $M(...,$INPUT,...) {...} + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $S.Filter = ... + $INPUT + ... + - pattern: $S.Filter = String.Format(...,$INPUT) + - pattern: $S.Filter = String.Concat(...,$INPUT) + pattern-sanitizers: + - pattern-either: + - pattern: Regex.Replace($INPUT, ...) + - pattern: $ENCODER.LdapFilterEncode($INPUT) + - pattern: $ENCODER.LdapDistinguishedNameEncode($INPUT) +- id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + patterns: + - pattern-either: + - patterns: + - pattern: $LIFETIME = $FALSE + - pattern-inside: new TokenValidationParameters {...} + - patterns: + - pattern: | + (TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE + - metavariable-regex: + metavariable: $LIFETIME + regex: (RequireExpirationTime|ValidateLifetime) + - metavariable-regex: + metavariable: $FALSE + regex: (false) + - focus-metavariable: $FALSE + fix: | + true + message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the + JWT tokens lifetime is not validated. This can lead to an JWT token being used + after it has expired, which has security implications. It is recommended to validate + the JWT lifetime to ensure only valid tokens are used. + metadata: + category: security + technology: + - csharp + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-613: Insufficient Session Expiration' + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://cwe.mitre.org/data/definitions/613.html + - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + shortlink: https://sg.run/KA0d + semgrep.dev: + rule: + r_id: 28955 + rv_id: 1262628 + rule_id: bwU5kK + version_id: w8TRolJ + url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + origin: community + languages: + - csharp + severity: WARNING +- id: java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + patterns: + - pattern-inside: | + management: + ... + endpoints: + ... + web: + ... + exposure: + ... + - pattern: | + include: "*" + message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints + such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless + you have Spring Security enabled or another means to protect these endpoints, + this functionality is available without authentication, causing a severe security + risk. + severity: WARNING + languages: + - yaml + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + category: security + technology: + - spring + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + shortlink: https://sg.run/1Bzw + semgrep.dev: + rule: + r_id: 29422 + rv_id: 1263076 + rule_id: eqUerQ + version_id: w8TRo5n + url: https://semgrep.dev/playground/r/w8TRo5n/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + origin: community +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(..., $REQUEST, ...): + ... + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + shortlink: https://sg.run/49BE + semgrep.dev: + rule: + r_id: 31144 + rv_id: 1263388 + rule_id: EwUepx + version_id: 7ZTE3qK + url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + origin: community +- id: python.django.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` + module. If user data is used to generate the data in this file, it is possible + that an attacker could inject a formula when the CSV is imported into a spreadsheet + application that runs an attacker script, which could steal data from the importing + user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in + replacement with the same API that will attempt to mitigate formula injection + attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + technology: + - django + - python + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection + shortlink: https://sg.run/Pw9q + semgrep.dev: + rule: + r_id: 31145 + rv_id: 1263389 + rule_id: 7KUK1y + version_id: LjTkgD9 + url: https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: | + $WRITER = csv.writer(...) + + ... + + $WRITER.$WRITE(...) + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-inside: | + def $FUNC(..., $REQUEST, ...): + ... + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + severity: ERROR +- id: python.flask.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` + module. If user data is used to generate the data in this file, it is possible + that an attacker could inject a formula when the CSV is imported into a spreadsheet + application that runs an attacker script, which could steal data from the importing + user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in + replacement with the same API that will attempt to mitigate formula injection + attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + technology: + - python + - flask + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection + shortlink: https://sg.run/JzqQ + semgrep.dev: + rule: + r_id: 31146 + rv_id: 1263428 + rule_id: L1UR2K + version_id: jQTn50Y + url: https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection + origin: community + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: | + $WRITER = csv.writer(...) + + ... + + $WRITER.$WRITE(...) + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + mode: taint + options: + symbolic_propagation: true + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: | + @$APP.route($ROUTE, ...) + def $FUNC(..., $ROUTEVAR, ...): + ... + - focus-metavariable: $ROUTEVAR + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: | + $CMD = ["...", ...] + ... + subprocess.$FUNC($CMD, ...) + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + severity: ERROR + message: Detected user input entering a `subprocess` call unsafely. This could result + in a command injection vulnerability. An attacker could use this vulnerability + to execute arbitrary commands on the host, which allows them to download malware, + scan sensitive data, or run any command they wish on the server. Do not let users + choose the command to run. In general, prefer to use Python API versions of system + commands. If you must use subprocess, use a dictionary to allowlist a set of commands. + metadata: + category: security + technology: + - flask + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + confidence: HIGH + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + shortlink: https://sg.run/5gW3 + semgrep.dev: + rule: + r_id: 31147 + rv_id: 1263433 + rule_id: 8GU3qp + version_id: bZT53gQ + url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + origin: community +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in + a `actions/github-script`''s `script:` step could allow an attacker to inject + their own code into the runner. This would allow them to steal secrets and code. + `github` context data can have arbitrary user input and should be treated as untrusted. + Instead, use an intermediate environment variable with `env:` to store the data + and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: "$ENVVAR".' + metadata: + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + technology: + - github-actions + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + shortlink: https://sg.run/g1G0 + semgrep.dev: + rule: + r_id: 31441 + rv_id: 1423394 + rule_id: OrUQvK + version_id: 5PT7Zyw + url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + uses: $ACTION + ... + - pattern-inside: | + with: + ... + script: ... + ... + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... + }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.workflow ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && + ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.workflow && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... + }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: php.lang.security.injection.echoed-request.echoed-request + mode: taint + message: '`Echo`ing user input risks cross-site scripting vulnerability. You should + use `htmlentities()` when showing data to users.' + languages: + - php + severity: ERROR + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + pattern-sinks: + - pattern: echo $...VARS; + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + fix: echo htmlentities($...VARS); + metadata: + technology: + - php + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request + shortlink: https://sg.run/Bqqb + semgrep.dev: + rule: + r_id: 31707 + rv_id: 1263283 + rule_id: BYUyyg + version_id: d6TyxE9 + url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request + origin: community +- id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + message: 'An encryption mode of operation is being used without proper message authentication. + This can potentially result in the encrypted content to be decrypted by an attacker. + Consider instead use an AEAD mode of operation like GCM. ' + languages: + - python + severity: ERROR + metadata: + category: security + technology: + - cryptography + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + shortlink: https://sg.run/N9JL + semgrep.dev: + rule: + r_id: 31871 + rv_id: 1263357 + rule_id: lBUpNZ + version_id: BjTkZj5 + url: https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + origin: community + patterns: + - pattern-either: + - patterns: + - pattern: | + Cipher(..., $HAZMAT_MODE(...),...) + - pattern-not-inside: | + Cipher(..., $HAZMAT_MODE(...),...) + ... + HMAC(...) + - pattern-not-inside: | + Cipher(..., $HAZMAT_MODE(...),...) + ... + hmac.HMAC(...) + - metavariable-pattern: + metavariable: $HAZMAT_MODE + patterns: + - pattern-either: + - pattern: modes.CTR + - pattern: modes.CBC + - pattern: modes.CFB + - pattern: modes.OFB +- id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + message: 'An encryption mode of operation is being used without proper message authentication. + This can potentially result in the encrypted content to be decrypted by an attacker. + Consider instead use an AEAD mode of operation like GCM. ' + languages: + - python + severity: ERROR + metadata: + category: security + technology: + - cryptography + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + shortlink: https://sg.run/k1K1 + semgrep.dev: + rule: + r_id: 31872 + rv_id: 1263556 + rule_id: YGUw8w + version_id: GxTkeyz + url: https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + origin: community + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + AES.new(..., $PYCRYPTODOME_MODE) + - pattern-not-inside: | + AES.new(..., $PYCRYPTODOME_MODE) + ... + HMAC.new + - metavariable-pattern: + metavariable: $PYCRYPTODOME_MODE + patterns: + - pattern-either: + - pattern: AES.MODE_CBC + - pattern: AES.MODE_CTR + - pattern: AES.MODE_CFB + - pattern: AES.MODE_OFB +- id: java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + patterns: + - pattern-inside: | + management: + ... + endpoints: + ... + web: + ... + exposure: + ... + include: + ... + - pattern: | + include: [..., $ACTUATOR, ...] + - metavariable-comparison: + metavariable: $ACTUATOR + comparison: not str($ACTUATOR) in ["health","*"] + message: Spring Boot Actuator "$ACTUATOR" is enabled. Depending on the actuator, + this can pose a significant security risk. Please double-check if the actuator + is needed and properly secured. + severity: WARNING + languages: + - yaml + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + category: security + technology: + - spring + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + shortlink: https://sg.run/JzKQ + semgrep.dev: + rule: + r_id: 32290 + rv_id: 1263078 + rule_id: kxUWpX + version_id: O9TpxBp + url: https://semgrep.dev/playground/r/O9TpxBp/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + origin: community +- id: java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + patterns: + - pattern: management.endpoints.web.exposure.include=$...ACTUATORS + - metavariable-comparison: + metavariable: $...ACTUATORS + comparison: not str($...ACTUATORS) in ["health","*"] + message: Spring Boot Actuators "$...ACTUATORS" are enabled. Depending on the actuators, + this can pose a significant security risk. Please double-check if the actuators + are needed and properly secured. + severity: WARNING + languages: + - generic + options: + generic_ellipsis_max_span: 0 + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + category: security + technology: + - spring + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + shortlink: https://sg.run/5g23 + semgrep.dev: + rule: + r_id: 32291 + rv_id: 1263079 + rule_id: wdUWrZ + version_id: e1Tyjqe + url: https://semgrep.dev/playground/r/e1Tyjqe/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + origin: community +- id: terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + patterns: + - pattern: | + resource "google_storage_bucket" $ANYTHING { + ... + } + - pattern-not-inside: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n logging + {\n log_bucket = ...\n } \n ...\n}\n" + message: Ensure bucket logs access. + languages: + - hcl + severity: WARNING + metadata: + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + technology: + - terraform + - gcp + category: security + references: + - https://docs.bridgecrew.io/docs/google-cloud-policy-index + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + shortlink: https://sg.run/5g5D + semgrep.dev: + rule: + r_id: 32303 + rv_id: 1263813 + rule_id: gxUrdg + version_id: JdTzxRN + url: https://semgrep.dev/playground/r/JdTzxRN/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + origin: community +- id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial + stream output. Its use is strongly discouraged. ARC4 does not use mode constructions. + Use a strong symmetric cipher such as EAS instead. With the `cryptography` package + it is recommended to use the `Fernet` which is a secure implementation of AES + in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class + from the hazmat primitives but use the AES algorithm instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + shortlink: https://sg.run/xoZL + semgrep.dev: + rule: + r_id: 33630 + rv_id: 1263348 + rule_id: KxU8gK + version_id: QkTGq3Q + url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) + - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) + - metavariable-regex: + metavariable: $ARC4 + regex: ^(ARC4)$ + - focus-metavariable: $ARC4 + fix: AES +- id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + message: Blowfish is a block cipher developed by Bruce Schneier. It is known to + be susceptible to attacks when using weak keys. The author has recommended that + users of Blowfish move to newer algorithms such as AES. With the `cryptography` + package it is recommended to use `Fernet` which is a secure implementation of + AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class + from the hazmat primitives but use the AES algorithm instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + - https://tools.ietf.org/html/rfc5469 + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + shortlink: https://sg.run/OdzL + semgrep.dev: + rule: + r_id: 33631 + rv_id: 1263349 + rule_id: qNULvO + version_id: 3ZT4XK7 + url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) + - metavariable-regex: + metavariable: $BLOWFISH + regex: ^(Blowfish)$ + - focus-metavariable: $BLOWFISH + fix: AES +- id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B303 + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - cryptography + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/eY88 + semgrep.dev: + rule: + r_id: 33632 + rv_id: 1263352 + rule_id: lBUopp + version_id: JdTzxww + url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + origin: community + severity: WARNING + languages: + - python + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$MD5() + - metavariable-regex: + metavariable: $MD5 + regex: ^(MD5)$ + - focus-metavariable: $MD5 + fix: SHA256 +- id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + patterns: + - pattern: hashlib.md5(...) + - pattern-not: hashlib.md5(..., usedforsecurity=False, ...) + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B303 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/vYrY + semgrep.dev: + rule: + r_id: 33633 + rv_id: 1263536 + rule_id: PeU2e2 + version_id: kbTzGE1 + url: https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + origin: community + severity: WARNING + languages: + - python +- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + shortlink: https://sg.run/dlOE + semgrep.dev: + rule: + r_id: 33634 + rv_id: 1263545 + rule_id: JDUGnK + version_id: ExTExln + url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.Blowfish.new(...) + - pattern: Crypto.Cipher.Blowfish.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + message: Detected DES cipher or Triple DES algorithm which is considered insecure. + This algorithm is not cryptographically secure and can be reversed easily. Use + a secure symmetric cipher from the cryptodome package instead. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + shortlink: https://sg.run/Z5bw + semgrep.dev: + rule: + r_id: 33635 + rv_id: 1263546 + rule_id: 5rUr73 + version_id: 7ZTE3G7 + url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.DES.new(...) + - pattern: Crypto.Cipher.DES.new(...) + - pattern: Cryptodome.Cipher.DES3.new(...) + - pattern: Crypto.Cipher.DES3.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + message: Detected RC2 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + shortlink: https://sg.run/nAbY + semgrep.dev: + rule: + r_id: 33636 + rv_id: 1263547 + rule_id: GdUYlW + version_id: LjTkgn6 + url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC2.new(...) + - pattern: Crypto.Cipher.ARC2.new(...) +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm + is not cryptographically secure and can be reversed easily. Use secure stream + ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES + with a block size of 128 bits. When using a block cipher, use a modern mode of + operation that also provides authentication, such as GCM. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + bandit-code: B304 + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + shortlink: https://sg.run/Eo6N + semgrep.dev: + rule: + r_id: 33637 + rv_id: 1263548 + rule_id: ReUnEB + version_id: 8KT5rXY + url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: Cryptodome.Cipher.ARC4.new(...) + - pattern: Crypto.Cipher.ARC4.new(...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + shortlink: https://sg.run/7JP2 + semgrep.dev: + rule: + r_id: 33638 + rv_id: 1263550 + rule_id: AbU0Ex + version_id: QkTGqD8 + url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD2.new(...) + - pattern: Cryptodome.Hash.MD2.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + shortlink: https://sg.run/Lve6 + semgrep.dev: + rule: + r_id: 33639 + rv_id: 1263551 + rule_id: BYUJy4 + version_id: 3ZT4Xnp + url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD4.new(...) + - pattern: Cryptodome.Hash.MD4.new (...) +- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use a modern + hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + category: security + technology: + - pycryptodome + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + shortlink: https://sg.run/85JN + semgrep.dev: + rule: + r_id: 33640 + rv_id: 1263552 + rule_id: DbUXwo + version_id: 44TEjpk + url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + origin: community + options: + symbolic_propagation: true + severity: WARNING + languages: + - python + pattern-either: + - pattern: Crypto.Hash.MD5.new(...) + - pattern: Cryptodome.Hash.MD5.new (...) +- id: terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + patterns: + - pattern: resource + - pattern-inside: | + resource "google_dns_managed_zone" "..." { + ... + dnssec_config { + ... + default_key_specs { + ... + algorithm = "rsasha1" + key_type = "zoneSigning" + ... + } + ... + } + ... + } + - pattern-inside: | + resource "google_dns_managed_zone" "..." { + ... + dnssec_config { + ... + default_key_specs { + ... + algorithm = "rsasha1" + key_type = "keySigning" + ... + } + ... + } + ... + } + message: "Ensure that RSASHA1 is not used for the zone-signing and key-signing keys + in Cloud DNS DNSSEC\t" + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + shortlink: https://sg.run/bKKW + semgrep.dev: + rule: + r_id: 33670 + rv_id: 1263837 + rule_id: 7KUZZb + version_id: bZT53oD + url: https://semgrep.dev/playground/r/bZT53oD/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + patterns: + - pattern: resource + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + require_ssl = true + ... + } + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = ... + ... + } + ... + } + message: Ensure all Cloud SQL database instance requires all incoming connections + to use SSL + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + shortlink: https://sg.run/W4Yg + semgrep.dev: + rule: + r_id: 33709 + rv_id: 1263873 + rule_id: v8Uod5 + version_id: pZT033e + url: https://semgrep.dev/playground/r/pZT033e/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + patterns: + - pattern: resource + - pattern-either: + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + authorized_networks { + ... + value = "0.0.0.0/0" + ... + } + ... + } + ... + } + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + dynamic "authorized_networks" { + ... + content { + ... + value = "0.0.0.0/0" + ... + } + ... + } + ... + } + ... + } + message: Ensure that Cloud SQL database Instances are not open to the world + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + category: security + technology: + - terraform + - gcp + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + shortlink: https://sg.run/0Xv5 + semgrep.dev: + rule: + r_id: 33710 + rv_id: 1263876 + rule_id: d8U7Ll + version_id: jQTn559 + url: https://semgrep.dev/playground/r/jQTn559/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + origin: community + languages: + - hcl + severity: WARNING +- id: csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + message: You are using the outdated PKCS#1 v1.5 encryption padding for your RSA + key. Use the OAEP padding instead. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangedeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangedeformatter + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + shortlink: https://sg.run/GoJ1 + semgrep.dev: + rule: + r_id: 35492 + rv_id: 1262625 + rule_id: QrU2G5 + version_id: bZT53zb + url: https://semgrep.dev/playground/r/bZT53zb/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + origin: community + languages: + - csharp + pattern-either: + - pattern: (RSAPKCS1KeyExchangeFormatter $FORMATER).CreateKeyExchange(...); + - pattern: (RSAPKCS1KeyExchangeDeformatter $DEFORMATER).DecryptKeyExchange(...); +- id: php.lang.security.redirect-to-request-uri.redirect-to-request-uri + patterns: + - pattern-either: + - pattern: | + header('$LOCATION' . $_SERVER['REQUEST_URI']); + - pattern: | + header('$LOCATION' . $_SERVER['REQUEST_URI'] . $MORE); + - metavariable-regex: + metavariable: $LOCATION + regex: ^(?i)location:\s*$ + message: Redirecting to the current request URL may redirect to another domain, + if the current path starts with two slashes. E.g. in https://www.example.com//attacker.com, + the value of REQUEST_URI is //attacker.com, and redirecting to it will redirect + to that domain. + metadata: + references: + - https://www.php.net/manual/en/reserved.variables.server.php + - https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html + category: security + technology: + - php + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + likelihood: MEDIUM + impact: LOW + confidence: MEDIUM + subcategory: + - vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/php.lang.security.redirect-to-request-uri.redirect-to-request-uri + shortlink: https://sg.run/RWl2 + semgrep.dev: + rule: + r_id: 35493 + rv_id: 1263299 + rule_id: 3qUb4n + version_id: A8Tgdvq + url: https://semgrep.dev/playground/r/A8Tgdvq/php.lang.security.redirect-to-request-uri.redirect-to-request-uri + origin: community + languages: + - php + severity: WARNING +- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `workflow_run` and checks out code + from the incoming pull request. When using `workflow_run`, the Action runs in + the context of the target repository, which includes access to all repository + secrets. Normally, this is safe because the Action only runs code from the target + repository, not the incoming PR. However, by checking out the incoming PR code, + you're now using the incoming code for the rest of the action. You may be inadvertently + executing arbitrary code from the incoming PR with access to repository secrets, + which would let an attacker steal repository secrets. This normally happens by + running build scripts (e.g., `npm build` and `make`) or dependency installation + scripts (e.g., `python setup.py install`). Audit your workflow file to make sure + no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + for additional mitigations. + metadata: + category: security + owasp: A01:2017 - Injection + cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + subcategory: + - vuln + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability + technology: + - github-actions + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + shortlink: https://sg.run/A0p6 + semgrep.dev: + rule: + r_id: 35494 + rv_id: 947046 + rule_id: 4bU8E4 + version_id: kbTYRwl + url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + origin: community + patterns: + - pattern-inside: | + on: + ... + workflow_run: ... + ... + ... + - pattern-inside: | + jobs: + ... + $JOBNAME: + ... + steps: + ... + - pattern: | + ... + uses: "$ACTION" + with: + ... + ref: $EXPR + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern: ${{ github.event.workflow_run ... }} + severity: WARNING +- id: csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + message: Usage of deprecated cipher algorithm detected. Use Aes or ChaCha20Poly1305 + instead. + severity: ERROR + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.des?view=net-6.0#remarks + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rc2?view=net-6.0#remarks + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aes?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + shortlink: https://sg.run/k8Qo + semgrep.dev: + rule: + r_id: 36772 + rv_id: 1262622 + rule_id: WAUJr0 + version_id: 9lT4bRK + url: https://semgrep.dev/playground/r/9lT4bRK/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + origin: community + languages: + - csharp + patterns: + - pattern: $KEYTYPE.Create(...); + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: DES + - pattern: RC2 +- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode + message: Usage of the insecure ECB mode detected. You should use an authenticated + encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305. + severity: WARNING + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + shortlink: https://sg.run/wj9n + semgrep.dev: + rule: + r_id: 36773 + rv_id: 1262623 + rule_id: 0oUqWP + version_id: yeTxpPw + url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + origin: community + languages: + - csharp + patterns: + - pattern-either: + - pattern: ($KEYTYPE $KEY).EncryptEcb(...); + - pattern: ($KEYTYPE $KEY).DecryptEcb(...); + - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 +- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + message: You are using an insecure random number generator (RNG) to create a cryptographic + key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator + instead. + severity: ERROR + metadata: + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + category: security + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key + subcategory: + - vuln + technology: + - .net + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + shortlink: https://sg.run/xjrA + semgrep.dev: + rule: + r_id: 36774 + rv_id: 1262624 + rule_id: KxU3Nq + version_id: rxTAK2O + url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + origin: community + languages: + - csharp + mode: taint + pattern-sources: + - patterns: + - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... + - pattern: $KEY + pattern-sinks: + - pattern-either: + - patterns: + - pattern: ($KEYTYPE $CIPHER).Key = $SINK; + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 + - pattern: new AesGcm(...) + - pattern: new AesCcm(...) + - pattern: new ChaCha20Poly1305(...) +- id: html.security.plaintext-http-link.plaintext-http-link + metadata: + category: security + technology: + - html + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + confidence: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/319.html + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link + shortlink: https://sg.run/RA5q + semgrep.dev: + rule: + r_id: 39193 + rv_id: 1262976 + rule_id: AbUnNo + version_id: xyTjzRL + url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link + origin: community + patterns: + - pattern: ... + - metavariable-regex: + metavariable: $URL + regex: ^(?i)http:// + message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL + if possible. + severity: WARNING + languages: + - html +- id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use HMAC + instead. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::org.apache.commons + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + shortlink: https://sg.run/AWL2 + semgrep.dev: + rule: + r_id: 39194 + rv_id: 1263012 + rule_id: BYUGK0 + version_id: WrTqK7K + url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + origin: community + patterns: + - pattern: | + $DU.$GET_ALGO().digest(...) + - metavariable-pattern: + metavariable: $GET_ALGO + pattern: getMd5Digest + - metavariable-pattern: + metavariable: $DU + pattern: DigestUtils + - focus-metavariable: $GET_ALGO + fix: | + getSha512Digest +- id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + message: Using input or workflow parameters in here-scripts can lead to command + injection or code injection. Convert the parameters to env variables instead. + languages: + - yaml + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - "A03:2021 \u2013 Injection" + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://github.com/argoproj/argo-workflows/issues/5061 + - https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370 + technology: + - ci + - argo + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + - Command Injection + source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + shortlink: https://sg.run/yqeZ + semgrep.dev: + rule: + r_id: 40768 + rv_id: 1151472 + rule_id: 10U0zW + version_id: xyTp17z + url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + origin: community + severity: ERROR + patterns: + - pattern-inside: | + apiVersion: $VERSION + ... + - metavariable-regex: + metavariable: $VERSION + regex: (argoproj.io.*) + - pattern-either: + - patterns: + - pattern-inside: | + command: + ... + - $LANG + ... + ... + source: + $SCRIPT + - metavariable-regex: + metavariable: $LANG + regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $SCRIPT + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $SCRIPT + - patterns: + - pattern-either: + - pattern-inside: | + container: + ... + command: $LANG + ... + args: $PARAM + - pattern-inside: | + containerSet: + ... + containers: + - ... + command: $LANG + ... + args: $PARAM + - metavariable-regex: + metavariable: $LANG + regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $PARAM + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $PARAM +- id: python.cryptography.security.empty-aes-key.empty-aes-key + message: Potential empty AES encryption key. Using an empty key in AES encryption + can result in weak encryption and may allow attackers to easily decrypt sensitive + data. Ensure that a strong, non-empty key is used for AES encryption. + patterns: + - pattern: AES.new("",...) + languages: + - python + severity: WARNING + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-310: Cryptographic Issues' + references: + - https://cwe.mitre.org/data/definitions/327.html + - https://cwe.mitre.org/data/definitions/310.html + category: security + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + owasp: A6:2017 misconfiguration + functional-categories: + - crypto::search::key-length::pycrypto + - crypto::search::key-length::pycryptodome + technology: + - python + - pycrypto + - pycryptodome + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key + shortlink: https://sg.run/zQ9G + semgrep.dev: + rule: + r_id: 44817 + rv_id: 946105 + rule_id: OrUADK + version_id: 8KTKjRg + url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key + origin: community +- id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + patterns: + - pattern: | + ENTRYPOINT $...VARS + - pattern-not-inside: | + USER $USER + ... + fix: | + USER non-root + ENTRYPOINT $...VARS + message: By not specifying a USER, a program in the container may run as 'root'. + This is a security hazard. If an attacker can control a process running as root, + they may have control over the container. Ensure that the last USER in a Dockerfile + is a USER other than 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + shortlink: https://sg.run/k281 + semgrep.dev: + rule: + r_id: 47272 + rv_id: 1262659 + rule_id: ReUW9E + version_id: o5TbD21 + url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + origin: community +- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + pattern-either: + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + account_aggregation_source { + ... + regions = ... + ... + } + ... + } + - pattern: | + resource "aws_config_configuration_aggregator" $ANYTHING { + ... + organization_aggregation_source { + ... + regions = ... + ... + } + ... + } + message: The AWS configuration aggregator does not aggregate all AWS Config region. + This may result in unmonitored configuration in regions that are thought to be + unused. Configure the aggregator with all_regions for the source. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + shortlink: https://sg.run/O6A7 + semgrep.dev: + rule: + r_id: 47275 + rv_id: 1263703 + rule_id: DbUo7v + version_id: A8Tgdwv + url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + origin: community +- id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - $NAME: $CONTAINER + ... + - pattern: | + image: ... + ... + - pattern-not: | + image: ... + ... + securityContext: + ... + - metavariable-regex: + metavariable: $NAME + regex: name + - focus-metavariable: $NAME + fix: | + securityContext: + allowPrivilegeEscalation: false + $NAME + message: In Kubernetes, each pod runs in its own isolated environment with its own + set of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. By adding a `securityContext` to + your Kubernetes pod, you can help to ensure that your containerized applications + are more secure and less vulnerable to privilege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + shortlink: https://sg.run/eleR + semgrep.dev: + rule: + r_id: 47276 + rv_id: 1263931 + rule_id: WAU5J6 + version_id: 2KTv2j8 + url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + origin: community + languages: + - yaml + severity: WARNING +- id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + patterns: + - pattern-inside: | + containers: + ... + - pattern-inside: | + - name: $CONTAINER + ... + - pattern-inside: | + image: ... + ... + - pattern-inside: | + securityContext: + ... + - pattern: | + allowPrivilegeEscalation: $TRUE + - metavariable-pattern: + metavariable: $TRUE + pattern: | + true + - focus-metavariable: $TRUE + fix: | + false + message: In Kubernetes, each pod runs in its own isolated environment with its own set + of security policies. However, certain container images may contain `setuid` + or `setgid` binaries that could allow an attacker to perform privilege escalation + and gain access to sensitive resources. To mitigate this risk, it's recommended + to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` + set to `false`. This will prevent the container from running any privileged processes + and limit the impact of any potential attacks. In the container `$CONTAINER` + this parameter is set to `true` which makes this container much more vulnerable + to privelege escalation attacks. + metadata: + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + category: security + technology: + - kubernetes + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + shortlink: https://sg.run/vw3W + semgrep.dev: + rule: + r_id: 47277 + rv_id: 1263932 + rule_id: 0oUkqQ + version_id: X0Tzyqr + url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + origin: community + languages: + - yaml + severity: WARNING +- id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + patterns: + - pattern: | + resource "aws_docdb_cluster" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_docdb_cluster" $ANYTHING { + ... + enabled_cloudwatch_logs_exports = [..., "audit", ...] + ... + } + message: Auditing is not enabled for DocumentDB. To ensure that you are able to + accurately audit the usage of your DocumentDB cluster, you should enable auditing + and export logs to CloudWatch. + languages: + - hcl + severity: INFO + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + shortlink: https://sg.run/xJYP + semgrep.dev: + rule: + r_id: 48630 + rv_id: 1263705 + rule_id: AbU1WN + version_id: DkTRbA4 + url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + origin: community +- id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + patterns: + - pattern: | + resource "aws_ecr_repository" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_ecr_repository" $ANYTHING { + ... + image_tag_mutability = "IMMUTABLE" + ... + } + message: The ECR repository allows tag mutability. Image tags could be overwritten + with compromised images. ECR images should be set to IMMUTABLE to prevent code + injection through image mutation. This can be done by setting `image_tag_mutability` + to IMMUTABLE. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + shortlink: https://sg.run/ZEeL + semgrep.dev: + rule: + r_id: 48635 + rv_id: 1263716 + rule_id: KxUB4o + version_id: A8Tgdwd + url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + origin: community +- id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + patterns: + - pattern-inside: | + resource "aws_ecr_repository_policy" $ANYTHING { + ... + } + - pattern-either: + - patterns: + - pattern: policy = "$JSONPOLICY" + - metavariable-pattern: + metavariable: $JSONPOLICY + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, ...} + - patterns: + - pattern-inside: policy = jsonencode(...) + - pattern-not-inside: | + {..., Effect = "Deny", ...} + - pattern-either: + - pattern: | + {..., Principal = "*", ...} + - pattern: | + {..., Principal = [..., "*", ...], ...} + - pattern: | + {..., Principal = { AWS = "*" }, ...} + - pattern: | + {..., Principal = { AWS = [..., "*", ...] }, ...} + message: Detected wildcard access granted in your ECR repository policy principal. + This grants access to all users, including anonymous users (public access). Instead, + limit principals, actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy + - https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html + - https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html + - https://cwe.mitre.org/data/definitions/732.html + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + shortlink: https://sg.run/nzqb + semgrep.dev: + rule: + r_id: 48636 + rv_id: 1263717 + rule_id: qNUzov + version_id: BjTkZ6A + url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + origin: community + languages: + - hcl + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + pattern: $CIPHER.getInstance("=~/AES/ECB.*/") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + shortlink: https://sg.run/dB2Y + semgrep.dev: + rule: + r_id: 48734 + rv_id: 1263009 + rule_id: WAU2yA + version_id: A8TgdEo + url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + origin: community + message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality + and is not semantically secure so should not be used. Instead, use a strong, + secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + pattern: $CIPHER.getInstance("Blowfish") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + shortlink: https://sg.run/ZE4n + semgrep.dev: + rule: + r_id: 48735 + rv_id: 1263010 + rule_id: 0oUR28 + version_id: BjTkZy0 + url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + origin: community + message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes + it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead, + use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + pattern-either: + - patterns: + - pattern-either: + - pattern-inside: | + import javax; + ... + - pattern-either: + - pattern: javax.crypto.Cipher.getInstance("AES") + - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.*; + ... + - pattern-inside: | + import javax.crypto; + ... + - pattern-either: + - pattern: crypto.Cipher.getInstance("AES") + - pattern: (crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: | + import javax.crypto.*; + ... + - pattern-inside: | + import javax.crypto.Cipher; + ... + - pattern-either: + - pattern: Cipher.getInstance("AES") + - pattern: (Cipher $CIPHER).getInstance("AES") + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + shortlink: https://sg.run/nzKO + semgrep.dev: + rule: + r_id: 48736 + rv_id: 1263011 + rule_id: KxUB7Z + version_id: DkTRbwy + url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + origin: community + message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses + ECB mode. ECB doesn''t provide message confidentiality and is not semantically + secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + pattern: $CIPHER.getInstance("RC2") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + shortlink: https://sg.run/EEvA + semgrep.dev: + rule: + r_id: 48737 + rv_id: 1263014 + rule_id: qNUzXG + version_id: K3TKkg0 + url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + origin: community + message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and + is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + pattern: $CIPHER.getInstance("RC4") + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + shortlink: https://sg.run/7OYR + semgrep.dev: + rule: + r_id: 48738 + rv_id: 1263015 + rule_id: lBUw8k + version_id: qkTR7vk + url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + origin: community + message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including + stream cipher attacks and bit flipping attacks. Instead, use a strong, secure + cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + severity: WARNING + languages: + - java +- id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + message: Detected an HTTP request sent via HttpGet. This could lead to sensitive + information being sent over an insecure channel. Instead, it is recommended to + send requests over HTTPS. + severity: WARNING + metadata: + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + category: security + cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: A03:2017 - Sensitive Data Exposure + references: + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection() + subcategory: + - vuln + technology: + - java + vulnerability: Insecure Transport + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + shortlink: https://sg.run/QE2q + semgrep.dev: + rule: + r_id: 48942 + rv_id: 946061 + rule_id: 6JUOJ2 + version_id: WrTEo9G + url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + origin: community + languages: + - java + fix-regex: + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + count: 1 + patterns: + - pattern: | + "=~/[Hh][Tt][Tt][Pp]://.*/" + - pattern-inside: | + $R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/"); + ... + $CLIENT. ... .execute($R, ...); +- id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + patterns: + - pattern: | + resource "aws_ebs_volume" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_ebs_volume" $ANYTHING { + ... + encrypted = true + ... + } + message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived + snapshots could be read if compromised. Volumes should be encrypted to ensure + sensitive data is stored securely. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted + - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + shortlink: https://sg.run/6ZbY + semgrep.dev: + rule: + r_id: 50759 + rv_id: 1263708 + rule_id: YGUKl1 + version_id: K3TKk1Z + url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + origin: community +- id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + patterns: + - pattern: | + resource "aws_launch_template" $ANYTHING { + ... + } + - pattern-not-inside: | + resource "aws_launch_template" $ANYTHING { + ... + metadata_options { + ... + http_endpoint = "disabled" + ... + } + ... + } + - pattern-not-inside: | + resource "aws_launch_template" $ANYTHING { + ... + metadata_options { + ... + http_tokens = "required" + ... + } + ... + } + message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1) + enabled. IMDSv2 introduced session authentication tokens which improve security + when talking to IMDS. You should either disable IMDS or require the use of IMDSv2. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe: + - 'CWE-1390: Weak Authentication' + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + shortlink: https://sg.run/pg9J + semgrep.dev: + rule: + r_id: 50762 + rv_id: 1263712 + rule_id: zdU0Wo + version_id: JdTzx88 + url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + origin: community +- id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + patterns: + - pattern-either: + - pattern: | + resource "aws_subnet" $ANYTHING { + ... + map_public_ip_on_launch = true + ... + } + - pattern: | + resource "aws_default_subnet" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_default_subnet" $ANYTHING { + ... + map_public_ip_on_launch = false + ... + } + message: Resources in the AWS subnet are assigned a public IP address. Resources + should not be exposed on the public internet, but should have access limited to + consumers required for the function of your application. Set `map_public_ip_on_launch` + to false so that resources are not publicly-accessible. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch + - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + shortlink: https://sg.run/XJZw + semgrep.dev: + rule: + r_id: 50764 + rv_id: 1263744 + rule_id: 2ZUo79 + version_id: d6Tyxdb + url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address + origin: community +- id: clojure.lang.security.use-of-md5.use-of-md5 + languages: + - clojure + severity: WARNING + message: MD5 hash algorithm detected. This is not collision resistant and leads + to easily-cracked password hashes. Replace with current recommended hashing algorithms. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + author: Gabriel Marquet + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 + shortlink: https://sg.run/BgPx + semgrep.dev: + rule: + r_id: 52195 + rv_id: 1262609 + rule_id: nJU1ep + version_id: 0bTKz2B + url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 + origin: community + pattern-either: + - pattern: (MessageDigest/getInstance "MD5") + - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance "MD5") + - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) +- id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + patterns: + - pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$ + message: Detects potential Google Maps API keys in code + languages: + - generic + severity: WARNING + metadata: + description: Detects potential Google Maps API keys in code + severity: MEDIUM + category: security + confidence: MEDIUM + impact: HIGH + likelihood: MEDIUM + subcategory: + - audit + owasp: + - A3:2017 Sensitive Data Exposure + references: + - https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e + cwe: + - 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File + or Directory' + technology: + - Google Maps + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + shortlink: https://sg.run/DL5d + semgrep.dev: + rule: + r_id: 52196 + rv_id: 945530 + rule_id: EwU3kN + version_id: NdTqkGz + url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + origin: community +- id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + patterns: + - pattern: | + resource "aws_kinesis_stream" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_kinesis_stream" $ANYTHING { + ... + encryption_type = "KMS" + ... + } + message: The AWS Kinesis stream does not encrypt data at rest. The data could be + read if the Kinesis stream storage layer is compromised. Enable Kinesis stream + server-side encryption. + languages: + - hcl + severity: WARNING + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type + - https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + shortlink: https://sg.run/KZ0L + semgrep.dev: + rule: + r_id: 52199 + rv_id: 1263728 + rule_id: 8GU72N + version_id: pZT037O + url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + origin: community +- id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + patterns: + - pattern-either: + - pattern-inside: | + resource "aws_sqs_queue_policy" $ANYTHING { + ... + } + - pattern-inside: | + resource "aws_sqs_queue" $ANYTHING { + ... + } + - pattern-either: + - patterns: + - pattern: policy = "$JSONPOLICY" + - metavariable-pattern: + metavariable: $JSONPOLICY + language: json + patterns: + - pattern-not-inside: | + {..., "Effect": "Deny", ...} + - pattern-either: + - pattern: | + {..., "Principal": "*", ...} + - pattern: | + {..., "Principal": [..., "*", ...], ...} + - pattern: | + {..., "Principal": { "AWS": "*" }, ...} + - pattern: | + {..., "Principal": { "AWS": [..., "*", ...] }, ...} + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\": + ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n + \ \"aws:PrincipalARN\": ...\n }\n},\n...}\n" + - patterns: + - pattern-inside: policy = jsonencode(...) + - pattern-not-inside: | + {..., Effect = "Deny", ...} + - pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\" + = ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\" + = ...\n }\n},\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\" + = ...\n }\n}\n...}\n" + - pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\" + = ...\n }\n},\n...}\n" + - pattern-either: + - pattern: | + {..., Principal = "*", ...} + - pattern: | + {..., Principal = [..., "*", ...], ...} + - pattern: | + {..., Principal = { AWS = "*" }, ...} + - pattern: | + {..., Principal = { AWS = [..., "*", ...] }, ...} + message: Wildcard used in your SQS queue policy principal. This grants access to + all users, including anonymous users (public access). Unless you explicitly require + anyone on the internet to be able to read or write to your queue, limit principals, + actions and resources to what you need according to least privilege. + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml + in None + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + shortlink: https://sg.run/z3eW + semgrep.dev: + rule: + r_id: 53517 + rv_id: 1263741 + rule_id: PeUl9d + version_id: O9TpxgE + url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + patterns: + - pattern: | + resource "aws_lambda_permission" $ANYTHING { + ... + principal = "$PRINCIPAL" + ... + } + - pattern-not: | + resource "aws_lambda_permission" $ANYTHING { + ... + source_arn = ... + ... + } + - metavariable-regex: + metavariable: $PRINCIPAL + regex: .*[.]amazonaws[.]com$ + message: The AWS Lambda permission has an AWS service principal but does not specify + a source ARN. If you grant permission to a service principal without specifying + the source, other accounts could potentially configure resources in their account + to invoke your Lambda function. Set the source_arn value to the ARN of the AWS + resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule, + API Gateway, or SNS topic. + languages: + - hcl + severity: ERROR + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + references: + - https://cwe.mitre.org/data/definitions/732.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission + - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + shortlink: https://sg.run/kOP7 + semgrep.dev: + rule: + r_id: 54772 + rv_id: 1263732 + rule_id: OrU9Ox + version_id: 1QTypq5 + url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn + origin: community +- id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + patterns: + - pattern: | + resource "aws_lambda_function" $ANYTHING { + ... + } + - pattern-not: | + resource "aws_lambda_function" $ANYTHING { + ... + tracing_config { + ... + mode = "Active" + ... + } + ... + } + message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray + tracing enables end-to-end debugging and analysis of all function activity. This + makes it easier to trace the flow of logs and identify bottlenecks, slow downs + and timeouts. + languages: + - hcl + severity: INFO + metadata: + category: security + technology: + - aws + - terraform + owasp: + - A09:2021 Security Logging and Monitoring Failures + cwe: + - 'CWE-778: Insufficient Logging' + references: + - https://cwe.mitre.org/data/definitions/778.html + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode + - https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insufficient Logging + source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + shortlink: https://sg.run/wO2Y + semgrep.dev: + rule: + r_id: 54773 + rv_id: 946713 + rule_id: eqUl1O + version_id: QkTZ6vk + url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active + origin: community +- id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + ObjectMapper $OM = new ObjectMapper(...); + ... + - pattern-inside: | + $OM.enableDefaultTyping(); + ... + - pattern: $OM.readValue($JSON, ...); + - patterns: + - pattern-inside: | + class $CLASS { + ... + @JsonTypeInfo(use = Id.CLASS,...) + $TYPE $VAR; + ... + } + - metavariable-regex: + metavariable: $TYPE + regex: (Object|Serializable|Comparable) + - pattern: $OM.readValue($JSON, $CLASS.class); + - patterns: + - pattern-inside: | + class $CLASS { + ... + ObjectMapper $OM; + ... + $INITMETHODTYPE $INITMETHOD(...) { + ... + $OM = new ObjectMapper(); + ... + $OM.enableDefaultTyping(); + ... + } + ... + } + - pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n" + - pattern: $OM.readValue($JSON, ...); + message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling + default typing is dangerous and can lead to RCE. If an attacker can control `$JSON` + it might be possible to provide a malicious JSON which can be used to exploit + unsecure deserialization. In order to prevent this issue, avoid to enable default + typing (globally or by using "Per-class" annotations) and avoid using `Object` + and other dangerous types for member variable declaration which creating classes + for Jackson based deserialization. + languages: + - java + severity: WARNING + metadata: + category: security + subcategory: + - audit + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + confidence: MEDIUM + likelihood: LOW + impact: HIGH + owasp: + - A8:2017 Insecure Deserialization + - A8:2021 Software and Data Integrity Failures + references: + - https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038 + - https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 + - https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/ + technology: + - jackson + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + shortlink: https://sg.run/GDop + semgrep.dev: + rule: + r_id: 56948 + rv_id: 945724 + rule_id: QrUD20 + version_id: 2KTYbA9 + url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + origin: community +- id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + shortlink: https://sg.run/Gj32 + semgrep.dev: + rule: + r_id: 59048 + rv_id: 1263061 + rule_id: j2Udpk + version_id: YDTZeko + url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + origin: community + message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` + and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - + The previous links are not meant to be clicked. They are the literal config key + values that are supposed to be used to disable these features. For more information, + see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = SAXParserFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = SAXParserFactory.newInstance(); + static { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newSAXParser(); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + - pattern: | + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", + true); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + ... + $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); + $FACTORY.newSAXParser(); + languages: + - java +- id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + category: security + technology: + - java + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + shortlink: https://sg.run/1wyQ + semgrep.dev: + rule: + r_id: 59622 + rv_id: 1263062 + rule_id: v8UeQ1 + version_id: 6xT29GK + url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + origin: community + message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable + to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" + and "accessExternalStylesheet" to "". + mode: taint + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: | + $FACTORY = TransformerFactory.newInstance(); + - patterns: + - pattern: $FACTORY + - pattern-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern-not-inside: | + class $C { + ... + $V $FACTORY = TransformerFactory.newInstance(); + static { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + pattern-sinks: + - patterns: + - pattern: $FACTORY.newTransformer(...); + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + - pattern: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + - pattern: | + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); + ... + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + } + ... + } + - pattern-inside: | + class $C { + ... + $T $M(...) { + ... + $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); + ... + $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); + ... + } + ... + } + - pattern: $M($X) + - focus-metavariable: $X + fix: | + $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); + $FACTORY.newTransformer(...); + languages: + - java +- id: java.android.security.exported_activity.exported_activity + patterns: + - pattern-not-inside: + - pattern-inside: " \n" + - pattern-either: + - pattern: | + + - pattern: | + ... /> + message: The application exports an activity. Any application on the device can + launch the exported activity which may compromise the integrity of your application + or its data. Ensure that any exported activities do not have privileged access + to your application's control plane. + languages: + - generic + severity: WARNING + paths: + exclude: + - sources/ + - classes3.dex + - '*.so' + include: + - '*AndroidManifest.xml' + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-926: Improper Export of Android Application Components' + confidence: MEDIUM + likelihood: MEDIUM + impact: MEDIUM + owasp: + - A5:2021 Security Misconfiguration + technology: + - Android + references: + - https://cwe.mitre.org/data/definitions/926.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity + shortlink: https://sg.run/eNGZ + semgrep.dev: + rule: + r_id: 60632 + rv_id: 945629 + rule_id: v8Ul0r + version_id: rxT6rGR + url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity + origin: community +- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + patterns: + - pattern: | + RUN sudo ... + message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can + help reduce the potential impact of configuration errors and security vulnerabilities. + metadata: + category: security + technology: + - dockerfile + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/250.html + - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + shortlink: https://sg.run/80Q7 + semgrep.dev: + rule: + r_id: 66384 + rv_id: 1262661 + rule_id: kxUlx1 + version_id: pZT03zY + url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + origin: community + languages: + - dockerfile + severity: WARNING +- id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + message: Potentially sensitive data was observed to be stored in UserDefaults, which + is not adequate protection of sensitive information. For data of a sensitive nature, + applications should leverage the Keychain. + severity: WARNING + metadata: + likelihood: LOW + impact: HIGH + confidence: MEDIUM + category: security + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + masvs: + - 'MASVS-STORAGE-1: The app securely stores sensitive data' + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html + - https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/ + subcategory: + - vuln + technology: + - ios + - macos + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + shortlink: https://sg.run/qvoO + semgrep.dev: + rule: + r_id: 66512 + rv_id: 1263696 + rule_id: KxUqoZ + version_id: 3ZT4Xy2 + url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + origin: community + languages: + - swift + options: + symbolic_propagation: true + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: "$KEY") + - pattern: | + UserDefaults.standard.set("$VALUE", forKey: $KEY) + - pattern: | + UserDefaults.standard.set($VALUE, forKey: "$KEY") + - pattern: | + UserDefaults.standard.set($VALUE, forKey: $KEY) + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $KEY +- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + message: Detected input from a HTTPServletRequest going into the environment variables + of an 'exec' command. Instead, call the command with user-supplied arguments + by using the overloaded method with one String array as the argument. `exec({"command", + "arg1", "arg2"})`. + languages: + - java + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + pattern-sinks: + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); + - focus-metavariable: $ENV_ARGS + metadata: + category: security + technology: + - java + cwe: + - 'CWE-454: External Initialization of Trusted Variables or Data Stores' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: false + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + shortlink: https://sg.run/EJAB + semgrep.dev: + rule: + r_id: 70981 + rv_id: 1409391 + rule_id: nJULjy + version_id: LjTRL6W + url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + origin: community +- patterns: + - pattern-either: + - pattern: | + provisioner "remote-exec" { + ... + } + - pattern: | + provisioner "local-exec" { + ... + } + - pattern-inside: | + resource "aws_instance" "..." { + ... + } + id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + message: Provisioners are a tool of last resort and should be avoided where possible. + Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute + arbitrary shell commands by design. + languages: + - terraform + severity: WARNING + metadata: + category: security + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command + Injection'')' + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + subcategory: + - audit + confidence: HIGH + likelihood: HIGH + impact: MEDIUM + technology: + - terraform + references: + - https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec + - https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + - Other + source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + shortlink: https://sg.run/7EjQ + semgrep.dev: + rule: + r_id: 70982 + rv_id: 1263736 + rule_id: EwUxO1 + version_id: bZT53j1 + url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec + origin: community +- id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + metadata: + category: security + subcategory: + - audit + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + technology: + - terraform + - aws + owasp: + - A05:2017 - Sensitive Data Exposure + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + references: + - https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy + - https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + shortlink: https://sg.run/LWlY + semgrep.dev: + rule: + r_id: 70983 + rv_id: 1263748 + rule_id: 7KU3dr + version_id: 7ZTE346 + url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy + origin: community + message: '`$POLICY` is missing a `condition` block which scopes users of this policy + to specific GitHub repositories. Without this, `$POLICY` is open to all users + on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub` + which scopes it to prevent this.' + languages: + - hcl + severity: WARNING + match: + where: + - metavariable: $IDENTIFIER + regex: .*oidc-provider/token\.actions\.githubusercontent\.com + all: + - inside: | + data "aws_iam_policy_document" $POLICY { + ... + } + - | + statement { + ... + principals { + ... + type = "Federated" + identifiers = [..., $IDENTIFIER, ...] + } + } + - not: | + statement { + ... + condition { + ... + variable = "token.actions.githubusercontent.com:sub" + } + } +- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + languages: + - clojure + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://xerces.apache.org/xerces2-j/features.html + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml + category: security + technology: + - clojure + - xml + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + shortlink: https://sg.run/v7An + semgrep.dev: + rule: + r_id: 71533 + rv_id: 1262608 + rule_id: bwU3Gj + version_id: WrTqKyD + url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + origin: community + message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. + Without prohibiting external entity declarations, this is vulnerable to XML external + entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" + to true. Alternatively, allow DOCTYPE declarations and only prohibit external + entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" + and "http://xml.org/sax/features/external-parameter-entities" to false. + patterns: + - pattern-inside: | + (ns ... (:require [clojure.xml :as ...])) + ... + - pattern-either: + - pattern-inside: | + (def ... ... ( ... )) + - pattern-inside: | + (defn ... ... ( ... )) + - pattern-either: + - pattern: (clojure.xml/parse $INPUT) + - patterns: + - pattern-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) + - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" + false) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ...) + - pattern-not-inside: | + (doto (javax.xml.parsers.SAXParserFactory/newInstance) + ... + (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) + ... + (.setFeature "http://xml.org/sax/features/external-general-entities" false) + ...) +- id: clojure.lang.security.use-of-sha1.use-of-sha1 + languages: + - clojure + severity: WARNING + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function + applications. + metadata: + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + technology: + - clojure + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-328: Use of Weak Hash' + category: security + subcategory: + - vuln + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/dvwX + semgrep.dev: + rule: + r_id: 71534 + rv_id: 1262610 + rule_id: NbUy12 + version_id: K3TKk7E + url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 + origin: community + patterns: + - pattern-either: + - pattern: (MessageDigest/getInstance $ALGO) + - pattern: (java.security.MessageDigest/getInstance $ALGO) + - metavariable-regex: + metavariable: $ALGO + regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) +- id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs + languages: + - generic + severity: WARNING + message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose + your application and its users to compromised code. SRIs allow you to consume + specific versions of content where if even a single byte is compromised, the resource + will not be loaded. Add an integrity attribute to your + - pattern-not: + paths: + include: + - '*.component' + - '*.page' +- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + languages: + - generic + severity: INFO + message: Visualforce Pages must have the cspHeader attribute set to true. This attribute + is available in API version 55 or higher. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + shortlink: https://sg.run/yoj8 + semgrep.dev: + rule: + r_id: 72424 + rv_id: 1262907 + rule_id: DbUj7d + version_id: RGT0L0r + url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + origin: community + patterns: + - pattern: ... + - pattern-not: ... + - pattern-not: ...... + - pattern-not: ...... + paths: + include: + - '*.page' +- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + languages: + - generic + severity: WARNING + message: Visualforce Pages must use API version 55 or higher for required use of + the cspHeader attribute set to true. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm + category: security + subcategory: + - vuln + technology: + - salesforce + - visualforce + cwe2022-top25: true + cwe2021-top25: true + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + shortlink: https://sg.run/rWr6 + semgrep.dev: + rule: + r_id: 72425 + rv_id: 1262908 + rule_id: WAUwJW + version_id: A8Tgdgn + url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + origin: community + patterns: + - pattern-inside: + - pattern-either: + - pattern-regex: '[>][0-9].[0-9][<]' + - pattern-regex: '[>][1-4][0-9].[0-9][<]' + - pattern-regex: '[>][5][0-4].[0-9][<]' + paths: + include: + - '*.page-meta.xml' +- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret + languages: + - python + message: The Django secret key is used as salt in HashIDs. The HashID mechanism + is not secure. By observing sufficient HashIDs, the salt used to construct them + can be recovered. This means the Django secret key can be obtained by attackers, + through the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - django + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret + shortlink: https://sg.run/bxeZ + semgrep.dev: + rule: + r_id: 72426 + rv_id: 946163 + rule_id: 0oUXqy + version_id: 0bT15nn + url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) + - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) + severity: ERROR +- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + languages: + - python + message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is + not secure. By observing sufficient HashIDs, the salt used to construct them can + be recovered. This means the Flask secret key can be obtained by attackers, through + the HashIDs. + metadata: + category: security + subcategory: + - vuln + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - "A02:2021 \u2013 Cryptographic Failures" + references: + - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + technology: + - flask + likelihood: LOW + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + shortlink: https://sg.run/N0Rx + semgrep.dev: + rule: + r_id: 72427 + rv_id: 946220 + rule_id: KxUX3z + version_id: 0bT15Px + url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + origin: community + pattern-either: + - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) + - patterns: + - pattern-inside: | + $APP = flask.Flask(...) + ... + - pattern-either: + - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) + severity: ERROR +- id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + references: + - https://docs.python.org/3/library/xml.html + - https://github.com/tiran/defusedxml + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + category: security + technology: + - python + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + shortlink: https://sg.run/n3jG + semgrep.dev: + rule: + r_id: 72436 + rv_id: 1263541 + rule_id: X5Uqnx + version_id: vdT06ER + url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + origin: community + message: The native Python `xml` library is vulnerable to XML External Entity (XXE) + attacks. These attacks can leak confidential data and "XML bombs" can cause denial + of service. Do not use this library to parse untrusted input. Instead the Python + documentation recommends using `defusedxml`. + languages: + - python + severity: ERROR + patterns: + - pattern: xml.etree.ElementTree.parse($...ARGS) + - pattern-not: xml.etree.ElementTree.parse("...") + fix: defusedxml.etree.ElementTree.parse($...ARGS) +- id: php.lang.security.tainted-exec.tainted-exec + mode: taint + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + pattern-sinks: + - pattern: exec(...) + - pattern: system(...) + - pattern: popen(...) + - pattern: passthru(...) + - pattern: shell_exec(...) + - pattern: pcntl_exec(...) + - pattern: proc_open(...) + pattern-sanitizers: + - pattern: escapeshellarg(...) + message: Executing non-constant commands. This can lead to command injection. You + should use `escapeshellarg()` when using command. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + references: + - https://www.stackhawk.com/blog/php-command-injection/ + - https://brightsec.com/blog/code-injection-php/ + - https://www.acunetix.com/websitesecurity/php-security-2/ + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + cwe2022-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec + shortlink: https://sg.run/JAkP + semgrep.dev: + rule: + r_id: 73146 + rv_id: 1263300 + rule_id: 9AUw06 + version_id: BjTkZ4y + url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec + origin: community + languages: + - php + severity: ERROR +- id: php.lang.security.injection.tainted-session.tainted-session + severity: WARNING + message: Session key based on user input risks session poisoning. The user can determine + the key used for the session, and thus write any session variable. Session variables + are typically trusted to be set only by the application, and manipulating the + session can result in access control issues. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-284: Improper Access Control' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://en.wikipedia.org/wiki/Session_poisoning + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session + shortlink: https://sg.run/bxNp + semgrep.dev: + rule: + r_id: 73470 + rv_id: 1263289 + rule_id: 4bUdoP + version_id: 8KT5rPE + url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $A . $B + - pattern: bin2hex(...) + - pattern: crc32(...) + - pattern: crypt(...) + - pattern: filter_input(...) + - pattern: filter_var(...) + - pattern: hash(...) + - pattern: md5(...) + - pattern: preg_filter(...) + - pattern: preg_grep(...) + - pattern: preg_match_all(...) + - pattern: sha1(...) + - pattern: sprintf(...) + - pattern: str_contains(...) + - pattern: str_ends_with(...) + - pattern: str_starts_with(...) + - pattern: strcasecmp(...) + - pattern: strchr(...) + - pattern: stripos(...) + - pattern: stristr(...) + - pattern: strnatcasecmp(...) + - pattern: strnatcmp(...) + - pattern: strncmp(...) + - pattern: strpbrk(...) + - pattern: strpos(...) + - pattern: strripos(...) + - pattern: strrpos(...) + - pattern: strspn(...) + - pattern: strstr(...) + - pattern: strtok(...) + - pattern: substr_compare(...) + - pattern: substr_count(...) + - pattern: vsprintf(...) + pattern-sinks: + - patterns: + - pattern-inside: $_SESSION[$KEY] = $VAL; + - pattern: $KEY +- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + patterns: + - pattern: | + "*" + - pattern-inside: | + resources: $A + ... + - pattern-inside: | + verbs: $A + ... + - pattern-inside: | + - apiGroups: [""] + ... + - pattern-inside: | + apiVersion: rbac.authorization.k8s.io/v1 + ... + - pattern-inside: | + kind: ClusterRole + ... + message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. + Attaching excessive permissions to a ClusterRole associated with the core namespace + allows the V1 API to perform arbitrary actions on arbitrary resources attached + to the cluster. Prefer explicit allowlists of verbs/resources when configuring + the core API namespace. ' + languages: + - yaml + severity: WARNING + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole + - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups + category: security + technology: + - kubernetes + cwe2021-top25: false + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + shortlink: https://sg.run/x6Dz + semgrep.dev: + rule: + r_id: 73474 + rv_id: 1263935 + rule_id: GdUR2A + version_id: 9lT4bw7 + url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + origin: community +- id: python.fastapi.security.wildcard-cors.wildcard-cors + languages: + - python + message: CORS policy allows any origin (using wildcard '*'). This is insecure and + should be avoided. + mode: taint + pattern-sources: + - pattern: '[..., "*", ...]' + pattern-sinks: + - patterns: + - pattern: | + $APP.add_middleware( + CORSMiddleware, + allow_origins=$ORIGIN, + ...); + - focus-metavariable: $ORIGIN + severity: WARNING + metadata: + cwe: + - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + category: security + technology: + - python + - fastapi + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + - https://cwe.mitre.org/data/definitions/942.html + likelihood: HIGH + impact: LOW + confidence: MEDIUM + vulnerability_class: + - Configuration + subcategory: + - vuln + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors + shortlink: https://sg.run/KxApY + semgrep.dev: + rule: + r_id: 112311 + rv_id: 1263413 + rule_id: lBU4JQ3 + version_id: A8Tgd1R + url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors + origin: community +- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + message: Detected the decoding of a JWT token without a verify step. JWT tokens + must be verified before use, otherwise the token's integrity is unknown. This + means a malicious actor could forge a JWT token with any claims. Set 'verify' + to `true` before using the token. + severity: ERROR + metadata: + owasp: + - A05:2021 - Security Misconfiguration + - A07:2021 - Identification and Authentication Failures + - A02:2025 - Security Misconfiguration + - A07:2025 - Authentication Failures + cwe: + - 'CWE-287: Improper Authentication' + - 'CWE-345: Insufficient Verification of Data Authenticity' + - 'CWE-347: Improper Verification of Cryptographic Signature' + category: security + subcategory: + - vuln + technology: + - jwt-simple + - jwt + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + references: + - https://www.npmjs.com/package/jwt-simple + - https://cwe.mitre.org/data/definitions/287 + - https://cwe.mitre.org/data/definitions/345 + - https://cwe.mitre.org/data/definitions/347 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Improper Authentication + source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + shortlink: https://sg.run/zdjod + semgrep.dev: + rule: + r_id: 120561 + rv_id: 1263191 + rule_id: r6UyNLy + version_id: 3ZT4Xxv + url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + origin: community + languages: + - javascript + - typescript + patterns: + - pattern-inside: | + $JWT = require('jwt-simple'); + ... + - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) + - metavariable-pattern: + metavariable: $NOVERIFY + patterns: + - pattern-either: + - pattern: | + true + - pattern: | + "..." +- id: php.lang.security.injection.printed-request.printed-request + mode: taint + message: '`Printing user input risks cross-site scripting vulnerability. You should + use `htmlentities()` when showing data to users.' + languages: + - php + severity: ERROR + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + pattern-sinks: + - pattern: print($...VARS); + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + fix: print(htmlentities($...VARS)); + metadata: + technology: + - php + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request + shortlink: https://sg.run/QrxEJ + semgrep.dev: + rule: + r_id: 128886 + rv_id: 1263284 + rule_id: KxUvRBw + version_id: ZRTKAk4 + url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request + origin: community +- id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + patterns: + - pattern-inside: | + &sessions.Options{ + ..., + SameSite: http.SameSiteNoneMode, + ..., + } + - pattern: | + &sessions.Options{ + ..., + } + message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting + SameSite to Lax, Strict or Default for enhanced security. + metadata: + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://pkg.go.dev/github.com/gorilla/sessions#Options + category: security + technology: + - gorilla + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + shortlink: https://sg.run/x8Nwj + semgrep.dev: + rule: + r_id: 133074 + rv_id: 1262913 + rule_id: YGUpGd4 + version_id: K3TKkKB + url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + origin: community + fix-regex: + regex: (SameSite\s*:\s+)http.SameSiteNoneMode + replacement: \1http.SameSiteDefaultMode + severity: WARNING + languages: + - go +- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + languages: + - solidity + message: Missing check for 'from' and 'to' being the same before updating balances + could lead to incorrect balance manipulation on self-transfers. Include a check + to ensure 'from' and 'to' are not the same before updating balances to prevent + balance manipulation during self-transfers. + severity: ERROR + metadata: + category: security + technology: + - blockchain + - solidity + cwe: 'CWE-682: Incorrect Calculation' + subcategory: + - vuln + confidence: HIGH + likelihood: HIGH + impact: HIGH + owasp: + - A7:2021 Identification and Authentication Failures + references: + - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities + - https://x.com/shoucccc/status/1757777764646859121 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + shortlink: https://sg.run/Or6X7 + semgrep.dev: + rule: + r_id: 133075 + rv_id: 946620 + rule_id: 6JUv7Nz + version_id: A8TJzYz + url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + origin: community + patterns: + - pattern-either: + - pattern: | + _balances[$FROM] = $FROM_BALANCE - value; + - pattern: | + _balances[$TO] = $TO_BALANCE + value; + - pattern-not-inside: | + if ($FROM != $TO) { + ... + _balances[$FROM] = $FROM_BALANCE - value; + ... + _balances[$TO] = $TO_BALANCE + value; + ... + } + - pattern-inside: | + function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual { + ... + } +- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + languages: + - yaml + message: Basic authentication is considered weak and should be avoided. Use a different + authentication scheme, such of OAuth2, OpenID Connect, or mTLS. + severity: ERROR + patterns: + - pattern-inside: | + openapi: $VERSION + ... + components: + ... + securitySchemes: + ... + $SCHEME: + ... + - metavariable-regex: + metavariable: $VERSION + regex: 3.* + - pattern: | + type: http + ... + scheme: basic + metadata: + category: security + subcategory: + - vuln + technology: + - openapi + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + cwe: 'CWE-287: Improper Authentication' + owasp: + - A04:2021 Insecure Design + - A07:2021 Identification and Authentication Failures + references: + - https://cwe.mitre.org/data/definitions/287.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + shortlink: https://sg.run/v8wNW + semgrep.dev: + rule: + r_id: 133077 + rv_id: 947072 + rule_id: zdUKgEX + version_id: 0bT1ErG + url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + origin: community +- id: python.twilio.security.twiml-injection.twiml-injection + languages: + - python + severity: WARNING + message: Using non-constant TwiML (Twilio Markup Language) argument when creating + a Twilio conversation could allow the injection of additional TwiML commands + metadata: + cwe: + - 'CWE-91: XML Injection' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - python + - twilio + - twiml + confidence: MEDIUM + likelihood: HIGH + impact: MEDIUM + subcategory: + - vuln + references: + - https://codeberg.org/fennix/funjection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection + shortlink: https://sg.run/GdEEy + semgrep.dev: + rule: + r_id: 134692 + rv_id: 1263580 + rule_id: oqUgjj2 + version_id: kbTzGp1 + url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection + origin: community + mode: taint + pattern-sources: + - pattern: | + f"..." + - pattern: | + "..." % ... + - pattern: | + "...".format(...) + - patterns: + - pattern: $ARG + - pattern-inside: | + def $F(..., $ARG, ...): + ... + pattern-sanitizers: + - pattern: xml.sax.saxutils.escape(...) + - pattern: html.escape(...) + pattern-sinks: + - patterns: + - pattern: | + $CLIENT.calls.create(..., twiml=$SINK, ...) + - focus-metavariable: $SINK +- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + message: A secret is hard-coded in the application. Secrets stored in source code, + such as credentials, identifiers, and other types of sensitive data, can be leaked + and used by internal or external malicious actors. It is recommended to rotate + the secret and retrieve them from a secure secret vault or Hardware Security Module + (HSM), alternatively environment variables can be used if allowed by your company + policy. + severity: WARNING + metadata: + likelihood: LOW + impact: HIGH + confidence: MEDIUM + category: security + subcategory: + - vuln + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2020-top25: true + cwe2021-top25: true + cwe2022-top25: true + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + technology: + - secrets + vulnerability_class: + - Hard-coded Secrets + source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + shortlink: https://sg.run/qN29x + semgrep.dev: + rule: + r_id: 137856 + rv_id: 1263257 + rule_id: ReUD6Kg + version_id: DkTRbLX + url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + origin: community + languages: + - kotlin + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: '$PASS = env[...] ?: $VALUE' + - metavariable-regex: + metavariable: $PASS + regex: (password|pass|passwd|loginPassword) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^[A-Za-z0-9/+=]+$ + paths: + include: + - '*build.gradle.kts' +- id: php.lang.security.injection.tainted-callable.tainted-callable + severity: WARNING + message: Callable based on user input risks remote code execution. + metadata: + technology: + - php + category: security + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/language.types.callable.php + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable + shortlink: https://sg.run/YGb33 + semgrep.dev: + rule: + r_id: 141958 + rv_id: 1263285 + rule_id: 0oULBKK + version_id: nWT2L5x + url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable + origin: community + languages: + - php + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + pattern-sinks: + - patterns: + - pattern: $CALLABLE + - pattern-either: + - pattern-inside: $ARRAYITERATOR->uasort($CALLABLE) + - pattern-inside: $ARRAYITERATOR->uksort($CALLABLE) + - pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...) + - pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...) + - pattern-inside: $EVLOOP->fork($CALLABLE, ...) + - pattern-inside: $EVLOOP->idle($CALLABLE, ...) + - pattern-inside: $EVLOOP->prepare($CALLABLE, ...) + - pattern-inside: $EVWATCHER->setCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE) + - pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE) + - pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE) + - pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE) + - pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE) + - pattern-inside: $SQLITE3->setAuthorizer($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE) + - pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...) + - pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...) + - pattern-inside: apcu_entry($KEY, $CALLABLE, ...) + - pattern-inside: array_filter($ARRAY, $CALLABLE, ...) + - pattern-inside: array_map($CALLABLE, ...) + - pattern-inside: array_reduce($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk($ARRAY, $CALLABLE, ...) + - pattern-inside: call_user_func_array($CALLABLE, ...) + - pattern-inside: call_user_func($CALLABLE, ...) + - pattern-inside: Closure::fromCallable($CALLABLE) + - pattern-inside: createCollation($NAME, $CALLABLE) + - pattern-inside: eio_grp($CALLABLE, ...) + - pattern-inside: eio_nop($PRI, $CALLABLE, ...) + - pattern-inside: eio_sync($PRI, $CALLABLE, ...) + - pattern-inside: EvPrepare::createStopped($CALLABLE, ...) + - pattern-inside: fann_set_callback($ANN, $CALLABLE) + - pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...) + - pattern-inside: forward_static_call_array($CALLABLE, ...) + - pattern-inside: forward_static_call($CALLABLE, ...) + - pattern-inside: header_register_callback($CALLABLE) + - pattern-inside: ibase_set_event_handler($CALLABLE, ...) + - pattern-inside: IntlChar::enumCharTypes($CALLABLE) + - pattern-inside: iterator_apply($ITERATOR, $CALLABLE) + - pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE) + - pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...) + - pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new EvCheck($CALLABLE, ...) + - pattern-inside: new EventHttpRequest($CALLABLE, ...) + - pattern-inside: new EvFork($CALLABLE, ...) + - pattern-inside: new EvIdle($CALLABLE, ...) + - pattern-inside: new Fiber($CALLABLE) + - pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...) + - pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new Zookeeper($HOST, $CALLABLE, ...) + - pattern-inside: ob_start($CALLABLE, ...) + - pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE) + - pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE) + - pattern-inside: readline_completion_function($CALLABLE) + - pattern-inside: register_shutdown_function($CALLABLE, ...) + - pattern-inside: register_tick_function($CALLABLE, ...) + - pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE) + - pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...) + - pattern-inside: set_error_handler($CALLABLE, ...) + - pattern-inside: set_exception_handler($CALLABLE) + - pattern-inside: setAuthorizer($CALLABLE) + - pattern-inside: spl_autoload_register($CALLABLE, ...) + - pattern-inside: uasort($ARRAY, $CALLABLE) + - pattern-inside: uksort($ARRAY, $CALLABLE) + - pattern-inside: usort($ARRAY, $CALLABLE) + - pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_default_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE) + - pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE) + - pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...) +- id: javascript.node-crypto.security.aead-no-final.aead-no-final + message: The 'final' call of a Decipher object checks the authentication tag in + a mode for authenticated encryption. Failing to call 'final' will invalidate all + integrity guarantees of the released ciphertext. + metadata: + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final + shortlink: https://sg.run/r6EEA + semgrep.dev: + rule: + r_id: 146569 + rv_id: 1263222 + rule_id: 2ZUz884 + version_id: zyTb2X0 + url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.update(...) + - pattern-not-inside: | + $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) + ... + $DECIPHER.final(...) + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ +- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode + of operation is missing an expected authentication tag length. If the expected + authentication tag length is not specified or otherwise checked, the application + might be tricked into verifying a shorter-than-expected authentication tag. This + can be abused by an attacker to spoof ciphertexts or recover the implicit authentication + key of GCM, allowing arbitrary forgeries. + metadata: + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + category: security + subcategory: + - vuln + technology: + - node-crypto + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + references: + - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ + - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + shortlink: https://sg.run/NbGG1 + semgrep.dev: + rule: + r_id: 146571 + rv_id: 1263223 + rule_id: j2UgPP3 + version_id: pZT03qd + url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern: | + $CRYPTO.createDecipheriv('$ALGO', $KEY, $IV) + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm)$ +- id: php.lang.security.injection.tainted-exec.tainted-exec + languages: + - php + severity: WARNING + message: User input is passed to a function that executes a shell command. This + can lead to remote code execution. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + category: security + technology: + - php + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + impact: HIGH + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec + shortlink: https://sg.run/kxEEz + semgrep.dev: + rule: + r_id: 146572 + rv_id: 1263286 + rule_id: 10UOGG5 + version_id: ExTExyR + url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: escapeshellcmd(...) + - pattern: escapeshellarg(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: exec(...) + - pattern: system(...) + - pattern: passthru(...) + - patterns: + - pattern: proc_open(...) + - pattern-not: proc_open([...], ...) + - pattern: popen(...) + - pattern: expect_popen(...) + - pattern: shell_exec(...) + - pattern: | + `...` +- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + languages: + - yaml + message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method: + $METHOD $PATH. This Action configuration will enable the ''Always Allow'' option + for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk + of a user selecting the ''Always Allow'' button is that the agent could perform + unintended actions on behalf of the user. When working with sensitive functionality, + it is always best to include a Human In The Loop (HITL) type of control. Consider + the trade-off between security and user friction and then make a risk-based decision + about this function.' + severity: WARNING + pattern-either: + - pattern-inside: | + post: + ... + x-openai-isConsequential: false + - pattern-inside: | + put: + ... + x-openai-isConsequential: false + - pattern-inside: | + patch: + ... + x-openai-isConsequential: false + - pattern-inside: | + delete: + ... + x-openai-isConsequential: false + metadata: + category: security + subcategory: + - audit + technology: + - openapi + - openai + likelihood: HIGH + impact: HIGH + confidence: HIGH + cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' + owasp: + - A04:2021 Insecure Design + - LLM08:2023 - Excessive Agency + references: + - https://platform.openai.com/docs/actions/consequential-flag + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + shortlink: https://sg.run/x8EEP + semgrep.dev: + rule: + r_id: 146574 + rv_id: 947071 + rule_id: yyURooD + version_id: WrTEZN8 + url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + origin: community +- id: python.lang.security.insecure-uuid-version.insecure-uuid-version + patterns: + - pattern: uuid.uuid1(...) + message: Using UUID version 1 for UUID generation can lead to predictable UUIDs + based on system information (e.g., MAC address, timestamp). This may lead to security + risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better + randomness and security. + metadata: + references: + - https://www.landh.tech/blog/20230811-sandwich-attack/ + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.3.2 Insecure UUID Generation + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values + version: '4' + category: security + technology: + - python + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version + shortlink: https://sg.run/BYBgW + semgrep.dev: + rule: + r_id: 148295 + rv_id: 1263539 + rule_id: kxUd1yD + version_id: O9Tpx97 + url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version + origin: community + languages: + - python + severity: WARNING + fix-regex: + regex: uuid1 + replacement: uuid4 +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + pattern-either: + - patterns: + - pattern-inside: | + import "crypto/sha256" + ... + - pattern-either: + - pattern: | + sha256.New224() + - pattern: | + sha256.Sum224(...) + - patterns: + - pattern-inside: | + import "golang.org/x/crypto/sha3" + ... + - pattern-either: + - pattern: | + sha3.New224() + - pattern: | + sha3.Sum224(...) + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + category: security + technology: + - go + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + shortlink: https://sg.run/ReJwY + semgrep.dev: + rule: + r_id: 151749 + rv_id: 1262925 + rule_id: GdUvElR + version_id: 9lT4b4w + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + origin: community +- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + languages: + - java + severity: WARNING + metadata: + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + shortlink: https://sg.run/Ab2KQ + semgrep.dev: + rule: + r_id: 151750 + rv_id: 1263017 + rule_id: ReUDGEz + version_id: YDTZewo + url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + origin: community + pattern-either: + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) + - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) + - patterns: + - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: php.lang.security.audit.sha224-hash.sha224-hash + pattern-either: + - pattern: hash('sha224', ...); + - pattern: hash('sha512/224', ...); + - pattern: hash('sha3-224', ...); + - pattern: hash_hmac('sha224', ...); + - pattern: hash_hmac('sha512/224', ...); + - pattern: hash_hmac('sha3-224', ...); + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - php + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/BYXqv + semgrep.dev: + rule: + r_id: 151751 + rv_id: 1263275 + rule_id: AbU97EA + version_id: bZT53Jo + url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - php + severity: WARNING +- id: python.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - python + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/Db1Yv + semgrep.dev: + rule: + r_id: 151752 + rv_id: 1263511 + rule_id: BYUX0y9 + version_id: 5PTo1QL + url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash + origin: community + severity: WARNING + languages: + - python + pattern-either: + - pattern: hashlib.sha224(...) + - pattern: hashlib.sha3_224(...) +- id: ruby.lang.security.audit.sha224-hash.sha224-hash + message: This code uses a 224-bit hash function, which is deprecated or disallowed + in some security policies. Consider updating to a stronger hash function such + as SHA-384 or higher to ensure compliance and security. + metadata: + cwe: + - 'CWE-328: Use of Weak Hash' + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + category: security + technology: + - ruby + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash + shortlink: https://sg.run/WABbo + semgrep.dev: + rule: + r_id: 151753 + rv_id: 1263592 + rule_id: DbU60wQ + version_id: 8KT5rRY + url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash + origin: community + languages: + - ruby + severity: WARNING + pattern-either: + - pattern: Digest::SHA224.$FUNC + - pattern: OpenSSL::Digest::SHA224.$FUNC + - pattern: SHA3::Digest::SHA224(...) + - patterns: + - pattern-either: + - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) + - pattern: OpenSSL::HMAC.digest("$ALGO", ...) + - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") + - pattern: OpenSSL::Digest.digest("$ALGO", ...) + - pattern: OpenSSL::Digest.new("$ALGO", ...) + - metavariable-regex: + metavariable: $ALGO + regex: .*224 +- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + patterns: + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + database_version = "$DB" + ... + } + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = $VALUE + ... + } + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" + ... + } + ... + } + - metavariable-regex: + metavariable: $DB + regex: .*(MYSQL|POSTGRES).* + - focus-metavariable: $VALUE + fix: | + "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" + message: Ensure all Cloud SQL database instance require incoming connections to + use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + shortlink: https://sg.run/WANR2 + semgrep.dev: + rule: + r_id: 153509 + rv_id: 1263874 + rule_id: 5rUdGAz + version_id: 2KTv22E + url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + origin: community + languages: + - hcl + severity: WARNING +- id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + patterns: + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + database_version = "$DB" + ... + } + - pattern-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = $VALUE + ... + } + ... + } + - pattern-not-inside: | + resource "google_sql_database_instance" "..." { + ... + ip_configuration { + ... + ssl_mode = "ENCRYPTED_ONLY" + ... + } + ... + } + - metavariable-regex: + metavariable: $DB + regex: .*(SQLSERVER).* + - focus-metavariable: $VALUE + fix: | + "ENCRYPTED_ONLY" + message: Ensure all Cloud SQL database instance require incoming connections to + use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value + that is supported. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - gcp + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + shortlink: https://sg.run/0o92j + semgrep.dev: + rule: + r_id: 153510 + rv_id: 1263875 + rule_id: GdUvX6A + version_id: X0Tzyyl + url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + origin: community + languages: + - hcl + severity: WARNING +- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + message: Function `flask.url_for` with `_external=True` argument will generate URLs + using the `Host` header of the HTTP request, which may lead to security risks + such as Host header injection + metadata: + cwe: + - 'CWE-673: External Influence of Sphere Definition' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - flask + references: + - https://flask.palletsprojects.com/en/latest/api/#flask.url_for + - https://portswigger.net/kb/issues/00500300_host-header-injection + subcategory: + - audit + likelihood: MEDIUM + impact: LOW + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + shortlink: https://sg.run/gEGeR + semgrep.dev: + rule: + r_id: 191541 + rv_id: 1263418 + rule_id: JDU5oql + version_id: K3TKk6n + url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + origin: community + languages: + - python + severity: WARNING + patterns: + - pattern-not: flask.url_for(..., _external=False, ...) + - pattern-not: url_for(..., _external=False, ...) + - pattern-either: + - pattern: flask.url_for(..., _external=$VAR, ...) + - pattern: url_for(..., _external=$VAR, ...) +- id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + languages: + - php + severity: WARNING + message: Detected usage of vulnerable functions with user input, which could lead + to SSRF vulnerabilities. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_POST[...] + - pattern: $_REQUEST[...] + - pattern: get_option(...) + - pattern: get_user_meta(...) + - pattern: get_query_var(...) + pattern-sinks: + - patterns: + - focus-metavariable: $URL + - pattern-either: + - pattern: wp_remote_get($URL, ...) + - pattern: wp_safe_remote_get($URL, ...) + - pattern: wp_safe_remote_request($URL, ...) + - pattern: wp_safe_remote_head($URL, ...) + - pattern: wp_oembed_get($URL, ...) + - pattern: vip_safe_wp_remote_get($URL, ...) + - pattern: wp_safe_remote_post($URL, ...) + paths: + include: + - '**/wp-content/plugins/**/*.php' + metadata: + cwe: 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: A10:2021 - Server-Side Request Forgery (SSRF) + category: security + confidence: MEDIUM + likelihood: MEDIUM + impact: HIGH + subcategory: + - audit + technology: + - Wordpress Plugins + references: + - https://developer.wordpress.org/reference/functions/wp_safe_remote_get/ + - https://developer.wordpress.org/reference/functions/wp_remote_get/ + - https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/ + vulnerability_class: + - Server-Side Request Forgery (SSRF) + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + shortlink: https://sg.run/K3y06 + semgrep.dev: + rule: + r_id: 191611 + rv_id: 1039233 + rule_id: 6JUZyKX + version_id: JdTp6rq + url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + origin: community +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action + with the name `discussion.yaml`. + paths: + include: + - '**/.github/workflows/discussion.yaml' + metadata: + category: security + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + technology: + - github-actions + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + shortlink: https://sg.run/JdYPZ + semgrep.dev: + rule: + r_id: 238946 + rv_id: 1263927 + rule_id: 7KUDRPj + version_id: 6xT29ol + url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, + which can lead to security vulnerabilities (CWE-502). Use a concrete struct type + instead. + severity: WARNING + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + category: security + technology: + - go + confidence: HIGH + likelihood: MEDIUM + impact: HIGH + subcategory: + - vuln + references: + - https://cwe.mitre.org/data/definitions/502.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + shortlink: https://sg.run/6WbKL + semgrep.dev: + rule: + r_id: 274359 + rv_id: 1409387 + rule_id: 4bUAQDG + version_id: ZRTDkjk + url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + origin: community + patterns: + - pattern-either: + - pattern: | + var $VAR interface{} + ... + json.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + yaml.Unmarshal($DATA, &$VAR) + - pattern: | + var $VAR interface{} + ... + xml.Unmarshal($DATA, &$VAR) +- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch + names can be silently repointed by the action owner, enabling supply-chain attacks + \u2014 as seen in the trivy-action and kics-github-action compromises. Pin the + reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`." + severity: WARNING + languages: + - yaml + metadata: + category: security + cwe: + - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' + - 'CWE-353: Missing Support for Integrity Check' + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + - Other + source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + shortlink: https://sg.run/2LgAL + semgrep.dev: + rule: + r_id: 288863 + rv_id: 1413422 + rule_id: GdUxYDx + version_id: xyTRDAd + url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + origin: community + patterns: + - pattern-inside: '{steps: ...}' + - pattern: | + uses: "$ACTION" + - metavariable-pattern: + metavariable: $ACTION + language: generic + patterns: + - pattern-not-regex: ^\./ + - pattern-not-regex: ^docker:// + - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' +- id: yaml.github-actions.security.secrets-inherit.secrets-inherit + languages: + - yaml + severity: ERROR + message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s + secrets to a reusable workflow. This violates the principle of least privilege + because the called workflow receives access to every secret in the repository, + not just the ones it needs. If the called workflow is compromised or sourced from + a third party, an attacker gains access to all repository secrets. Instead, explicitly + pass only the secrets that the called workflow requires using the `secrets:` map, + e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.' + metadata: + category: security + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow + - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions + technology: + - github-actions + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit + shortlink: https://sg.run/X2PZB + semgrep.dev: + rule: + r_id: 288864 + rv_id: 1413424 + rule_id: ReUQnKg + version_id: e1T42L1 + url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit + origin: community + patterns: + - pattern-inside: | + jobs: + ... + - pattern: 'secrets: inherit' +- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*minimumReleaseAge) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: minimumReleaseAge\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 604800 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ + message: 'This bunfig.toml does not set a minimum release age or sets it too low. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge + = 604800` under the `[install]` section to wait 7 days before resolving newly + published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/bunfig.toml' + - '**/.bunfig.toml' + metadata: + category: security + technology: + - bun + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://bun.sh/docs/runtime/bunfig + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + shortlink: https://sg.run/JqPrR + semgrep.dev: + rule: + r_id: 291646 + rv_id: 1423385 + rule_id: oqUyJOb + version_id: BjTyRe5 + url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + origin: community +- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + pattern-either: + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + - package-ecosystem: $ECOSYSTEM + ... + - pattern-not: | + - package-ecosystem: $ECOSYSTEM + ... + cooldown: + ... + ... + - patterns: + - pattern-inside: | + updates: + ... + - pattern-regex: default-days\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-inside: | + updates: + ... + - pattern: | + cooldown: + default-days: $DAYS + - metavariable-regex: + metavariable: $DAYS + regex: ^\D + - focus-metavariable: $DAYS + message: 'This Dependabot configuration does not set a cooldown period. Newly published + packages can be malicious or unstable. Add a `cooldown` block with `default-days: + 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing + updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.github/dependabot.yml' + - '**/.github/dependabot.yaml' + metadata: + category: security + technology: + - dependabot + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + shortlink: https://sg.run/5WvGK + semgrep.dev: + rule: + r_id: 291647 + rv_id: 1423386 + rule_id: zdUArOL + version_id: DkTwEGl + url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + origin: community +- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) + - pattern-not-regex: min-release-age + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: min-release-age\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)min-release-age\s*=\s*$ + message: 'This .npmrc does not set a minimum release age or sets it too low. Newly + published packages can be malicious or unstable. Add `min-release-age = 7` to + wait 7 days before resolving newly published package versions. Added in: v11.10 + Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/.npmrc' + metadata: + category: security + technology: + - npm + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ + - https://github.com/npm/cli/pull/8965 + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + shortlink: https://sg.run/GRo1z + semgrep.dev: + rule: + r_id: 291648 + rv_id: 1423387 + rule_id: pKU6A82 + version_id: WrT7LdL + url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` + to transitive dependencies from being installed from untrusted sources. Added + in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + blockExoticSubdeps: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!true$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#blockexoticsubdeps + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + shortlink: https://sg.run/RrWRv + semgrep.dev: + rule: + r_id: 291649 + rv_id: 1423388 + rule_id: 2ZUQEZ5 + version_id: 0bTGnwj + url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + origin: community +- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + message: 'This pnpm workspace configuration does not set a minimum release age. + Newly published packages can be malicious or unstable. Add `minimumReleaseAge: + 10080` (minutes) to wait at least seven days before installing newly published + package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 10080 + - focus-metavariable: $AGE + - patterns: + - pattern: | + minimumReleaseAge: $AGE + - metavariable-regex: + metavariable: $AGE + regex: ^\D + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + shortlink: https://sg.run/Aj0o0 + semgrep.dev: + rule: + r_id: 291650 + rv_id: 1423389 + rule_id: X5Uwn1n + version_id: K3TgxrW + url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + origin: community +- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent + malicious package updates from downgrading security settings. Added in: v10.21.0 + Reference: https://pnpm.io/settings#trustpolicy' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: | + trustPolicy: $VAL + - metavariable-regex: + metavariable: $VAL + regex: ^(?!no-downgrade$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ + metadata: + category: security + technology: + - pnpm + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://pnpm.io/settings#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + shortlink: https://sg.run/B2Kz7 + semgrep.dev: + rule: + r_id: 291651 + rv_id: 1423390 + rule_id: j2U6J8N + version_id: qkTvDQn + url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + origin: community +- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + pattern-either: + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-either: + - pattern: | + { ..., "matchPackageNames": [...], ... } + - pattern: | + { ..., "matchPackagePatterns": [...], ... } + - pattern: | + { ..., "matchDepTypes": [...], ... } + - pattern-not: | + { + ..., + "minimumReleaseAge": $AGE, + ... + } + - pattern-not: | + { + ..., + "minimumReleaseAge": false, + ... + } + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' + - metavariable-comparison: + metavariable: $AGE + comparison: int($AGE) < 7 + - focus-metavariable: $AGE + - patterns: + - pattern-inside: | + "packageRules": [ + ... + ] + - pattern: | + "minimumReleaseAge": "$AGE" + - metavariable-regex: + metavariable: $AGE + regex: ^(?!\d+ days?$) + - focus-metavariable: $AGE + message: 'This Renovate configuration does not set a minimum release age. Newly + published packages can be malicious or unstable. Add `"minimumReleaseAge": "7 + days"` within a `packageRules` entry to wait 7 days before proposing updates to + newly published package versions. Set `"minimumReleaseAge": false` to set an exception + for minimal release age for the package rule. Added in: v42' + languages: + - json + severity: MEDIUM + paths: + include: + - '**/renovate.json' + - '**/renovate.json5' + - '**/.renovaterc' + - '**/.renovaterc.json' + - '**/.renovaterc.json5' + metadata: + category: security + technology: + - renovate + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.renovatebot.com/configuration-options/#minimumreleaseage + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + shortlink: https://sg.run/D8l2q + semgrep.dev: + rule: + r_id: 291652 + rv_id: 1443454 + rule_id: 10UbQrX + version_id: jQT1KAX + url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + origin: community +- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + pattern-either: + - patterns: + - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*exclude-newer) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P\d+) days?" + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" + - metavariable-regex: + metavariable: $VAL + regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T) + - focus-metavariable: $VAL + message: 'This pyproject.toml configures uv but does not set a dependency cooldown. + Newly published packages can be malicious or unstable. Add `exclude-newer = "7 + days"` under `[tool.uv]` to wait 7 days before resolving newly published package + versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/pyproject.toml' + - '**/uv.toml' + metadata: + category: security + technology: + - uv + - python + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + shortlink: https://sg.run/WeY0Z + semgrep.dev: + rule: + r_id: 291653 + rv_id: 1423392 + rule_id: 9AUo6vE + version_id: YDTwLle + url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + origin: community +- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + pattern-either: + - patterns: + - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? + - metavariable-comparison: + metavariable: $DAYS + comparison: int($DAYS) < 7 + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) + - metavariable-regex: + metavariable: $VAL + regex: ^(?!['"]?\d+d['"]?$) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ + message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly + published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"` + to wait 7 days before resolving newly published package versions. Added in: 4.10 + Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' + languages: + - yaml + severity: MEDIUM + paths: + include: + - '**/.yarnrc.yml' + metadata: + category: security + technology: + - yarn + - javascript + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: HIGH + likelihood: LOW + impact: HIGH + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + shortlink: https://sg.run/0gvNq + semgrep.dev: + rule: + r_id: 291654 + rv_id: 1423393 + rule_id: yyUBeEz + version_id: JdTnXlj + url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + origin: community +- id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`. + Without a cooldown, Poetry may resolve newly published package versions that have + not yet been vetted by the community. Supply chain attacks frequently involve + publishing a malicious version of a popular package and waiting for it to be pulled + in \u2014 most are detected and removed within days. Set `min-release-age = 7` + under `[solver]` to require that package versions are at least 7 days old before + they are considered during dependency resolution. Added in: v2.4.0" + languages: + - generic + severity: MEDIUM + paths: + include: + - '**/poetry.toml' + - '**/config.toml' + pattern-either: + - pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z) + - pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P"[^"]*"|[0-6](?:\s|#|$)|false) + metadata: + category: security + technology: + - poetry + - python + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: MEDIUM + likelihood: LOW + impact: MEDIUM + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://python-poetry.org/docs/configuration/#solvermin-release-age + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + shortlink: https://sg.run/JqnYZ + semgrep.dev: + rule: + r_id: 309390 + rv_id: 1443453 + rule_id: kxUjBPy + version_id: X0TYPX6 + url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + origin: community +- id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown + below 7 days) allows Bundler to resolve newly published gem versions immediately, + before the community has had time to detect malicious releases. The May 2026 RubyGems + supply-chain attack demonstrated that threat actors can push compromised gem versions + and have them automatically pulled into builds within minutes. Add `cooldown: + 7` to each public source declaration so Bundler ignores gem versions published + within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org", + cooldown: 7`). If you operate an internal or private registry where the supply-chain + risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires + Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`; + `bundle install` with an existing lockfile is unaffected.' + languages: + - ruby + severity: MEDIUM + paths: + include: + - '**/Gemfile' + - '**/gems.rb' + exclude: + - '**/vendor/**' + - '**/.bundle/**' + pattern-either: + - patterns: + - pattern: source "...", ... + - pattern-not: 'source "...", ..., cooldown: $N, ...' + - patterns: + - pattern: 'source "...", ..., cooldown: $N, ...' + - metavariable-comparison: + metavariable: $N + comparison: $N > 0 and $N < 7 + - focus-metavariable: $N + metadata: + category: security + technology: + - bundler + - ruby + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + owasp: + - A08:2021 - Software and Data Integrity Failures + confidence: MEDIUM + likelihood: LOW + impact: MEDIUM + subcategory: + - audit + vulnerability_class: + - Insecure Configuration + references: + - https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + shortlink: https://sg.run/5Wlkl + semgrep.dev: + rule: + r_id: 309391 + rv_id: 1443455 + rule_id: wdUzPbP + version_id: 1QTEjAN + url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + origin: community +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell + interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote + server is compromised or the URL is hijacked, an attacker can execute arbitrary + code in your CI runner. Consider downloading the file first, verifying its checksum + or signature, and then executing it." + metadata: + category: security + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + technology: + - github-actions + - bash + - curl + cwe2021-top25: true + cwe2022-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + shortlink: https://sg.run/GR8K1 + semgrep.dev: + rule: + r_id: 309392 + rv_id: 1443456 + rule_id: x8UAgrE + version_id: 9lT3zYb + url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + origin: community + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: | + - run: ... + ... + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + languages: + - yaml + message: "A secret is exposed in the workflow-level `env:` block, making it available + to every job and step in this workflow \u2014 including any untrusted code run + in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level + `env:` so the secret is only available where it is actually needed." + metadata: + category: security + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets + - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow + technology: + - github-actions + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + shortlink: https://sg.run/Rrn12 + semgrep.dev: + rule: + r_id: 309393 + rv_id: 1443457 + rule_id: OrUnq7z + version_id: yeTqX9r + url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + origin: community + patterns: + - pattern-inside: | + env: + ... + - pattern-regex: \$\{\{\s*secrets\. + - pattern-not-inside: 'jobs: ...' + severity: WARNING +- id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + languages: + - ruby + severity: ERROR + message: Detected user input used to manually construct a SQL string. This is usually + bad practice because manual construction could accidentally result in a SQL injection. + An attacker could use a SQL injection to steal or modify contents of the database. + Instead, use a parameterized query which is available by default in most database + engines. Alternatively, consider using an object-relational mapper (ORM) such + as ActiveRecord which will protect your queries. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - rails + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/Y85o + semgrep.dev: + rule: + r_id: 14714 + rv_id: 1263667 + rule_id: bwU8gl + version_id: YDTZeLL + url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + pattern-sanitizers: + - pattern: | + $PARAMS.slice(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern: | + $RECORD.where($X,...) + - pattern: | + $RECORD.find(..., :conditions => $X,...) + - focus-metavariable: $X + - patterns: + - pattern: | + "$SQLVERB#{$EXPR}..." + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $SQLVERB + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", $EXPR) + - pattern: | + "$SQLSTR" + $EXPR + - pattern: | + "$SQLSTR" % $EXPR + - pattern-not-inside: | + $FUNC("...", "...#{$EXPR}...",...) + - focus-metavariable: $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - php + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) + VALUES (?, ?)");`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/lZYG + semgrep.dev: + rule: + r_id: 14757 + rv_id: 1263290 + rule_id: qNUXdL + version_id: gETB7vY + url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string + origin: community + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: mysqli_real_escape_string(...) + - pattern: real_escape_string(...) + - pattern: $MYSQLI->real_escape_string(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($SQLSTR, ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "...$EXPR..." + - metavariable-regex: + metavariable: $EXPR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: | + "$SQLSTR".$EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* +- id: php.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - php + severity: WARNING + message: User data flows into the host portion of this manually-constructed URL. + This could allow an attacker to send data to their own server, potentially exposing + sensitive data such as cookies or authorization information sent with this request. + They could also probe internal servers or other resources that the server running + this code can access. (This is called server-side request forgery, or SSRF.) Do + not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or + hardcode the correct host. + metadata: + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + category: security + technology: + - php + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + impact: MEDIUM + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Server-Side Request Forgery (SSRF) + source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host + shortlink: https://sg.run/Y8no + semgrep.dev: + rule: + r_id: 14758 + rv_id: 1263291 + rule_id: lBU8K1 + version_id: QkTGqRd + url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + pattern-sinks: + - pattern-either: + - patterns: + - pattern: | + sprintf($URLSTR, ...) + - metavariable-pattern: + metavariable: $URLSTR + language: generic + pattern: $SCHEME://%s + - patterns: + - pattern: | + "...{$EXPR}..." + - pattern-regex: | + .*://\{.* + - patterns: + - pattern: | + "...$EXPR..." + - pattern-regex: | + .*://\$.* + - patterns: + - pattern: | + "...".$EXPR + - pattern-regex: | + .*://["'].* +- id: php.lang.security.md5-used-as-password.md5-used-as-password + severity: WARNING + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure + password hash because it can be cracked by an attacker in a short amount of time. + Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD, + PASSWORD_BCRYPT, $OPTIONS);`. + languages: + - php + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://www.php.net/password_hash + category: security + technology: + - md5 + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password + shortlink: https://sg.run/66YL + semgrep.dev: + rule: + r_id: 14759 + rv_id: 1263294 + rule_id: YGUD1O + version_id: PkTR37j + url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password + origin: community + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5(...) + - pattern: hash('md5', ...) + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) +- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string + languages: + - java + severity: ERROR + message: User data flows into this manually-constructed SQL string. User data can + be safely inserted into SQL strings using prepared statements or an object-relational + mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL + injection, which could let an attacker steal or manipulate data from the database. + Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + category: security + technology: + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string + shortlink: https://sg.run/9rzz + semgrep.dev: + rule: + r_id: 14767 + rv_id: 1409396 + rule_id: 10UdRR + version_id: 44TbKvr + url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + interfile: true + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { + ... + } + - pattern-inside: | + $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { + ... + } + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - focus-metavariable: $SOURCE + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + "$SQLSTR" + ... + - pattern: | + "$SQLSTR".concat(...) + - patterns: + - pattern-inside: | + StringBuilder $SB = new StringBuilder("$SQLSTR"); + ... + - pattern: $SB.append(...) + - patterns: + - pattern-inside: | + $VAR = "$SQLSTR"; + ... + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - patterns: + - pattern-inside: | + String $VAR = "$SQLSTR"; + ... + - pattern: String.format($VAR, ...) + - pattern-not-inside: System.out.println(...) + - pattern-not-inside: $LOG.info(...) + - pattern-not-inside: $LOG.warn(...) + - pattern-not-inside: $LOG.warning(...) + - pattern-not-inside: $LOG.debug(...) + - pattern-not-inside: $LOG.debugging(...) + - pattern-not-inside: $LOG.error(...) + - pattern-not-inside: new Exception(...) + - pattern-not-inside: throw ...; + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b +- id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + patterns: + - pattern-either: + - patterns: + - pattern: ssl_policy = $ANYTHING + - pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+ + - pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+ + - patterns: + - pattern: protocol = "HTTP" + - pattern-not-inside: | + resource $ANYTHING $NAME { + ... + default_action { + ... + redirect { + ... + protocol = "HTTPS" + ... + } + ... + } + ... + } + - pattern-inside: | + resource $RESOURCE $X { + ... + } + - metavariable-pattern: + metavariable: $RESOURCE + patterns: + - pattern-either: + - pattern: | + "aws_lb_listener" + - pattern: | + "aws_alb_listener" + message: Detected an AWS load balancer with an insecure TLS version. TLS versions + less than 1.2 are considered insecure because they can be broken. To fix this, + set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include + a default action to redirect to HTTPS. + metadata: + category: security + technology: + - terraform + - aws + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-326: Inadequate Encryption Strength' + references: + - https://www.ietf.org/rfc/rfc5246.txt + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + shortlink: https://sg.run/187G + semgrep.dev: + rule: + r_id: 14966 + rv_id: 1263747 + rule_id: 2ZUP9K + version_id: ExTEx0y + url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version + origin: community + languages: + - hcl + severity: WARNING +- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli + mode: taint + pattern-sources: + - patterns: + - pattern: | + (string $X) + - pattern-not: | + "..." + pattern-propagators: + - pattern: (StringBuilder $B).$ANY(...,(string $X),...) + from: $X + to: $B + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: | + new $PATTERN($CMD,...) + - focus-metavariable: $CMD + - patterns: + - pattern: | + $CMD.$PATTERN = $VALUE; + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $PATTERN + regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ + pattern-sanitizers: + - pattern-either: + - pattern: | + $CMD.Parameters.Add(...) + - pattern: | + $CMD.Parameters.AddRange(...) + - pattern: | + $CMD.Parameters.AddWithValue(...) + - pattern: | + $CMD.Parameters[$IDX].Value = ... + by-side-effect: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand' + and 'SqlParameter'. + metadata: + category: security + technology: + - csharp + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + shortlink: https://sg.run/d2Xd + semgrep.dev: + rule: + r_id: 15078 + rv_id: 1262648 + rule_id: x8UxeP + version_id: RGT0LqW + url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + origin: community + languages: + - csharp + severity: ERROR +- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + languages: + - scala + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently + Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. + keeping secrets in environment variables)' + metadata: + category: security + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + technology: + - jwt + confidence: HIGH + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + cwe2021-top25: true + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + shortlink: https://sg.run/Z40o + semgrep.dev: + rule: + r_id: 15079 + rv_id: 1263691 + rule_id: OrU6W1 + version_id: 7ZTE3kr + url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + origin: community + pattern-either: + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC256("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC384("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); + ... + } + ... + } + - pattern: | + com.auth0.jwt.algorithms.Algorithm.HMAC512("..."); + - pattern: | + $SECRET = "..."; + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + - pattern: | + class $CLASS { + ... + $DECL $SECRET = "..."; + ... + def $FUNC (...): $RETURNTYPE = { + ... + com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); + ... + } + ... + } + severity: ERROR +- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + message: Enabling authentication ensures that all communications in the application + are authenticated. The `auth_settings` block needs to be filled out with the appropriate + auth backend settings + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + auth_settings { + ... + enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-287: Improper Authentication' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + shortlink: https://sg.run/JxYw + semgrep.dev: + rule: + r_id: 15102 + rv_id: 1263755 + rule_id: 0oU23p + version_id: PkTR3P8 + url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + message: Use the latest version of HTTP to ensure you are benefiting from security + fixes. Add `http2_enabled = true` to your appservice resource block + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + site_config { + ... + http2_enabled = true + ... + } + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + site_config { + ... + http2_enabled = false + ... + } + ... + } + metadata: + cwe: + - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response + Smuggling'')' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + shortlink: https://sg.run/5DkA + semgrep.dev: + rule: + r_id: 15103 + rv_id: 1263756 + rule_id: KxU7LJ + version_id: JdTzx98 + url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + message: By default, clients can connect to App Service by using both HTTP or HTTPS. + HTTP should be disabled enabling the HTTPS Only setting. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + https_only = true + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + https_only = false + ... + } + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only + - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + shortlink: https://sg.run/GOKp + semgrep.dev: + rule: + r_id: 15104 + rv_id: 1263757 + rule_id: qNUXwx + version_id: 5PTo1gg + url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + message: Detected an AppService that was not configured to use a client certificate. + Add `client_cert_enabled = true` in your resource block. + patterns: + - pattern: resource + - pattern-not-inside: | + resource "azurerm_app_service" "..." { + ... + client_cert_enabled = true + ... + } + - pattern-either: + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + } + - pattern-inside: | + resource "azurerm_app_service" "..." { + ... + client_cert_enabled = false + ... + } + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + shortlink: https://sg.run/RX1O + semgrep.dev: + rule: + r_id: 15105 + rv_id: 1263758 + rule_id: lBU8D6 + version_id: GxTkedE + url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + origin: community + languages: + - hcl + severity: INFO +- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version + = "1.2"` in your resource block. + patterns: + - pattern: min_tls_version = $ANYTHING + - pattern-inside: | + resource "azurerm_app_service" "$NAME" { + ... + } + - pattern-not-inside: min_tls_version = "1.2" + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + shortlink: https://sg.run/AXRp + semgrep.dev: + rule: + r_id: 15106 + rv_id: 1263759 + rule_id: YGUDbZ + version_id: RGT0L4x + url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + origin: community + languages: + - hcl + severity: ERROR +- id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + message: Detected a Storage that was not configured to deny action by default. Add + `enable_https_traffic_only = true` in your resource block. + patterns: + - pattern-not-inside: | + resource "azurerm_storage_account" "..." { + ... + enable_https_traffic_only = true + ... + } + - pattern-inside: | + resource "azurerm_storage_account" "..." { + ... + enable_https_traffic_only = false + ... + } + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + category: security + technology: + - terraform + - azure + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only + - https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + shortlink: https://sg.run/0y9v + semgrep.dev: + rule: + r_id: 15110 + rv_id: 1263805 + rule_id: pKUpDA + version_id: BjTkZ0A + url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + origin: community + languages: + - hcl + severity: WARNING +- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + metadata: + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + shortlink: https://sg.run/rY2n + semgrep.dev: + rule: + r_id: 15125 + rv_id: 1263258 + rule_id: v8U9Q7 + version_id: WrTqKgJ + url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + origin: community + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html + for more information. + severity: WARNING + pattern: | + $ENV.put($CTX.SECURITY_AUTHENTICATION, "none") + ... + $DCTX = InitialDirContext($ENV, ...) + languages: + - kt +- id: kotlin.lang.security.use-of-sha1.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + languages: + - kt + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - kotlin + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1 + shortlink: https://sg.run/N1pp + semgrep.dev: + rule: + r_id: 15127 + rv_id: 1263268 + rule_id: ZqUOdd + version_id: 2KTv2XZ + url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1 + origin: community + pattern-either: + - patterns: + - pattern: | + $VAR = $MD.getInstance("$ALGO") + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: | + $DU.getSha1Digest().digest(...) +- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + message: RSA keys should be at least 2048 bits based on NIST recommendation. + languages: + - kt + severity: WARNING + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - kotlin + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + shortlink: https://sg.run/krq7 + semgrep.dev: + rule: + r_id: 15128 + rv_id: 1263269 + rule_id: nJUZNL + version_id: X0TzypE + url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + origin: community + patterns: + - pattern-either: + - pattern: | + $KEY = $G.getInstance("RSA") + ... + $KEY.initialize($BITS) + - metavariable-comparison: + metavariable: $BITS + comparison: $BITS < 2048 diff --git a/backend/app/sandbox/rules/security-audit.yaml b/backend/app/sandbox/rules/security-audit.yaml new file mode 100644 index 0000000..8dbccb2 --- /dev/null +++ b/backend/app/sandbox/rules/security-audit.yaml @@ -0,0 +1,13698 @@ +rules: +- id: dockerfile.security.last-user-is-root.last-user-is-root + patterns: + - pattern: USER root + - pattern-not-inside: + patterns: + - pattern: | + USER root + ... + USER $X + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: root + message: The last user in the container is 'root'. This is a security hazard because + if an attacker gains control of the container they will have root access. Switch + back to another user after running commands as 'root'. + severity: ERROR + languages: + - dockerfile + metadata: + cwe: + - 'CWE-269: Improper Privilege Management' + source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 + references: + - https://github.com/hadolint/hadolint/wiki/DL3002 + category: security + technology: + - dockerfile + confidence: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root + shortlink: https://sg.run/5Z43 + semgrep.dev: + rule: + r_id: 20147 + rv_id: 1262658 + rule_id: ReU2n5 + version_id: 6xT29Eg + url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root + origin: community +- id: c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + pattern: gets(...) + message: Avoid 'gets()'. This function does not consider buffer boundaries and can + lead to buffer overflows. Use 'fgets()' or 'gets_s()' instead. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - https://us-cert.cisa.gov/bsi/articles/knowledge/coding-practices/fgets-and-gets_s + category: security + technology: + - c + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + shortlink: https://sg.run/dKqX + semgrep.dev: + rule: + r_id: 8834 + rv_id: 945170 + rule_id: GdU7OE + version_id: YDTvRlQ + url: https://semgrep.dev/playground/r/YDTvRlQ/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + origin: community + languages: + - c + severity: ERROR +- id: c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + message: Avoid using user-controlled format strings passed into 'sprintf', 'printf' + and 'vsprintf'. These functions put you at risk of buffer overflow vulnerabilities + through the use of format string exploits. Instead, use 'snprintf' and 'vsnprintf'. + metadata: + cwe: + - 'CWE-134: Use of Externally-Controlled Format String' + references: + - https://doc.castsoftware.com/display/SBX/Never+use+sprintf%28%29+or+vsprintf%28%29+functions + - https://www.cvedetails.com/cwe-details/134/Uncontrolled-Format-String.html + category: security + technology: + - c + confidence: LOW + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + shortlink: https://sg.run/ZvJx + semgrep.dev: + rule: + r_id: 8835 + rv_id: 945172 + rule_id: ReUgWx + version_id: o5TZeB2 + url: https://semgrep.dev/playground/r/o5TZeB2/c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + origin: community + languages: + - c + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $FUNC($BUFFER, argv[$NUM], ...); + ... + vsprintf(..., $BUFFER, ...); + - pattern: vsprintf(..., argv[$NUM], ...) + - pattern: | + $FUNC($BUFFER, argv[$NUM], ...); + ... + sprintf(..., $BUFFER, ...); + - pattern: sprintf(...,argv[$NUM],...) + - pattern: | + $FUNC($BUFFER, argv[$NUM], ...); + ... + printf(..., $BUFFER, ...); + - pattern: printf(...,argv[$NUM],...) + - metavariable-comparison: + metavariable: $NUM + comparison: int($NUM) > 0 +- id: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + pattern-either: + - pattern: strcat(...) + - pattern: strncat(...) + message: Finding triggers whenever there is a strcat or strncat used. This is an + issue because strcat or strncat can lead to buffer overflow vulns. Fix this by + using strcat_s instead. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - https://nvd.nist.gov/vuln/detail/CVE-2019-12553 + - https://techblog.mediaservice.net/2020/04/cve-2020-2851-stack-based-buffer-overflow-in-cde-libdtsvc/ + category: security + technology: + - c + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + shortlink: https://sg.run/EkRP + semgrep.dev: + rule: + r_id: 8837 + rv_id: 945174 + rule_id: BYUNjA + version_id: pZTNOXb + url: https://semgrep.dev/playground/r/pZTNOXb/c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + origin: community + languages: + - c + severity: WARNING +- id: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + pattern: strtok(...) + message: Avoid using 'strtok()'. This function directly modifies the first argument + buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead. + metadata: + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + references: + - https://wiki.sei.cmu.edu/confluence/display/c/STR06-C.+Do+not+assume+that+strtok%28%29+leaves+the+parse+string+unchanged + - https://man7.org/linux/man-pages/man3/strtok.3.html#BUGS + - https://stackoverflow.com/a/40335556 + category: security + technology: + - c + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + shortlink: https://sg.run/LwqG + semgrep.dev: + rule: + r_id: 8839 + rv_id: 1028278 + rule_id: WAUo5v + version_id: qkTx1oq + url: https://semgrep.dev/playground/r/qkTx1oq/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + origin: community + languages: + - c + severity: WARNING +- id: c.lang.security.double-free.double-free + patterns: + - pattern-not: | + free($VAR); + ... + $VAR = NULL; + ... + free($VAR); + - pattern-not: | + free($VAR); + ... + $VAR = malloc(...); + ... + free($VAR); + - pattern-inside: | + free($VAR); + ... + $FREE($VAR); + - metavariable-pattern: + metavariable: $FREE + pattern: free + - focus-metavariable: $FREE + message: Variable '$VAR' was freed twice. This can lead to undefined behavior. + metadata: + cwe: + - 'CWE-415: Double Free' + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cwe.mitre.org/data/definitions/415.html + - https://owasp.org/www-community/vulnerabilities/Doubly_freeing_memory + category: security + technology: + - c + confidence: LOW + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Memory Issues + source: https://semgrep.dev/r/c.lang.security.double-free.double-free + shortlink: https://sg.run/eLl0 + semgrep.dev: + rule: + r_id: 8832 + rv_id: 1262604 + rule_id: JDUyw8 + version_id: RGT0L3W + url: https://semgrep.dev/playground/r/RGT0L3W/c.lang.security.double-free.double-free + origin: community + languages: + - c + severity: ERROR +- id: c.lang.security.use-after-free.use-after-free + patterns: + - pattern-either: + - pattern: $VAR->$ACCESSOR + - pattern: (*$VAR).$ACCESSOR + - pattern: $VAR[$NUM] + - pattern-inside: free($VAR); ... + - pattern-not-inside: $VAR = NULL; ... + - pattern-not-inside: free($VAR); ... $VAR = malloc(...); ... + message: Variable '$VAR' was used after being freed. This can lead to undefined + behavior. + metadata: + cwe: + - 'CWE-416: Use After Free' + references: + - https://cwe.mitre.org/data/definitions/416.html + - https://ctf-wiki.github.io/ctf-wiki/pwn/linux/glibc-heap/use_after_free/ + category: security + technology: + - c + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Memory Issues + source: https://semgrep.dev/r/c.lang.security.use-after-free.use-after-free + shortlink: https://sg.run/gL6e + semgrep.dev: + rule: + r_id: 8841 + rv_id: 945178 + rule_id: KxUb9l + version_id: 1QToKPy + url: https://semgrep.dev/playground/r/1QToKPy/c.lang.security.use-after-free.use-after-free + origin: community + languages: + - c + severity: WARNING +- id: c.lang.security.random-fd-exhaustion.random-fd-exhaustion + pattern-either: + - patterns: + - pattern: | + $FD = open("/dev/urandom", ...); + ... + read($FD, ...); + - pattern-not: | + $FD = open("/dev/urandom", ...); + ... + $BYTES_READ = read($FD, ...); + - patterns: + - pattern: | + $FD = open("/dev/random", ...); + ... + read($FD, ...); + - pattern-not: | + $FD = open("/dev/random", ...); + ... + $BYTES_READ = read($FD, ...); + message: Call to 'read()' without error checking is susceptible to file descriptor + exhaustion. Consider using the 'getrandom()' function. + metadata: + cwe: + - 'CWE-774: Allocation of File Descriptors or Handles Without Limits or Throttling' + references: + - https://lwn.net/Articles/606141/ + category: security + technology: + - c + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + shortlink: https://sg.run/8yNj + semgrep.dev: + rule: + r_id: 8840 + rv_id: 945177 + rule_id: 0oU5k4 + version_id: jQTzvry + url: https://semgrep.dev/playground/r/jQTzvry/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + origin: community + languages: + - c + severity: WARNING +- id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + shortlink: https://sg.run/J9yZ + semgrep.dev: + rule: + r_id: 9090 + rv_id: 1262916 + rule_id: PeUZ4X + version_id: YDTZeZB + url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + origin: community + message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This + creates a connection without encryption to a gRPC server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Instead, + establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' + function. You can create a create credentials using a ''tls.Config{}'' struct + with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' + languages: + - go + severity: ERROR + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + metadata: + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + category: security + technology: + - grpc + confidence: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + shortlink: https://sg.run/5Q5l + semgrep.dev: + rule: + r_id: 9091 + rv_id: 1262917 + rule_id: JDUy0B + version_id: 6xT2923 + url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + origin: community + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. + This allows for a connection without encryption to this server. A malicious attacker + could tamper with the gRPC message, which could compromise the machine. Include + credentials derived from an SSL certificate in order to create a secure gRPC connection. + You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", + "cert.key")'. + languages: + - go + severity: ERROR + mode: taint + pattern-sinks: + - requires: OPTIONS and not CREDS + pattern: grpc.NewServer($OPT, ...) + - requires: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + options: + interfile: true + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + category: security + technology: + - jwt + - secrets + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + shortlink: https://sg.run/Rod2 + semgrep.dev: + rule: + r_id: 9093 + rv_id: 1262920 + rule_id: GdU7Ny + version_id: pZT0305 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + origin: community + severity: WARNING + languages: + - go + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + []byte("$F") + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $TOKEN.SignedString($F) + - focus-metavariable: $F +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + message: The package `net/http/cgi` is on the import blocklist. The package is + vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http` + or a web framework to build a web application instead. + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec + references: + - https://godoc.org/golang.org/x/crypto/sha3 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + shortlink: https://sg.run/l2gj + semgrep.dev: + rule: + r_id: 9113 + rv_id: 1262921 + rule_id: yyUnov + version_id: 2KTv2vJ + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + origin: community + languages: + - go + severity: WARNING + pattern-either: + - patterns: + - pattern-inside: | + import "net/http/cgi" + ... + - pattern: | + cgi.$FUNC(...) +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + message: Disabled host key verification detected. This allows man-in-the-middle + attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. + See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to + learn more about the problem and how to fix it. + metadata: + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + shortlink: https://sg.run/Yv6X + semgrep.dev: + rule: + r_id: 9114 + rv_id: 1262922 + rule_id: r6UrW9 + version_id: X0TzyzN + url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + origin: community + languages: + - go + severity: WARNING + pattern: ssh.InsecureIgnoreHostKey() +- id: go.lang.security.audit.crypto.math_random.math-random-used + metadata: + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + shortlink: https://sg.run/6nK6 + semgrep.dev: + rule: + r_id: 9115 + rv_id: 1262923 + rule_id: bwUwy8 + version_id: jQTn5nj + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + origin: community + message: Do not use `math/rand`. Use `crypto/rand` instead. + languages: + - go + severity: WARNING + patterns: + - pattern-either: + - pattern: | + import $RAND "$MATH" + - pattern: | + import "$MATH" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: | + ... + rand.$FUNC(...) + - pattern-inside: | + ... + $RAND.$FUNC(...) + - focus-metavariable: + - $MATH + fix: | + crypto/rand +- id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, + SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: MEDIUM + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + shortlink: https://sg.run/zvE1 + semgrep.dev: + rule: + r_id: 9117 + rv_id: 1262926 + rule_id: kxUkJ2 + version_id: yeTxpxj + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + origin: community + languages: + - go + severity: WARNING + fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered + weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. + See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other + cipher suites to use. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + category: security + technology: + - go + confidence: HIGH + subcategory: + - vuln + likelihood: HIGH + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + shortlink: https://sg.run/px8N + semgrep.dev: + rule: + r_id: 9118 + rv_id: 1262927 + rule_id: wdUJYk + version_id: rxTAKAZ + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} + - pattern: | + tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + message: Detected DES cipher algorithm which is insecure. The algorithm is considered + weak and has been deprecated. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + shortlink: https://sg.run/jREA + semgrep.dev: + rule: + r_id: 9121 + rv_id: 1262930 + rule_id: eqU8B3 + version_id: kbTzGzA + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + origin: community + patterns: + - pattern-inside: | + import "crypto/des" + ... + - pattern-either: + - pattern: | + des.NewTripleDESCipher(...) + - pattern: | + des.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision + resistant and is therefore not suitable as a cryptographic signature. Use SHA256 + or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + shortlink: https://sg.run/2xB5 + semgrep.dev: + rule: + r_id: 9119 + rv_id: 1262928 + rule_id: x8Un6q + version_id: bZT535Y + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + origin: community + patterns: + - pattern-inside: | + import "crypto/md5" + ... + - pattern-either: + - pattern: | + md5.New() + - pattern: | + md5.Sum(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many + known vulnerabilities. Use AES instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + shortlink: https://sg.run/1ZAD + semgrep.dev: + rule: + r_id: 9122 + rv_id: 1262931 + rule_id: v8Unl0 + version_id: w8TRoRQ + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + origin: community + patterns: + - pattern-inside: | + import "crypto/rc4" + ... + - pattern: rc4.NewCipher(...) +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not + collision resistant and is therefore not suitable as a cryptographic signature. + Use SHA256 or SHA3 instead. + languages: + - go + severity: WARNING + metadata: + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + cwe: + - 'CWE-328: Use of Weak Hash' + source-rule-url: https://github.com/securego/gosec#available-rules + category: security + technology: + - go + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Insecure Hashing Algorithm + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + shortlink: https://sg.run/XBYA + semgrep.dev: + rule: + r_id: 9120 + rv_id: 1262929 + rule_id: OrU31O + version_id: NdTzyz1 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + origin: community + patterns: + - pattern-inside: | + import "crypto/sha1" + ... + - pattern-either: + - pattern: | + sha1.New() + - pattern: | + sha1.Sum(...) +- id: go.lang.security.audit.database.string-formatted-query.string-formatted-query + languages: + - go + message: String-formatted SQL query detected. This could lead to SQL injection if + the string is not sanitized properly. Audit this call to ensure the SQL is not + manipulable by external data. + severity: WARNING + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/go.lang.security.audit.database.string-formatted-query.string-formatted-query + shortlink: https://sg.run/ydEr + semgrep.dev: + rule: + r_id: 9124 + rv_id: 1262937 + rule_id: ZqU5bD + version_id: ZRTKA2q + url: https://semgrep.dev/playground/r/ZRTKA2q/go.lang.security.audit.database.string-formatted-query.string-formatted-query + origin: community + patterns: + - metavariable-regex: + metavariable: $OBJ + regex: (?i).*(db|database) + - pattern-not-inside: | + $VAR = "..." + "..." + ... + $OBJ.$SINK(..., $VAR, ...) + - pattern-not: $OBJ.Exec("...") + - pattern-not: $OBJ.ExecContext($CTX, "...") + - pattern-not: $OBJ.Query("...") + - pattern-not: $OBJ.QueryContext($CTX, "...") + - pattern-not: $OBJ.QueryRow("...") + - pattern-not: $OBJ.QueryRow($CTX, "...") + - pattern-not: $OBJ.QueryRowContext($CTX, "...") + - pattern-either: + - pattern: $OBJ.Exec($X + ...) + - pattern: $OBJ.ExecContext($CTX, $X + ...) + - pattern: $OBJ.Query($X + ...) + - pattern: $OBJ.QueryContext($CTX, $X + ...) + - pattern: $OBJ.QueryRow($X + ...) + - pattern: $OBJ.QueryRow($CTX, $X + ...) + - pattern: $OBJ.QueryRowContext($CTX, $X + ...) + - pattern: $OBJ.Exec(fmt.$P("...", ...)) + - pattern: $OBJ.ExecContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.Query(fmt.$P("...", ...)) + - pattern: $OBJ.QueryContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow(fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow($CTX, fmt.$U("...", ...)) + - pattern: $OBJ.QueryRowContext($CTX, fmt.$P("...", ...)) + - patterns: + - pattern-either: + - pattern: $QUERY = fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: $QUERY = fmt.Sprintf("$SQLSTR", ...) + - pattern: $QUERY = fmt.Printf("$SQLSTR", ...) + - pattern: $QUERY = $X + ... + - pattern-either: + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.Query($QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.ExecContext($CTX, $QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.Exec($QUERY, ...) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRow($CTX, $QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRow($QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryContext($CTX, $QUERY) + ... + } + - pattern-inside: | + func $FUNC(...) { + ... + $OBJ.QueryRowContext($CTX, $QUERY, ...) + ... + } +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + message: Detected a network listener listening on 0.0.0.0 or an empty string. This + could unexpectedly expose the server publicly as it binds to all available interfaces. + Instead, specify another IP address that is not 0.0.0.0 nor the empty string. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: HIGH + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + shortlink: https://sg.run/rdE0 + semgrep.dev: + rule: + r_id: 9125 + rv_id: 1262939 + rule_id: nJUz3J + version_id: ExTExoK + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + origin: community + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep + could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous + because they deserialize function code to run when certain Request events occur, + which could lead to code being run without your knowledge. Ensure that your ClientTrace + is statically defined. + metadata: + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - vuln + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + shortlink: https://sg.run/kXEK + semgrep.dev: + rule: + r_id: 9128 + rv_id: 1262942 + rule_id: L1Uyjp + version_id: 8KT5rNv + url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + origin: community + patterns: + - pattern-not-inside: | + package $PACKAGE + ... + &httptrace.ClientTrace { ... } + ... + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING + languages: + - go +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. If user data can reach this template, you may have a XSS vulnerability. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + category: security + technology: + - go + confidence: MEDIUM + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + shortlink: https://sg.run/weE0 + semgrep.dev: + rule: + r_id: 9129 + rv_id: 1262943 + rule_id: 8GUjDW + version_id: gETB7Pe + url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + origin: community + languages: + - go + severity: WARNING + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTML($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTML($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTML($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTML($OTHER, ...) +- id: go.lang.security.audit.net.pprof.pprof-debug-exposure + metadata: + cwe: + - 'CWE-489: Active Debug Code' + owasp: A06:2017 - Security Misconfiguration + source-rule-url: https://github.com/securego/gosec#available-rules + references: + - https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ + category: security + technology: + - go + confidence: LOW + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Active Debug Code + source: https://semgrep.dev/r/go.lang.security.audit.net.pprof.pprof-debug-exposure + shortlink: https://sg.run/x1Ep + semgrep.dev: + rule: + r_id: 9130 + rv_id: 945583 + rule_id: gxU1Kp + version_id: 9lTy168 + url: https://semgrep.dev/playground/r/9lTy168/go.lang.security.audit.net.pprof.pprof-debug-exposure + origin: community + message: The profiling 'pprof' endpoint is automatically exposed on /debug/pprof. + This could leak information about the server. Instead, use `import "net/http/pprof"`. + See https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ + for more information and mitigation. + languages: + - go + severity: WARNING + patterns: + - pattern-inside: | + import _ "net/http/pprof" + ... + - pattern-inside: | + func $ANY(...) { + ... + } + - pattern-not-inside: | + $MUX = http.NewServeMux(...) + ... + http.ListenAndServe($ADDR, $MUX) + - pattern-not: http.ListenAndServe("=~/^localhost.*/", ...) + - pattern-not: http.ListenAndServe("=~/^127[.]0[.]0[.]1.*/", ...) + - pattern: http.ListenAndServe(...) +- id: go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + message: Found a formatted template string passed to 'template. HTMLAttr()'. 'template.HTMLAttr()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template or validate and sanitize the data before passing it into the + template. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTMLAttr + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + shortlink: https://sg.run/OPRp + semgrep.dev: + rule: + r_id: 9131 + rv_id: 1262945 + rule_id: QrUz9R + version_id: 3ZT4XRr + url: https://semgrep.dev/playground/r/3ZT4XRr/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.HTMLAttr($T + $X, ...) + - pattern: template.HTMLAttr(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.HTMLAttr($T, ...) + - pattern: | + $T = $X + $Y + ... + template.HTMLAttr($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.HTMLAttr($OTHER, ...) +- id: go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + message: Found a formatted template string passed to 'template.JS()'. 'template.JS()' + does not escape contents. Be absolutely sure there is no user-controlled data + in this template. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#JS + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + shortlink: https://sg.run/eLNl + semgrep.dev: + rule: + r_id: 9132 + rv_id: 1262946 + rule_id: 3qUP8K + version_id: 44TEj9E + url: https://semgrep.dev/playground/r/44TEj9E/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.JS($T + $X, ...) + - pattern: template.JS(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.JS($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.JS($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.JS($T, ...) + - pattern: | + $T = $X + $Y + ... + template.JS($T, ...) + - pattern: | + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.JS($OTHER, ...) +- id: go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + message: Found a formatted template string passed to 'template.URL()'. 'template.URL()' + does not escape contents, and this could result in XSS (cross-site scripting) + and therefore confidential data being stolen. Sanitize data coming into this function + or make sure that no user-controlled input is coming into the function. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#URL + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + shortlink: https://sg.run/vzE4 + semgrep.dev: + rule: + r_id: 9133 + rv_id: 1262947 + rule_id: 4bUkDW + version_id: PkTR3zz + url: https://semgrep.dev/playground/r/PkTR3zz/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + origin: community + languages: + - go + severity: WARNING + pattern-either: + - pattern: template.URL($T + $X, ...) + - pattern: template.URL(fmt.$P("...", ...), ...) + - pattern: | + $T = "..." + ... + $T = $FXN(..., $T, ...) + ... + template.URL($T, ...) + - pattern: | + $T = fmt.$P("...", ...) + ... + template.URL($T, ...) + - pattern: | + $T, $ERR = fmt.$P("...", ...) + ... + template.URL($T, ...) + - pattern: | + $T = $X + $Y + ... + template.URL($T, ...) + - pattern: |- + $T = "..." + ... + $OTHER, $ERR = fmt.$P(..., $T, ...) + ... + template.URL($OTHER, ...) +- id: go.lang.security.audit.net.use-tls.use-tls + pattern: http.ListenAndServe($ADDR, $HANDLER) + fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + metadata: + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + category: security + technology: + - go + confidence: MEDIUM + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + shortlink: https://sg.run/dKbY + semgrep.dev: + rule: + r_id: 9134 + rv_id: 1262948 + rule_id: PeUZ8X + version_id: JdTzxkn + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + origin: community + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. + See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + languages: + - go + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + patterns: + - pattern-inside: | + func $FUNC(..., $W http.ResponseWriter, ...) { + ... + var $TEMPLATE = "..." + ... + $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) + ... + } + - pattern-either: + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $DATA[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $DATA, $ERR := r.URL.Query()[...] + ... + $INTERM = $ANYTHING(..., $DATA, ...) + ... + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) + - pattern: | + $PARAMS = r.URL.Query() + ... + $DATA, $ERR := $PARAMS[...] + ... + $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) + message: Found data going from url query parameters into formatted data written + to ResponseWriter. This could be XSS and should not be done. If you must do this, + ensure your data is sanitized or escaped. + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - go + confidence: MEDIUM + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + shortlink: https://sg.run/Zvon + semgrep.dev: + rule: + r_id: 9135 + rv_id: 1262949 + rule_id: JDUyXB + version_id: 5PTo1qr + url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + origin: community + severity: WARNING + languages: + - go +- id: go.lang.security.audit.reflect-makefunc.reflect-makefunc + message: '''reflect.MakeFunc'' detected. This will sidestep protections that are + normally afforded by Go''s type system. Audit this call and be sure that user + input cannot be used to affect the code generated by MakeFunc; otherwise, you + will have a serious security vulnerability.' + metadata: + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + category: security + technology: + - go + confidence: LOW + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.lang.security.audit.reflect-makefunc.reflect-makefunc + shortlink: https://sg.run/KlPd + semgrep.dev: + rule: + r_id: 9111 + rv_id: 1262950 + rule_id: 10UKGb + version_id: GxTkeqB + url: https://semgrep.dev/playground/r/GxTkeqB/go.lang.security.audit.reflect-makefunc.reflect-makefunc + origin: community + severity: ERROR + pattern: reflect.MakeFunc(...) + languages: + - go +- id: go.lang.security.audit.unsafe.use-of-unsafe-block + message: Using the unsafe package in Go gives you low-level memory management and + many of the strengths of the C language, but also steps around the type safety + of Go and can lead to buffer overflows and possible arbitrary code execution by + an attacker. Only use this package if you absolutely know what you're doing. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-242: Use of Inherently Dangerous Function' + source_rule_url: https://github.com/securego/gosec/blob/master/rules/unsafe.go + category: security + technology: + - go + confidence: LOW + references: + - https://cwe.mitre.org/data/definitions/242.html + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Dangerous Method or Function + source: https://semgrep.dev/r/go.lang.security.audit.unsafe.use-of-unsafe-block + shortlink: https://sg.run/qxEx + semgrep.dev: + rule: + r_id: 9112 + rv_id: 945595 + rule_id: 9AU1p1 + version_id: ZRT35Wd + url: https://semgrep.dev/playground/r/ZRT35Wd/go.lang.security.audit.unsafe.use-of-unsafe-block + origin: community + pattern: unsafe.$FUNC(...) +- id: go.lang.security.bad_tmp.bad-tmp-file-creation + message: File creation in shared tmp directory without using `io.CreateTemp`. + languages: + - go + severity: WARNING + metadata: + cwe: + - 'CWE-377: Insecure Temporary File' + source-rule-url: https://github.com/securego/gosec + category: security + technology: + - go + confidence: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://pkg.go.dev/io/ioutil#TempFile + - https://pkg.go.dev/os#CreateTemp + - https://github.com/securego/gosec/blob/5fd2a370447223541cddb35da8d1bc707b7bb153/rules/tempfiles.go#L67 + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Other + source: https://semgrep.dev/r/go.lang.security.bad_tmp.bad-tmp-file-creation + shortlink: https://sg.run/Gejn + semgrep.dev: + rule: + r_id: 9104 + rv_id: 1262965 + rule_id: 6JUjnL + version_id: 2KTv2pJ + url: https://semgrep.dev/playground/r/2KTv2pJ/go.lang.security.bad_tmp.bad-tmp-file-creation + origin: community + pattern-either: + - pattern: ioutil.WriteFile("=~//tmp/.*$/", ...) + - pattern: os.Create("=~//tmp/.*$/", ...) + - pattern: os.WriteFile("=~//tmp/.*$/", ...) +- id: go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + message: 'Detected a possible denial-of-service via a zip bomb attack. By limiting + the max bytes read, you can mitigate this attack. `io.CopyN()` can specify a size. ' + severity: WARNING + languages: + - go + patterns: + - pattern-either: + - pattern: io.Copy(...) + - pattern: io.CopyBuffer(...) + - pattern-either: + - pattern-inside: | + gzip.NewReader(...) + ... + - pattern-inside: | + zlib.NewReader(...) + ... + - pattern-inside: | + zlib.NewReaderDict(...) + ... + - pattern-inside: | + bzip2.NewReader(...) + ... + - pattern-inside: | + flate.NewReader(...) + ... + - pattern-inside: | + flate.NewReaderDict(...) + ... + - pattern-inside: | + lzw.NewReader(...) + ... + - pattern-inside: | + tar.NewReader(...) + ... + - pattern-inside: | + zip.NewReader(...) + ... + - pattern-inside: | + zip.OpenReader(...) + ... + fix-regex: + regex: (.*)(Copy|CopyBuffer)\((.*?),(.*?)(\)|,.*\)) + replacement: \1CopyN(\3, \4, 1024*1024*256) + metadata: + cwe: + - 'CWE-400: Uncontrolled Resource Consumption' + source-rule-url: https://github.com/securego/gosec + references: + - https://golang.org/pkg/io/#CopyN + - https://github.com/securego/gosec/blob/master/rules/decompression-bomb.go + category: security + technology: + - go + confidence: LOW + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Denial-of-Service (DoS) + source: https://semgrep.dev/r/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + shortlink: https://sg.run/RodK + semgrep.dev: + rule: + r_id: 9105 + rv_id: 945606 + rule_id: oqUeqn + version_id: JdTDye5 + url: https://semgrep.dev/playground/r/JdTDye5/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + origin: community +- id: go.lang.security.zip.path-traversal-inside-zip-extraction + message: File traversal when extracting zip archive + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source_rule_url: https://github.com/securego/gosec/issues/205 + category: security + technology: + - go + confidence: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/go.lang.security.zip.path-traversal-inside-zip-extraction + shortlink: https://sg.run/Av64 + semgrep.dev: + rule: + r_id: 9106 + rv_id: 1262971 + rule_id: zdUkoR + version_id: rxTAK1Z + url: https://semgrep.dev/playground/r/rxTAK1Z/go.lang.security.zip.path-traversal-inside-zip-extraction + origin: community + languages: + - go + severity: WARNING + pattern: | + reader, $ERR := zip.OpenReader($ARCHIVE) + ... + for _, $FILE := range reader.File { + ... + path := filepath.Join($TARGET, $FILE.Name) + ... + } +- id: go.otto.security.audit.dangerous-execution.dangerous-execution + message: Detected non-static script inside otto VM. Audit the input to 'VM.Run'. + If unverified user data can reach this call site, this is a code injection vulnerability. + A malicious actor can inject a malicious script to execute arbitrary code. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - otto + - vm + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/go.otto.security.audit.dangerous-execution.dangerous-execution + shortlink: https://sg.run/4xWE + semgrep.dev: + rule: + r_id: 9144 + rv_id: 1262972 + rule_id: KxUbxk + version_id: bZT53ZY + url: https://semgrep.dev/playground/r/bZT53ZY/go.otto.security.audit.dangerous-execution.dangerous-execution + origin: community + severity: ERROR + patterns: + - pattern-inside: | + $VM = otto.New(...) + ... + - pattern-not: $VM.Run("...", ...) + - pattern: $VM.Run(...) + languages: + - go +- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + metadata: + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - jax-rs + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: LOW + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + shortlink: https://sg.run/DoWj + semgrep.dev: + rule: + r_id: 9152 + rv_id: 1262984 + rule_id: 2ZUb9l + version_id: 7ZTE3KW + url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } + - pattern: |- + $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { + ... + new File(..., $VAR, ...); + ... + } +- id: java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + metadata: + cwe: + - 'CWE-287: Improper Authentication' + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + shortlink: https://sg.run/jR6A + semgrep.dev: + rule: + r_id: 9165 + rv_id: 1262988 + rule_id: eqU8J3 + version_id: QkTGqE0 + url: https://semgrep.dev/playground/r/QkTGqE0/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind + origin: community + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP + statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html + for more information. + severity: WARNING + pattern: | + $ENV.put($CTX.SECURITY_AUTHENTICATION, "none"); + ... + $DCTX = new InitialDirContext($ENV, ...); + languages: + - java +- id: java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + metadata: + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + owasp: A03:2017 - Sensitive Data Exposure + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BAD_HEXA_CONVERSION + category: security + technology: + - java + references: + - https://cwe.mitre.org/data/definitions/704.html + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + shortlink: https://sg.run/1Z7D + semgrep.dev: + rule: + r_id: 9166 + rv_id: 945646 + rule_id: v8Uny0 + version_id: QkTZzgy + url: https://semgrep.dev/playground/r/QkTZzgy/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion + origin: community + message: '''Integer.toHexString()'' strips leading zeroes from each byte if read + byte-by-byte. This mistake weakens the hash value computed since it introduces + more collisions. Use ''String.format("%02X", ...)'' instead.' + severity: WARNING + languages: + - java + pattern: |- + $X $METHOD(...) { + ... + MessageDigest $MD = ...; + ... + $MD.digest(...); + ... + Integer.toHexString(...); + } +- id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A + malicious actor could discern the difference between plaintext with valid or invalid + padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' + instead. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE + references: + - https://capec.mitre.org/data/definitions/463.html + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY + category: security + technology: + - java + subcategory: + - audit + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + shortlink: https://sg.run/ydxr + semgrep.dev: + rule: + r_id: 9168 + rv_id: 1262990 + rule_id: ZqU5oD + version_id: 44TEjbE + url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + origin: community + severity: WARNING + fix: | + "AES/GCM/NoPadding" + languages: + - java + patterns: + - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") + - pattern: | + "=~/.*\/CBC\/PKCS5Padding/" +- id: java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + patterns: + - metavariable-pattern: + metavariable: $RUNTIME + patterns: + - pattern-either: + - pattern: (java.lang.Runtime $R) + - pattern: java.lang.Runtime.getRuntime(...) + - pattern-either: + - pattern: $RUNTIME.exec($X + $Y); + - pattern: $RUNTIME.exec(String.format(...)); + - pattern: $RUNTIME.loadLibrary($X + $Y); + - pattern: $RUNTIME.loadLibrary(String.format(...)); + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...},...) + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec($CMD,"-c",$ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList($CMD,"-c",$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{$CMD,"-c",$ARG,...},...) + - pattern-inside: | + $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; + ... + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec($CMD, $EXECUTE, $ARG, ...) + - pattern-inside: | + $CMD = new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/", ...}; + ... + - patterns: + - pattern-either: + - pattern: | + $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", $BASH, $ARG,...) + - pattern: | + $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...),...) + - pattern: | + $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...},...) + - pattern-inside: | + $BASH = new String[]{"=~/(-c)/", ...}; + ... + - pattern-not-inside: | + $ARG = "..."; + ... + - pattern-not: | + $RUNTIME.exec("...","...","...",...) + - pattern-not: | + $RUNTIME.exec(new String[]{"...","...","...",...},...) + - pattern-not: | + $RUNTIME.exec(Arrays.asList("...","...","...",...),...) + message: A formatted or concatenated string was detected as input to a java.lang.Runtime + call. This is dangerous if a variable is controlled by user input and could result + in a command injection. Ensure your variables are not controlled by users or sufficiently + sanitized. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#COMMAND_INJECTION. + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + shortlink: https://sg.run/rd90 + semgrep.dev: + rule: + r_id: 9169 + rv_id: 1262991 + rule_id: nJUzvJ + version_id: PkTR3ez + url: https://semgrep.dev/playground/r/PkTR3ez/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call + origin: community + severity: ERROR + languages: + - java +- id: java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + metadata: + cwe: + - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTPONLY_COOKIE + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.4.2 Missing Cookie Attribute + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + shortlink: https://sg.run/b7Be + semgrep.dev: + rule: + r_id: 9170 + rv_id: 1262993 + rule_id: EwU2z6 + version_id: 5PTo17r + url: https://semgrep.dev/playground/r/5PTo17r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly + origin: community + message: A cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' + flag for cookies instructs the browser to forbid client-side scripts from reading + the cookie. Set the 'HttpOnly' flag by calling 'cookie.setHttpOnly(true);' + severity: WARNING + languages: + - java + patterns: + - pattern-not-inside: $COOKIE.setValue(""); ... + - pattern-either: + - pattern: $COOKIE.setHttpOnly(false); + - patterns: + - pattern-not-inside: $COOKIE.setHttpOnly(...); ... + - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... + - pattern: $RESPONSE.addCookie($COOKIE); +- id: java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + metadata: + cwe: + - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_COOKIE + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.4.1 Missing Cookie Attribute + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cookie Security + source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + shortlink: https://sg.run/kXoK + semgrep.dev: + rule: + r_id: 9172 + rv_id: 1262994 + rule_id: L1Uyvp + version_id: GxTkelB + url: https://semgrep.dev/playground/r/GxTkelB/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag + origin: community + message: A cookie was detected without setting the 'secure' flag. The 'secure' flag + for cookies prevents the client from transmitting the cookie over insecure channels + such as HTTP. Set the 'secure' flag by calling '$COOKIE.setSecure(true);' + severity: WARNING + languages: + - java + patterns: + - pattern-not-inside: $COOKIE.setValue(""); ... + - pattern-either: + - pattern: $COOKIE.setSecure(false); + - patterns: + - pattern-not-inside: $COOKIE.setSecure(...); ... + - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... + - pattern: $RESPONSE.addCookie($COOKIE); +- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + message: When data from an untrusted source is put into a logger and not neutralized + correctly, an attacker could forge log entries or include malicious content. + metadata: + cwe: + - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + shortlink: https://sg.run/wek0 + semgrep.dev: + rule: + r_id: 9173 + rv_id: 1262995 + rule_id: 8GUjwW + version_id: RGT0LEr + url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - patterns: + - pattern-inside: | + class $CLASS { + ... + Logger $LOG = ...; + ... + } + - pattern-either: + - pattern-inside: | + $X $METHOD(...,HttpServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...,ServletRequest $REQ,...) { + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + HttpServletRequest $REQ = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + Logger $LOG = ...; + ... + ServletRequest $REQ = ...; + ... + } + - pattern-either: + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.$LEVEL(<... $VAL ...>); + - pattern: | + String $VAL = $REQ.getParameter(...); + ... + $LOG.log($LEVEL,<... $VAL ...>); + - pattern: | + $LOG.$LEVEL(<... $REQ.getParameter(...) ...>); + - pattern: | + $LOG.log($LEVEL,<... $REQ.getParameter(...) ...>); +- id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + message: DES is considered deprecated. AES is the recommended cipher. Upgrade to + use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + for more information. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + shortlink: https://sg.run/5Q73 + semgrep.dev: + rule: + r_id: 9191 + rv_id: 1262996 + rule_id: PeUZNg + version_id: A8TgdEn + url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") + - pattern-inside: $CIPHER.getInstance("DES") + - pattern-either: + - pattern: | + "=~/DES/.*/" + - pattern: | + "DES" + fix: | + "AES/GCM/NoPadding" + languages: + - java + - kt +- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended + cipher. Upgrade to use AES. + metadata: + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE + references: + - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + shortlink: https://sg.run/Geqn + semgrep.dev: + rule: + r_id: 9192 + rv_id: 1262997 + rule_id: JDUy8J + version_id: BjTkZyQ + url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + origin: community + severity: WARNING + patterns: + - pattern-either: + - pattern: | + $CIPHER.getInstance("=~/DESede.*/") + - pattern: | + $CRYPTO.KeyGenerator.getInstance("DES") + languages: + - java + - kt +- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + patterns: + - pattern-either: + - pattern: new NullCipher(...); + - pattern: new javax.crypto.NullCipher(...); + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + shortlink: https://sg.run/AvA4 + semgrep.dev: + rule: + r_id: 9194 + rv_id: 1263001 + rule_id: GdU7pw + version_id: K3TKkgB + url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + origin: community + message: 'NullCipher was detected. This will not encrypt anything; the cipher text + will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for + more information.' + severity: WARNING + languages: + - java +- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + message: Initialization Vectors (IVs) for block ciphers should be randomly generated + each time they are used. Using a static IV means the same plaintext encrypts to + the same ciphertext every time, weakening the strength of the encryption. + metadata: + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + references: + - https://cwe.mitre.org/data/definitions/329.html + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + shortlink: https://sg.run/BkB5 + semgrep.dev: + rule: + r_id: 9195 + rv_id: 1263002 + rule_id: ReUgj1 + version_id: qkTR7vP + url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + byte[] $IV = { + ... + }; + ... + new IvParameterSpec($IV, ...); + - pattern: | + class $CLASS { + byte[] $IV = { + ... + }; + ... + $METHOD(...) { + ... + new IvParameterSpec($IV, ...); + ... + } + } +- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + metadata: + functional-categories: + - crypto::search::mode::javax.crypto + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING + references: + - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + - kotlin + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + shortlink: https://sg.run/DoOj + semgrep.dev: + rule: + r_id: 9196 + rv_id: 1263003 + rule_id: AbUzoj + version_id: l4TJRpK + url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + origin: community + message: Using RSA without OAEP mode weakens the encryption. + severity: WARNING + languages: + - java + - kt + pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") +- id: java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DEFAULT_HTTP_CLIENT + asvs: + section: V9 Communications Verification Requirements + control_id: 9.1.3 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + shortlink: https://sg.run/J9Gj + semgrep.dev: + rule: + r_id: 9202 + rv_id: 1263005 + rule_id: qNUj8b + version_id: JdTzxnb + url: https://semgrep.dev/playground/r/JdTzxnb/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated + origin: community + message: DefaultHttpClient is deprecated. Further, it does not support connections + using TLS1.2, which makes using DefaultHttpClient a security hazard. Use HttpClientBuilder + instead. + severity: WARNING + languages: + - java + pattern: new DefaultHttpClient(...); + fix-regex: + regex: DefaultHttpClient + replacement: HttpClientBuilder +- id: java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + message: Insecure HostnameVerifier implementation detected. This will accept any + SSL certificate with any hostname, which creates the possibility for man-in-the-middle + attacks. + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_HOSTNAME_VERIFIER + asvs: + section: V9 Communications Verification Requirements + control_id: 9.2.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + shortlink: https://sg.run/5QoD + semgrep.dev: + rule: + r_id: 9203 + rv_id: 1263006 + rule_id: lBU9n8 + version_id: 5PTo17W + url: https://semgrep.dev/playground/r/5PTo17W/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + class $CLASS implements HostnameVerifier { + ... + public boolean verify(...) { return true; } + } + - pattern: |- + new HostnameVerifier(...){ + public boolean verify(...) { + return true; + } + } + - pattern: import org.apache.http.conn.ssl.NoopHostnameVerifier; +- id: java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + metadata: + cwe: + - 'CWE-295: Improper Certificate Validation' + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_TRUST_MANAGER + asvs: + section: V9 Communications Verification Requirements + control_id: 9.2.1 Weak TLS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + version: '4' + references: + - https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + shortlink: https://sg.run/GePy + semgrep.dev: + rule: + r_id: 9204 + rv_id: 1263007 + rule_id: YGUR9A + version_id: GxTkel1 + url: https://semgrep.dev/playground/r/GxTkel1/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager + origin: community + message: Detected empty trust manager implementations. This is dangerous because + it accepts any certificate, enabling man-in-the-middle attacks. Consider using + a KeyStore and TrustManagerFactory instead. See https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https + for more information. + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS implements X509TrustManager { + ... + } + - pattern-inside: | + new X509TrustManager() { + ... + } + - pattern-inside: | + class $CLASS implements X509ExtendedTrustManager { + ... + } + - pattern-inside: | + new X509ExtendedTrustManager() { + ... + } + - pattern-not: public void checkClientTrusted(...) { $SOMETHING; } + - pattern-not: public void checkServerTrusted(...) { $SOMETHING; } + - pattern-either: + - pattern: public void checkClientTrusted(...) {} + - pattern: public void checkServerTrusted(...) {} + - pattern: public X509Certificate[] getAcceptedIssuers(...) { return null; } +- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + metadata: + functional-categories: + - net::search::crypto-config::java.net + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + asvs: + section: V6 Stored Cryptography Verification Requirements + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + shortlink: https://sg.run/W8zA + semgrep.dev: + rule: + r_id: 9197 + rv_id: 1263008 + rule_id: BYUN3X + version_id: RGT0LEj + url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + origin: community + message: Detected use of a Java socket that is not encrypted. As a result, the traffic + could be read by an attacker intercepting the network traffic. Use an SSLSocket + created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. + severity: WARNING + languages: + - java + pattern-either: + - pattern: new ServerSocket(...) + - pattern: new Socket(...) +- id: java.lang.security.audit.el-injection.el-injection + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#EL_INJECTION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.el-injection.el-injection + shortlink: https://sg.run/x1wp + semgrep.dev: + rule: + r_id: 9174 + rv_id: 1263021 + rule_id: gxU1Np + version_id: pZT03e1 + url: https://semgrep.dev/playground/r/pZT03e1/java.lang.security.audit.el-injection.el-injection + origin: community + message: An expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF; + ... + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF = ...; + ... + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + $X $METHOD(...) { + ... + ExpressionFactory $EF = ...; + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ExpressionFactory $EF,...) { + ... + $EF.createValueExpression($CTX,$INPUT,...); + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF; + ... + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + class $CLASS { + ... + ExpressionFactory $EF = ...; + ... + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + ... + } + - pattern: | + $X $METHOD(...) { + ... + ExpressionFactory $EF = ...; + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(...,ExpressionFactory $EF,...) { + ... + $EF.createMethodExpression($CTX,$INPUT,...); + ... + } + - pattern: | + $X $METHOD(String $INPUT, ...) { + ... + $OBJECT.buildConstraintViolationWithTemplate($INPUT, ...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $EF.createValueExpression($CTX,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $EF.createValueExpression($CTX,$S,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $EF.createMethodExpression($CTX,"...",...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $EF.createMethodExpression($CTX,$S,...); + ... + } +- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps + - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string + shortlink: https://sg.run/OPXp + semgrep.dev: + rule: + r_id: 9175 + rv_id: 1409389 + rule_id: QrUzxR + version_id: ExTeyBP + url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string + origin: community + options: + taint_assume_safe_numbers: true + taint_assume_safe_booleans: true + message: Detected a formatted string in a SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a + prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement + using 'connection.prepareStatement'. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + $ANNOT $FUNC (..., $INPUT, ...) { + ... + } + - pattern: (String $INPUT) + - focus-metavariable: $INPUT + label: INPUT + - patterns: + - pattern-either: + - pattern: $X + $INPUT + - pattern: $X += $INPUT + - pattern: String.format(..., $INPUT, ...) + - pattern: String.join(..., $INPUT, ...) + - pattern: (String $STR).concat($INPUT) + - pattern: $INPUT.concat(...) + - patterns: + - pattern-either: + - pattern: $STRB.append($INPUT) + - pattern: new $STRB(..., $INPUT, ...) + - metavariable-type: + metavariable: $STRB + type: StringBuilder + label: CONCAT + requires: INPUT + pattern-propagators: + - pattern: (StringBuffer $S).append($X) + from: $X + to: $S + - pattern: (StringBuilder $S).append($X) + from: $X + to: $S + pattern-sinks: + - patterns: + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) + - pattern-either: + - pattern: (Statement $S).$SQLFUNC(...) + - pattern: (PreparedStatement $P).$SQLFUNC(...) + - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) + - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) + - pattern: (EntityManager $EM).$SQLFUNC(...) + - metavariable-regex: + metavariable: $SQLFUNC + regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare + requires: CONCAT + pattern-sanitizers: + - patterns: + - pattern: (CriteriaBuilder $CB).$ANY(...) + severity: ERROR + languages: + - java +- id: java.lang.security.audit.http-response-splitting.http-response-splitting + metadata: + cwe: + - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP + Request/Response Splitting'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING + references: + - https://www.owasp.org/index.php/HTTP_Response_Splitting + category: security + technology: + - java + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting + shortlink: https://sg.run/eL0l + semgrep.dev: + rule: + r_id: 9176 + rv_id: 1263023 + rule_id: 3qUPyK + version_id: X0Tzykw + url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting + origin: community + message: Older Java application servers are vulnerable to HTTP response splitting, + which may occur if an HTTP request can be injected with CRLF characters. This + finding is reported for completeness; it is recommended to ensure your environment + is not affected by testing this yourself. + severity: INFO + languages: + - java + pattern-either: + - pattern: | + $VAR = $REQ.getParameter(...); + ... + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); + - patterns: + - pattern-inside: | + $RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) { + ... + } + - pattern: | + $COOKIE = new Cookie(..., $VAR, ...); + ... + $RESP.addCookie($COOKIE, ...); +- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + metadata: + cwe: + - 'CWE-297: Improper Validation of Certificate with Host Mismatch' + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL + category: security + technology: + - java + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authentication + source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + shortlink: https://sg.run/vzN4 + semgrep.dev: + rule: + r_id: 9177 + rv_id: 1263024 + rule_id: 4bUkrW + version_id: jQTn5Dv + url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + origin: community + message: Insecure SMTP connection detected. This connection will trust any SSL certificate. + Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'. + severity: WARNING + patterns: + - pattern-not-inside: | + $EMAIL.setSSLCheckServerIdentity(true); + ... + - pattern-inside: | + $EMAIL = new SimpleEmail(...); + ... + - pattern: $EMAIL.send(...); + languages: + - java +- id: java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + metadata: + cwe: + - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command + (''SQL Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION_SPRING_JDBC + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.5 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - jdbc + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - SQL Injection + source: https://semgrep.dev/r/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + shortlink: https://sg.run/dKWY + semgrep.dev: + rule: + r_id: 9178 + rv_id: 1263026 + rule_id: PeUZNX + version_id: 9lT4bqk + url: https://semgrep.dev/playground/r/9lT4bqk/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string + origin: community + message: 'Possible JDBC injection detected. Use the parameterized query feature + available in queryForObject instead of concatenating or formatting strings: ''jdbc.queryForObject("select + * from table where name = ?", Integer.class, parameterName);''' + patterns: + - pattern-inside: | + $JDBC = new JdbcTemplate(...); + ... + - pattern-either: + - pattern: $JDBC.queryForObject($STR + $VAR, ...); + - pattern: $JDBC.queryForObject(String.format(...), ...); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.queryForObject($Q, ...); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.queryForObject($Q, ...); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.queryForObject($Q, ...); + - pattern: $JDBC.queryForList($STR + $VAR); + - pattern: $JDBC.queryForList(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.queryForList($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.queryForList($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.queryForList($Q, ...); + - pattern: $JDBC.update($STR + $VAR); + - pattern: $JDBC.update(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.update($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.update($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.update($Q, ...); + - pattern: $JDBC.execute($STR + $VAR); + - pattern: $JDBC.execute(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.execute($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.execute($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.execute($Q, ...); + - pattern: $JDBC.insert($STR + $VAR); + - pattern: $JDBC.insert(String.format(...)); + - pattern: | + String $Q = $STR + $VAR; + ... + $JDBC.insert($Q); + - pattern: | + String $Q = String.format(...); + ... + $JDBC.insert($Q); + - pattern: | + StringBuilder $Q = new StringBuilder(...); + ... + $Q.append($STR + $VAR); + ... + $JDBC.insert($Q, ...); + severity: WARNING + languages: + - java +- id: java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + metadata: + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ENTRY_POISONING + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.7 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + shortlink: https://sg.run/ZvOn + semgrep.dev: + rule: + r_id: 9179 + rv_id: 1263027 + rule_id: JDUy8B + version_id: yeTxpGP + url: https://semgrep.dev/playground/r/yeTxpGP/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning + origin: community + message: An object-returning LDAP search will allow attackers to control the LDAP + response. This could lead to Remote Code Execution. + severity: WARNING + pattern-either: + - pattern: | + new SearchControls($S, $CL, $TL, $AT, true, $DEREF) + - pattern: | + SearchControls $VAR = new SearchControls(); + ... + $VAR.setReturningObjFlag(true); + languages: + - java +- id: java.lang.security.audit.ldap-injection.ldap-injection + message: Detected non-constant data passed into an LDAP query. If this data can + be controlled by an external user, this is an LDAP injection. Ensure data passed + to an LDAP query is not controllable; or properly sanitize the data. + metadata: + cwe: + - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP + Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_INJECTION + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.3.7 Injection + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - LDAP Injection + source: https://semgrep.dev/r/java.lang.security.audit.ldap-injection.ldap-injection + shortlink: https://sg.run/nd2O + semgrep.dev: + rule: + r_id: 9180 + rv_id: 1263028 + rule_id: 5rUObQ + version_id: rxTAKl2 + url: https://semgrep.dev/playground/r/rxTAKl2/java.lang.security.audit.ldap-injection.ldap-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + $X $METHOD(...) { + ... + InitialDirContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + DirContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + InitialLdapContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + LdapContext $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + LdapCtx $CTX = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + EventDirContext $CTX = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $CTX.search($Y,$INPUT,...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $CTX.search($Y,"...",...); + ... + } +- id: java.lang.security.audit.object-deserialization.object-deserialization + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OBJECT_DESERIALIZATION + references: + - https://www.owasp.org/index.php/Deserialization_of_untrusted_data + - https://www.oracle.com/java/technologies/javase/seccodeguide.html#8 + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.lang.security.audit.object-deserialization.object-deserialization + shortlink: https://sg.run/Ek0A + semgrep.dev: + rule: + r_id: 9181 + rv_id: 1263030 + rule_id: GdU7py + version_id: NdTzyGe + url: https://semgrep.dev/playground/r/NdTzyGe/java.lang.security.audit.object-deserialization.object-deserialization + origin: community + message: Found object deserialization using ObjectInputStream. Deserializing entire + Java objects is dangerous because malicious actors can create Java object streams + with unintended consequences. Ensure that the objects being deserialized are not + user-controlled. If this must be done, consider using HMACs to sign the data stream + to make sure it is not tampered with, or consider only transmitting object fields + and populating a new object. + severity: WARNING + languages: + - java + pattern: new ObjectInputStream(...); +- id: java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + message: Detected file permissions that are overly permissive (read, write, and + execute). It is generally a bad practices to set overly permissive file permission + such as read+write+exec for all users. If the file affected is a configuration, + a binary, a script or sensitive data, it can lead to privilege escalation or information + leakage. Instead, follow the principle of least privilege and give users only + the permissions they need. + severity: WARNING + languages: + - java + metadata: + cwe: + - 'CWE-276: Incorrect Default Permissions' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OVERLY_PERMISSIVE_FILE_PERMISSION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Authorization + source: https://semgrep.dev/r/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + shortlink: https://sg.run/LwzJ + semgrep.dev: + rule: + r_id: 9183 + rv_id: 1263032 + rule_id: AbUzwB + version_id: w8TRoNn + url: https://semgrep.dev/playground/r/w8TRoNn/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission + origin: community + pattern-either: + - pattern: java.nio.file.Files.setPosixFilePermissions($FILE, java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/")); + - pattern: | + $TYPE $P = java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/"); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: | + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_READ); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: | + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_WRITE); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); + - pattern: |- + $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_EXECUTE); + ... + java.nio.file.Files.setPosixFilePermissions($FILE, $P); +- id: java.lang.security.audit.permissive-cors.permissive-cors + message: https://find-sec-bugs.github.io/bugs.htm#PERMISSIVE_CORS Permissive CORS + policy will allow a malicious application to communicate with the victim application + in an inappropriate way, leading to spoofing, data theft, relay and other attacks. + metadata: + cwe: + - 'CWE-183: Permissive List of Allowed Inputs' + asvs: + section: 'V14: Configuration Verification Requirements' + control_id: 14.4.8 Permissive CORS + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x22-V14-Config.md#v144-http-security-headers-requirements + version: '4' + category: security + technology: + - java + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Validation + source: https://semgrep.dev/r/java.lang.security.audit.permissive-cors.permissive-cors + shortlink: https://sg.run/8y77 + semgrep.dev: + rule: + r_id: 9184 + rv_id: 1263033 + rule_id: BYUN66 + version_id: xyTjz0p + url: https://semgrep.dev/playground/r/xyTjz0p/java.lang.security.audit.permissive-cors.permissive-cors + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + HttpServletResponse $RES = ...; + ... + $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + HttpServletResponse $RES = ...; + ... + $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + ServerHttpResponse $RES = ...; + ... + $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + HttpHeaders $HEADERS = ...; + ... + $HEADERS.set("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + - pattern: | + ServerWebExchange $SWE = ...; + ... + $SWE.getResponse().getHeaders().add("Access-Control-Allow-Origin", "*"); + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,ServerHttpResponse $RES,...) { + ... + $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: | + $X $METHOD(...,ServerWebExchange $SWE,...) { + ... + $SWE.getResponse().getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); + ... + } + - pattern: ResponseEntity.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") + - pattern: ServerResponse.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") +- id: java.lang.security.audit.script-engine-injection.script-engine-injection + message: Detected potential code injection using ScriptEngine. Ensure user-controlled + data cannot enter '.eval()', otherwise, this is a code injection vulnerability. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SCRIPT_ENGINE_INJECTION + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.lang.security.audit.script-engine-injection.script-engine-injection + shortlink: https://sg.run/gLqn + semgrep.dev: + rule: + r_id: 9185 + rv_id: 1263034 + rule_id: DbUpAr + version_id: O9TpxEp + url: https://semgrep.dev/playground/r/O9TpxEp/java.lang.security.audit.script-engine-injection.script-engine-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS { + ... + ScriptEngine $SE; + ... + } + - pattern-inside: | + class $CLASS { + ... + ScriptEngine $SE = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ScriptEngine $SE = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $SE.eval(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $SE.eval("..."); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $SE.eval($S); + ... + } +- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + message: Application redirects to a destination URL specified by a user-supplied + parameter that is not validated. This could direct users to malicious locations. + Consider using an allowlist to validate URLs. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + asvs: + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + control_id: 5.1.5 Open Redirect + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements + version: '4' + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + impact: LOW + likelihood: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + shortlink: https://sg.run/Q51P + semgrep.dev: + rule: + r_id: 9186 + rv_id: 1263048 + rule_id: WAUo0p + version_id: PkTR329 + url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.sendRedirect($URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.sendRedirect($REQ.getParameter(...)); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + String $URL = $REQ.getParameter(...); + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.addHeader("Location",$URL); + ... + } + - pattern: | + $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } + - pattern: |- + $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { + ... + $RES.addHeader("Location",$REQ.getParameter(...)); + ... + } +- id: java.lang.security.audit.url-rewriting.url-rewriting + message: URL rewriting has significant security risks. Since session ID appears + in the URL, it may be easily seen by third parties. + metadata: + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#URL_REWRITING + category: security + technology: + - java + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Mishandled Sensitive Information + source: https://semgrep.dev/r/java.lang.security.audit.url-rewriting.url-rewriting + shortlink: https://sg.run/3x7b + semgrep.dev: + rule: + r_id: 9187 + rv_id: 1263049 + rule_id: 0oU5j3 + version_id: JdTzxGb + url: https://semgrep.dev/playground/r/JdTzxGb/java.lang.security.audit.url-rewriting.url-rewriting + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeURL(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeUrl(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeRedirectURL(...); + ... + } + - pattern: | + $X $METHOD(...,HttpServletResponse $RES,...) { + ... + $RES.encodeRedirectUrl(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeURL(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeUrl(...); + ... + } + - pattern: | + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeRedirectURL(...); + ... + } + - pattern: |- + $X $METHOD(...) { + ... + HttpServletResponse $RES = ...; + ... + $RES.encodeRedirectUrl(...); + ... + } +- id: java.lang.security.audit.weak-ssl-context.weak-ssl-context + metadata: + cwe: + - 'CWE-326: Inadequate Encryption Strength' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + category: security + technology: + - java + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context + shortlink: https://sg.run/4x7E + semgrep.dev: + rule: + r_id: 9188 + rv_id: 1263050 + rule_id: KxUb1k + version_id: 5PTo1rW + url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context + origin: community + message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL + versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") + for the best security. + severity: WARNING + languages: + - java + patterns: + - pattern-not: SSLContext.getInstance("TLSv1.3") + - pattern-not: SSLContext.getInstance("TLSv1.2") + - pattern: SSLContext.getInstance("...") + fix-regex: + regex: (.*?)\.getInstance\(.*?\) + replacement: \1.getInstance("TLSv1.2") +- id: java.lang.security.audit.xml-decoder.xml-decoder + message: XMLDecoder should not be used to parse untrusted data. Deserializing user + input can lead to arbitrary code execution. Use an alternative and explicitly + disable external entities. See https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + for alternatives and vulnerability prevention. + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XML_DECODER + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.audit.xml-decoder.xml-decoder + shortlink: https://sg.run/PJjq + semgrep.dev: + rule: + r_id: 9189 + rv_id: 1263051 + rule_id: qNUj3y + version_id: GxTkeY1 + url: https://semgrep.dev/playground/r/GxTkeY1/java.lang.security.audit.xml-decoder.xml-decoder + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern: | + $X $METHOD(...) { + ... + new XMLDecoder(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + new XMLDecoder("..."); + ... + } + - pattern-not: |- + $X $METHOD(...) { + ... + String $STR = "..."; + ... + new XMLDecoder($STR); + ... + } +- id: java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + metadata: + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_REQUEST_WRAPPER + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + shortlink: https://sg.run/J96Q + semgrep.dev: + rule: + r_id: 9190 + rv_id: 1263056 + rule_id: lBU9Gj + version_id: WrTqKGK + url: https://semgrep.dev/playground/r/WrTqKGK/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure + origin: community + message: It looks like you're using an implementation of XSSRequestWrapper from + dzone. (https://www.javacodegeeks.com/2012/07/anti-cross-site-scripting-xss-filter.html) + The XSS filtering in this code is not secure and can be bypassed by malicious + actors. It is recommended to use a stack that automatically escapes in your view + or templates instead of filtering yourself. + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + class XSSRequestWrapper extends HttpServletRequestWrapper { + ... + } + - pattern: |- + $P = $X.compile("", $X.CASE_INSENSITIVE); + $V = $P.matcher(...).replaceAll(""); +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + metadata: + cwe: + - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path + Traversal'')' + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + references: + - https://www.owasp.org/index.php/Path_Traversal + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Path Traversal + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + shortlink: https://sg.run/oxXN + semgrep.dev: + rule: + r_id: 9160 + rv_id: 1263064 + rule_id: NbUk7X + version_id: zyTb2rq + url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + origin: community + message: Detected a potential path traversal. A malicious actor could control the + location of this file, to include going backwards in the directory with '../'. + To address this, ensure that user-controlled variables in file paths are sanitized. + You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern: | + (HttpServletRequest $REQ) + - patterns: + - pattern-inside: | + (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); + ... + for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { + ... + } + - pattern: | + $COOKIE.getValue(...) + - patterns: + - pattern-inside: | + $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); + ... + - pattern: | + $PARAM = $VALS[$INDEX]; + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: | + (java.io.File $FILE) = ... + - pattern: | + (java.io.FileOutputStream $FOS) = ... + - pattern: | + new java.io.FileInputStream(...) + severity: ERROR + languages: + - java +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + message: 'Cross-site scripting detected in HttpServletResponse writer with variable + ''$VAR''. User input was detected going directly from the HttpServletRequest into + output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + ''Encode.forHtml($VAR)''.' + metadata: + cwe: + - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site + Scripting'')' + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + category: security + technology: + - java + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site-Scripting (XSS) + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + shortlink: https://sg.run/pxjN + semgrep.dev: + rule: + r_id: 9162 + rv_id: 1263066 + rule_id: wdUJOk + version_id: 2KTv2EG + url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + origin: community + severity: ERROR + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: | + $WRITER = $RESP.getWriter(...); + ... + $WRITER.write(..., $VAR, ...); + languages: + - java +- id: java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + severity: ERROR + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + shortlink: https://sg.run/2x75 + semgrep.dev: + rule: + r_id: 9163 + rv_id: 1263068 + rule_id: x8Unkq + version_id: jQTn5Jv + url: https://semgrep.dev/playground/r/jQTn5Jv/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + origin: community + message: XML external entities are enabled for this XMLInputFactory. This is vulnerable + to XML external entity attacks. Disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" + to false. + patterns: + - pattern-either: + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", + Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + Boolean.TRUE); + languages: + - java +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + severity: WARNING + metadata: + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + category: security + technology: + - java + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: LOW + impact: HIGH + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + shortlink: https://sg.run/XBwA + semgrep.dev: + rule: + r_id: 9164 + rv_id: 1263069 + rule_id: OrU35O + version_id: 1QTypQZ + url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + origin: community + message: XML external entities are not explicitly disabled for this XMLInputFactory. + This could be vulnerable to XML external entity vulnerabilities. Explicitly disable + external entities by setting "javax.xml.stream.isSupportingExternalEntities" to + false. + patterns: + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); + ... + } + - pattern-not-inside: | + $METHOD(...) { + ... + $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); + ... + } + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + languages: + - java +- id: java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + severity: ERROR + metadata: + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://frohoff.github.io/appseccali-marshalling-pickles/ + - https://book.hacktricks.xyz/network-services-pentesting/1099-pentesting-java-rmi + - https://youtu.be/t_aw1mDNhzI + - https://github.com/qtc-de/remote-method-guesser + - https://github.com/openjdk/jdk/blob/master/src/java.rmi/share/classes/sun/rmi/server/UnicastRef.java#L303C4-L331 + category: security + technology: + - rmi + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + shortlink: https://sg.run/zvnl + semgrep.dev: + rule: + r_id: 9217 + rv_id: 1263072 + rule_id: NbUkw5 + version_id: rxTAKN2 + url: https://semgrep.dev/playground/r/rxTAKN2/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + origin: community + message: Using an arbitrary object ('$PARAMTYPE $PARAM') with Java RMI is an insecure + deserialization vulnerability. This object can be manipulated by a malicious actor + allowing them to execute code on your system. Instead, use an integer ID to look + up your object, or consider alternative serialization schemes such as JSON. + languages: + - java + patterns: + - pattern: | + interface $INTERFACE extends Remote { + $RETURNTYPE $METHOD($PARAMTYPE $PARAM) throws RemoteException; + } + - metavariable-pattern: + metavariable: $PARAMTYPE + language: generic + patterns: + - pattern-not: String + - pattern-not: java.lang.String + - pattern-not: boolean + - pattern-not: Boolean + - pattern-not: java.lang.Boolean + - pattern-not: byte + - pattern-not: Byte + - pattern-not: java.lang.Byte + - pattern-not: char + - pattern-not: Character + - pattern-not: java.lang.Character + - pattern-not: double + - pattern-not: Double + - pattern-not: java.lang.Double + - pattern-not: float + - pattern-not: Float + - pattern-not: java.lang.Float + - pattern-not: int + - pattern-not: Integer + - pattern-not: java.lang.Integer + - pattern-not: long + - pattern-not: Long + - pattern-not: java.lang.Long + - pattern-not: short + - pattern-not: Short + - pattern-not: java.lang.Short +- id: java.spring.security.audit.spel-injection.spel-injection + message: A Spring expression is built with a dynamic value. The source of the value(s) + should be verified to avoid that unfiltered values fall into this risky code evaluation. + metadata: + cwe: + - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPEL_INJECTION + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A03_2021-Injection + cwe2022-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/java.spring.security.audit.spel-injection.spel-injection + shortlink: https://sg.run/XBp4 + semgrep.dev: + rule: + r_id: 9220 + rv_id: 1263075 + rule_id: x8Un7b + version_id: kbTzG5Y + url: https://semgrep.dev/playground/r/kbTzG5Y/java.spring.security.audit.spel-injection.spel-injection + origin: community + severity: WARNING + languages: + - java + patterns: + - pattern-either: + - pattern-inside: | + class $CLASS { + ... + ExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + ExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + ExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + class $CLASS { + ... + SpelExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + SpelExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + SpelExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + class $CLASS { + ... + TemplateAwareExpressionParser $PARSER; + ... + } + - pattern-inside: | + class $CLASS { + ... + TemplateAwareExpressionParser $PARSER = ...; + ... + } + - pattern-inside: | + $X $METHOD(...) { + ... + TemplateAwareExpressionParser $PARSER = ...; + ... + } + - pattern: | + $X $METHOD(...) { + ... + $PARSER.parseExpression(...); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + $PARSER.parseExpression("..."); + ... + } + - pattern-not: | + $X $METHOD(...) { + ... + String $S = "..."; + ... + $PARSER.parseExpression($S); + ... + } +- id: java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + message: CSRF protection is disabled for this configuration. This is a security + risk. + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_PROTECTION_DISABLED + asvs: + section: V4 Access Control + control_id: 4.2.2 CSRF + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + version: '4' + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + shortlink: https://sg.run/jRnl + semgrep.dev: + rule: + r_id: 9221 + rv_id: 1263080 + rule_id: OrU3gK + version_id: vdT06dL + url: https://semgrep.dev/playground/r/vdT06dL/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + origin: community + severity: WARNING + languages: + - java + pattern: $OBJ.csrf(...).disable(...) +- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + message: Application redirects a user to a destination URL specified by a user supplied + parameter that is not validated. + metadata: + cwe: + - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + category: security + technology: + - spring + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Open Redirect + source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + shortlink: https://sg.run/9oXz + semgrep.dev: + rule: + r_id: 9223 + rv_id: 1263083 + rule_id: v8Un7w + version_id: nWT2Lk0 + url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + origin: community + severity: WARNING + languages: + - java + pattern-either: + - pattern: | + $X $METHOD(...,String $URL,...) { + return "redirect:" + $URL; + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + return $REDIR; + ... + } + - pattern: | + $X $METHOD(...,String $URL,...) { + ... + new ModelAndView("redirect:" + $URL); + ... + } + - pattern: |- + $X $METHOD(...,String $URL,...) { + ... + String $REDIR = "redirect:" + $URL; + ... + new ModelAndView($REDIR); + ... + } +- id: java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + patterns: + - pattern-inside: | + @RequestMapping(...) + $RETURNTYPE $METHOD(...) { ... } + - pattern-not-inside: | + @RequestMapping(..., method = $X, ...) + $RETURNTYPE $METHOD(...) { ... } + - pattern: | + RequestMapping + message: Detected a method annotated with 'RequestMapping' that does not specify + the HTTP method. CSRF protections are not enabled for GET, HEAD, TRACE, or OPTIONS, + and by default all HTTP methods are allowed when the HTTP method is not explicitly + specified. This means that a method that performs state changes could be vulnerable + to CSRF attacks. To mitigate, add the 'method' field and specify the HTTP method + (such as 'RequestMethod.POST'). + severity: WARNING + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + references: + - https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + category: security + technology: + - spring + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + shortlink: https://sg.run/2xlq + semgrep.dev: + rule: + r_id: 9219 + rv_id: 1263089 + rule_id: wdUJ7q + version_id: QkTGq2l + url: https://semgrep.dev/playground/r/QkTGq2l/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + origin: community + languages: + - java +- id: javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + message: Found an insecure gRPC connection. This creates a connection without encryption + to a gRPC client/server. A malicious attacker could tamper with the gRPC message, + which could compromise the machine. + metadata: + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + category: security + technology: + - grpc + references: + - https://blog.gopheracademy.com/advent-2017/go-grpc-beyond-basics/#:~:text=disables%20transport%20security + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - 'Insecure Deserialization ' + source: https://semgrep.dev/r/javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + shortlink: https://sg.run/5QkD + semgrep.dev: + rule: + r_id: 9291 + rv_id: 1263180 + rule_id: lBU9D8 + version_id: e1TyjAl + url: https://semgrep.dev/playground/r/e1TyjAl/javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern-either: + - pattern: | + require('grpc'); + ... + $GRPC($ADDR,...,$CREDENTIALS.createInsecure(),...); + - pattern: | + require('grpc'); + ... + new $GRPC($ADDR,...,$CREDENTIALS.createInsecure(),...); + - pattern: |- + require('grpc'); + ... + $CREDS = <... $CREDENTIALS.createInsecure() ...>; + ... + $GRPC($ADDR,...,$CREDS,...); + - pattern: |- + require('grpc'); + ... + $CREDS = <... $CREDENTIALS.createInsecure() ...>; + ... + new $GRPC($ADDR,...,$CREDS,...); +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + interfile: true + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/Ro1g + semgrep.dev: + rule: + r_id: 9293 + rv_id: 1263182 + rule_id: JDUyRl + version_id: d6TyxbX + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-inside: | + $JOSE = require("jose"); + ... + - pattern-either: + - pattern-inside: | + var {JWT} = $JOSE; + ... + - pattern-inside: | + var {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + const {JWT} = $JOSE; + ... + - pattern-inside: | + const {JWK, JWT} = $JOSE; + ... + - pattern-inside: | + let {JWT} = $JOSE; + ... + - pattern-inside: | + let {JWK, JWT} = $JOSE; + ... + - pattern-either: + - pattern: | + JWT.verify($P, "...", ...); + - pattern: | + JWT.sign($P, "...", ...); + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: | + $JWT.sign($P, JWK.asKey("..."), ...); + options: + symbolic_propagation: true + interfile: true +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jose + - jwt + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + shortlink: https://sg.run/AvRL + semgrep.dev: + rule: + r_id: 9294 + rv_id: 1263183 + rule_id: 5rUOGN + version_id: ZRTKAyb + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + origin: community + languages: + - javascript + - typescript + severity: ERROR + pattern-either: + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + var $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + $T = JWT.verify($P, JWK.None,...); + - pattern: | + var $JOSE = require("jose"); + ... + var { JWK, JWT } = $JOSE; + ... + JWT.verify($P, JWK.None,...); +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + message: A hard-coded credential was detected. It is not recommended to store credentials + in source-code, as this risks secrets being leaked and used by either an internal + or external malicious adversary. It is recommended to use environment variables + to securely provide credentials or retrieve credentials from a secure vault or + HSM (Hardware Security Module). + metadata: + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.2 Static API keys or secret + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + - javascript + - secrets + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - vuln + likelihood: HIGH + impact: MEDIUM + confidence: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Hard-coded Secrets + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + shortlink: https://sg.run/4xN9 + semgrep.dev: + rule: + r_id: 9300 + rv_id: 1263189 + rule_id: WAUon7 + version_id: gETB75D + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,"...",...); + - pattern-inside: | + $JWT.verify($DATA,"...",...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $JWT = require("jsonwebtoken") + ... + - pattern-inside: | + import $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import * as $JWT from "jsonwebtoken" + ... + - pattern-inside: | + import {...,$JWT,...} from "jsonwebtoken" + ... + - pattern-either: + - pattern-inside: | + $JWT.sign($DATA,$VALUE,...); + - pattern-inside: | + $JWT.verify($DATA,$VALUE,...); + - focus-metavariable: $VALUE +- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm + assumes the integrity of the token has already been verified. This would allow + a malicious actor to forge a JWT token that will automatically be verified. Do + not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + asvs: + section: 'V3: Session Management Verification Requirements' + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + version: '4' + category: security + technology: + - jwt + subcategory: + - vuln + likelihood: MEDIUM + impact: HIGH + confidence: MEDIUM + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + shortlink: https://sg.run/PJXv + semgrep.dev: + rule: + r_id: 9301 + rv_id: 1263190 + rule_id: 0oU53g + version_id: QkTGqQo + url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-inside: | + $JWT = require("jsonwebtoken"); + ... + - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) +- id: javascript.lang.security.detect-buffer-noassert.detect-buffer-noassert + message: Detected usage of noassert in Buffer API, which allows the offset the be + beyond the end of the buffer. This could result in writing or reading beyond the + end of the buffer. + metadata: + cwe: + - 'CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer' + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-buffer-noassert.js + category: security + technology: + - javascript + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + references: + - https://cwe.mitre.org/data/definitions/119.html + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Memory Issues + source: https://semgrep.dev/r/javascript.lang.security.detect-buffer-noassert.detect-buffer-noassert + shortlink: https://sg.run/qxpO + semgrep.dev: + rule: + r_id: 9312 + rv_id: 945886 + rule_id: j2Uvj8 + version_id: 9lTy1Y6 + url: https://semgrep.dev/playground/r/9lTy1Y6/javascript.lang.security.detect-buffer-noassert.detect-buffer-noassert + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern: $OBJ.$API(..., true) + - metavariable-regex: + metavariable: $API + regex: (read|write)(U?Int8|(U?Int(16|32)|Float|Double)(LE|BE)) +- id: javascript.lang.security.detect-child-process.detect-child-process + message: 'Detected calls to child_process from a function argument `$FUNC`. This + could lead to a command injection if the input is user controllable. Try to avoid + calls to child_process, and if it is needed ensure user input is correctly sanitized + or sandboxed. ' + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html#do-not-use-dangerous-functions + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-child-process.js + category: security + technology: + - javascript + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: HIGH + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.lang.security.detect-child-process.detect-child-process + shortlink: https://sg.run/l2lo + semgrep.dev: + rule: + r_id: 9313 + rv_id: 1409399 + rule_id: 10UKNB + version_id: 5PT7KnG + url: https://semgrep.dev/playground/r/5PT7KnG/javascript.lang.security.detect-child-process.detect-child-process + origin: community + languages: + - javascript + - typescript + severity: ERROR + mode: taint + pattern-sources: + - patterns: + - pattern-inside: | + function ... (...,$FUNC,...) { + ... + } + - focus-metavariable: $FUNC + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: | + $CP = require('child_process') + ... + - pattern-inside: | + import * as $CP from 'child_process' + ... + - pattern-inside: | + import $CP from 'child_process' + ... + - pattern-either: + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-not-inside: $CP.$EXEC("...",...) + - pattern-not-inside: $CP.$EXEC(["...",...],...) + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-not-inside: | + $CMD = ["...",...] + ... + - focus-metavariable: $CMD + - patterns: + - pattern-either: + - pattern: child_process.exec($CMD,...) + - pattern: child_process.execSync($CMD,...) + - pattern: child_process.spawn($CMD,...) + - pattern: child_process.spawnSync($CMD,...) + - pattern-not-inside: child_process.$EXEC("...",...) + - pattern-not-inside: child_process.$EXEC(["...",...],...) + - pattern-not-inside: | + $CMD = "..." + ... + - pattern-not-inside: | + $CMD = ["...",...] + ... + - focus-metavariable: $CMD +- id: javascript.lang.security.detect-disable-mustache-escape.detect-disable-mustache-escape + message: Markup escaping disabled. This can be used with some template engines to + escape disabling of HTML entities, which can lead to XSS attacks. + metadata: + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-disable-mustache-escape.js + category: security + technology: + - mustache + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Improper Encoding + source: https://semgrep.dev/r/javascript.lang.security.detect-disable-mustache-escape.detect-disable-mustache-escape + shortlink: https://sg.run/Yvwd + semgrep.dev: + rule: + r_id: 9314 + rv_id: 1263213 + rule_id: 9AU17r + version_id: DkTRb3X + url: https://semgrep.dev/playground/r/DkTRb3X/javascript.lang.security.detect-disable-mustache-escape.detect-disable-mustache-escape + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern: $OBJ.escapeMarkup = false +- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + message: Detected use of dynamic execution of JavaScript which may come from user-input, + which can lead to Cross-Site-Scripting (XSS). Where possible avoid including user-input + in functions which dynamically execute user-input. + metadata: + cwe: + - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code + (''Eval Injection'')' + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval! + category: security + technology: + - javascript + subcategory: + - vuln + likelihood: MEDIUM + impact: MEDIUM + confidence: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Code Injection + source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + shortlink: https://sg.run/6nwK + semgrep.dev: + rule: + r_id: 9315 + rv_id: 1263214 + rule_id: yyUngo + version_id: WrTqKkJ + url: https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + origin: community + languages: + - javascript + - typescript + severity: WARNING + mode: taint + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: | + $PROP = new URLSearchParams($WINDOW. ... .location.search).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams(location.search).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') + ... + - pattern-inside: | + $PROP = new URLSearchParams(location.hash.substring(1)).get('...') + ... + - focus-metavariable: $PROP + - patterns: + - pattern-either: + - pattern-inside: | + $PROPS = new URLSearchParams($WINDOW. ... .location.search) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.search) + ... + - pattern-inside: | + $PROPS = new + URLSearchParams($WINDOW. ... .location.hash.substring(1)) + ... + - pattern-inside: | + $PROPS = new URLSearchParams(location.hash.substring(1)) + ... + - pattern: $PROPS.get('...') + - focus-metavariable: $PROPS + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval(<... $SINK ...>) + - pattern: window.eval(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>)(...) + - pattern: setTimeout(<... $SINK ...>,...) + - pattern: setInterval(<... $SINK ...>,...) + - focus-metavariable: $SINK + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: location.href = $FUNC(...) + - pattern: location.hash = $FUNC(...) + - pattern: location.search = $FUNC(...) + - pattern: $WINDOW. ... .location.href = $FUNC(...) + - pattern: $WINDOW. ... .location.hash = $FUNC(...) + - pattern: $WINDOW. ... .location.search = $FUNC(...) +- id: javascript.lang.security.detect-no-csrf-before-method-override.detect-no-csrf-before-method-override + message: Detected use of express.csrf() middleware before express.methodOverride(). + This can allow GET requests (which are not checked by csrf) to turn into POST + requests later. + metadata: + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-no-csrf-before-method-override.js + references: + - https://github.com/nodesecurity/eslint-plugin-security/blob/master/docs/bypass-connect-csrf-protection-by-abusing.md + category: security + technology: + - javascript + owasp: + - A01:2021 - Broken Access Control + - A05:2017 - Broken Access Control + - A01:2025 - Broken Access Control + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + source: https://semgrep.dev/r/javascript.lang.security.detect-no-csrf-before-method-override.detect-no-csrf-before-method-override + shortlink: https://sg.run/oxoX + semgrep.dev: + rule: + r_id: 9316 + rv_id: 1263216 + rule_id: r6UrvQ + version_id: K3TKkPO + url: https://semgrep.dev/playground/r/K3TKkPO/javascript.lang.security.detect-no-csrf-before-method-override.detect-no-csrf-before-method-override + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern: | + express.csrf(); + ... + express.methodOverride(); +- id: javascript.lang.security.detect-pseudorandombytes.detect-pseudoRandomBytes + message: Detected usage of crypto.pseudoRandomBytes, which does not produce secure + random numbers. + metadata: + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-pseudoRandomBytes.js + asvs: + section: 'V6: Stored Cryptography Verification Requirements' + control_id: 6.3.1 Insecure Randomness + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values + version: '4' + category: security + technology: + - javascript + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Cryptographic Issues + source: https://semgrep.dev/r/javascript.lang.security.detect-pseudorandombytes.detect-pseudoRandomBytes + shortlink: https://sg.run/pxze + semgrep.dev: + rule: + r_id: 9318 + rv_id: 1263217 + rule_id: NbUkR2 + version_id: qkTR799 + url: https://semgrep.dev/playground/r/qkTR799/javascript.lang.security.detect-pseudorandombytes.detect-pseudoRandomBytes + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern: crypto.pseudoRandomBytes +- id: javascript.lang.security.spawn-git-clone.spawn-git-clone + message: Git allows shell commands to be specified in ext URLs for remote repositories. + For example, git clone 'ext::sh -c whoami% >&2' will execute the whoami command + to try to connect to a remote repository. Make sure that the URL is not controlled + by external input. + metadata: + cwe: + - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS + Command Injection'')' + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + category: security + technology: + - git + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A03_2021-Injection + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - Command Injection + source: https://semgrep.dev/r/javascript.lang.security.spawn-git-clone.spawn-git-clone + shortlink: https://sg.run/2xrr + semgrep.dev: + rule: + r_id: 9319 + rv_id: 1263220 + rule_id: kxUkPP + version_id: 6xT29A7 + url: https://semgrep.dev/playground/r/6xT29A7/javascript.lang.security.spawn-git-clone.spawn-git-clone + origin: community + languages: + - javascript + - typescript + severity: ERROR + patterns: + - pattern-either: + - pattern: spawn('git', ['clone',...,$F]) + - pattern: $X.spawn('git', ['clone',...,$F]) + - pattern: spawn('git', ['clone',...,$P,$F]) + - pattern: $X.spawn('git', ['clone',...,$P,$F]) + - pattern-not: spawn('git', ['clone',...,"..."]) + - pattern-not: $X.spawn('git', ['clone',...,"..."]) + - pattern-not: spawn('git', ['clone',...,"...","..."]) + - pattern-not: $X.spawn('git', ['clone',...,"...","..."]) +- id: javascript.node-expat.security.audit.expat-xxe.expat-xxe + message: If unverified user data can reach the XML Parser it can result in XML External + or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + category: security + technology: + - node-expat + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: MEDIUM + confidence: LOW + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.node-expat.security.audit.expat-xxe.expat-xxe + shortlink: https://sg.run/eLdL + semgrep.dev: + rule: + r_id: 9332 + rv_id: 1263224 + rule_id: gxU171 + version_id: 2KTv2AZ + url: https://semgrep.dev/playground/r/2KTv2AZ/javascript.node-expat.security.audit.expat-xxe.expat-xxe + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern-either: + - pattern: | + var $EXPAT = require('node-expat'); + ... + new $EXPAT.Parser(...); + ... + $PARSER.parse(...); + - pattern: | + var $EXPAT = require('node-expat'); + ... + new $EXPAT.Parser(...); + ... + $PARSER.write(...); + - pattern: | + require('node-expat'); + ... + new Parser(...); + ... + $PARSER.parse(...); + - pattern: | + require('node-expat'); + ... + new Parser(...); + ... + $PARSER.write(...); + - pattern-not: | + var $EXPAT = require('node-expat'); + ... + new $EXPAT.Parser(...); + ... + $PARSER.parse("..."); + - pattern-not: | + var $EXPAT = require('node-expat'); + ... + new $EXPAT.Parser(...); + ... + $PARSER.write("..."); + - pattern-not: | + require('node-expat'); + ... + new Parser(...); + ... + $PARSER.parse("..."); + - pattern-not: | + require('node-expat'); + ... + new Parser(...); + ... + $PARSER.write("..."); + - pattern-not: | + $X = "..."; + ... + $PARSER.parse($X); + - pattern-not: |- + $X = "..."; + ... + $PARSER.write($X); +- id: javascript.sax.security.audit.sax-xxe.sax-xxe + message: Use of 'ondoctype' in 'sax' library detected. By default, 'sax' won't do + anything with custom DTD entity definitions. If you're implementing a custom DTD + entity definition, be sure not to introduce XML External Entity (XXE) vulnerabilities, + or be absolutely sure that external entities received from a trusted source while + processing XML. + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + references: + - https://github.com/Leonidas-from-XIV/node-xml2js/issues/415 + - https://github.com/isaacs/sax-js + category: security + technology: + - sax + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.sax.security.audit.sax-xxe.sax-xxe + shortlink: https://sg.run/5QEj + semgrep.dev: + rule: + r_id: 9347 + rv_id: 1263239 + rule_id: qNUj7e + version_id: d6Tyxn9 + url: https://semgrep.dev/playground/r/d6Tyxn9/javascript.sax.security.audit.sax-xxe.sax-xxe + origin: community + languages: + - javascript + - typescript + severity: WARNING + pattern-either: + - pattern: | + require('sax'); + ... + $PARSER.ondoctype = ...; + - pattern: |- + require('sax'); + ... + $PARSER.on('doctype',...); +- id: javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + message: If unverified user data can reach the XML Parser it can result in XML External + or Internal Entity (XXE) Processing vulnerabilities + metadata: + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + asvs: + section: V5 Validation, Sanitization and Encoding + control_id: 5.5.2 Insecue XML Deserialization + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + version: '4' + category: security + technology: + - xml2json + cwe2022-top25: true + cwe2021-top25: true + subcategory: + - audit + likelihood: LOW + impact: LOW + confidence: LOW + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + vulnerability_class: + - XML Injection + source: https://semgrep.dev/r/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + shortlink: https://sg.run/l27o + semgrep.dev: + rule: + r_id: 9357 + rv_id: 1263253 + rule_id: 10UKpB + version_id: GxTkeg8 + url: https://semgrep.dev/playground/r/GxTkeg8/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe + origin: community + languages: + - javascript + - typescript + severity: WARNING + patterns: + - pattern: | + var $XML = require('xml2json'); + ... + $XML.toJson(...); + - pattern-not: | + var $XML = require('xml2json'); + ... + $XML.toJson("...",...); + - pattern-not: |- + var $XML = require('xml2json'); + ... + var $S = "..."; + ... + $XML.toJson($S,...); +- id: javascript.lang.security.audit.unknown-value-with-script-tag.unknown-value-with-script-tag + message: Cannot determine what '$UNK' is and it is used with a ' + - pattern-not-inside: