rules: - id: c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn pattern: gets(...) message: Avoid 'gets()'. This function does not consider buffer boundaries and can lead to buffer overflows. Use 'fgets()' or 'gets_s()' instead. metadata: cwe: - 'CWE-676: Use of Potentially Dangerous Function' references: - https://us-cert.cisa.gov/bsi/articles/knowledge/coding-practices/fgets-and-gets_s category: security technology: - c confidence: MEDIUM subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn shortlink: https://sg.run/dKqX semgrep.dev: rule: r_id: 8834 rv_id: 945170 rule_id: GdU7OE version_id: YDTvRlQ url: https://semgrep.dev/playground/r/YDTvRlQ/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn origin: community languages: - c severity: ERROR - id: c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn pattern: scanf(...) message: Avoid using 'scanf()'. This function, when used improperly, does not consider buffer boundaries and can lead to buffer overflows. Use 'fgets()' instead for reading input. metadata: cwe: - 'CWE-676: Use of Potentially Dangerous Function' references: - http://sekrit.de/webdocs/c/beginners-guide-away-from-scanf.html category: security technology: - c confidence: LOW subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn shortlink: https://sg.run/nd1g semgrep.dev: rule: r_id: 8836 rv_id: 945173 rule_id: AbUzPd version_id: zyTlkWW url: https://semgrep.dev/playground/r/zyTlkWW/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn origin: community languages: - c severity: WARNING - id: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn pattern: strtok(...) message: Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead. metadata: cwe: - 'CWE-676: Use of Potentially Dangerous Function' references: - https://wiki.sei.cmu.edu/confluence/display/c/STR06-C.+Do+not+assume+that+strtok%28%29+leaves+the+parse+string+unchanged - https://man7.org/linux/man-pages/man3/strtok.3.html#BUGS - https://stackoverflow.com/a/40335556 category: security technology: - c confidence: LOW subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn shortlink: https://sg.run/LwqG semgrep.dev: rule: r_id: 8839 rv_id: 1028278 rule_id: WAUo5v version_id: qkTx1oq url: https://semgrep.dev/playground/r/qkTx1oq/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn origin: community languages: - c severity: WARNING - id: c.lang.security.random-fd-exhaustion.random-fd-exhaustion pattern-either: - patterns: - pattern: | $FD = open("/dev/urandom", ...); ... read($FD, ...); - pattern-not: | $FD = open("/dev/urandom", ...); ... $BYTES_READ = read($FD, ...); - patterns: - pattern: | $FD = open("/dev/random", ...); ... read($FD, ...); - pattern-not: | $FD = open("/dev/random", ...); ... $BYTES_READ = read($FD, ...); message: Call to 'read()' without error checking is susceptible to file descriptor exhaustion. Consider using the 'getrandom()' function. metadata: cwe: - 'CWE-774: Allocation of File Descriptors or Handles Without Limits or Throttling' references: - https://lwn.net/Articles/606141/ category: security technology: - c confidence: MEDIUM subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/c.lang.security.random-fd-exhaustion.random-fd-exhaustion shortlink: https://sg.run/8yNj semgrep.dev: rule: r_id: 8840 rv_id: 945177 rule_id: 0oU5k4 version_id: jQTzvry url: https://semgrep.dev/playground/r/jQTzvry/c.lang.security.random-fd-exhaustion.random-fd-exhaustion origin: community languages: - c severity: WARNING - id: generic.nginx.security.alias-path-traversal.alias-path-traversal patterns: - pattern: | location $...LOCATION { ... alias .../; ... } - metavariable-pattern: metavariable: $...LOCATION pattern-regex: ^.*[^/]$ paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' fix-regex: regex: location\s+([A-Za-z0-9/-_\.]+) replacement: location \1/ languages: - generic severity: WARNING message: The alias in this location block is subject to a path traversal because the location path does not end in a path separator (e.g., '/'). To fix, add a path separator to the end of the path. metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md category: security technology: - nginx confidence: LOW owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control - https://www.acunetix.com/vulnerabilities/web/path-traversal-via-misconfigured-nginx-alias/ - https://www.youtube.com/watch?v=CIhHpkybYsY - https://github.com/orangetw/My-Presentation-Slides/blob/main/data/2018-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out.pdf cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/generic.nginx.security.alias-path-traversal.alias-path-traversal shortlink: https://sg.run/ZvNL semgrep.dev: rule: r_id: 9035 rv_id: 1262670 rule_id: 5rUOjq version_id: NdTzyBg url: https://semgrep.dev/playground/r/NdTzyBg/generic.nginx.security.alias-path-traversal.alias-path-traversal origin: community - id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: The host for this proxy URL is dynamically determined. This can be dangerous if the host can be injected by an attacker because it may forcibly alter destination of the proxy. Consider hardcoding acceptable destinations and retrieving them with 'map' or something similar. metadata: source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md references: - https://nginx.org/en/docs/http/ngx_http_map_module.html category: security technology: - nginx confidence: MEDIUM cwe: - 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host shortlink: https://sg.run/ndpb semgrep.dev: rule: r_id: 9036 rv_id: 1262671 rule_id: GdU7yl version_id: kbTzG2j url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host origin: community pattern-either: - pattern: proxy_pass $SCHEME://$$HOST ...; - pattern: proxy_pass $$SCHEME://$$HOST ...; - id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: The protocol scheme for this proxy is dynamically determined. This can be dangerous if the scheme can be injected by an attacker because it may forcibly alter the connection scheme. Consider hardcoding a scheme for this proxy. metadata: cwe: - 'CWE-16: CWE CATEGORY: Configuration' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md category: security technology: - nginx confidence: MEDIUM owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme shortlink: https://sg.run/EkAo semgrep.dev: rule: r_id: 9037 rv_id: 1262672 rule_id: ReUg7n version_id: w8TRoAJ url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme origin: community pattern: proxy_pass $$SCHEME:// ...; - id: generic.nginx.security.header-injection.header-injection pattern: | location ... <$VARIABLE> ... { ... add_header ... $$VARIABLE ... } paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: ERROR message: 'The $$VARIABLE path parameter is added as a header in the response. This could allow an attacker to inject a newline and add a new header into the response. This is called HTTP response splitting. To fix, do not allow whitespace in the path parameter: ''[^\s]+''.' metadata: cwe: - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP Request/Response Splitting'')' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md - https://owasp.org/www-community/attacks/HTTP_Response_Splitting category: security technology: - nginx confidence: MEDIUM owasp: - A03:2021 - Injection - A05:2025 - Injection subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection shortlink: https://sg.run/7oj4 semgrep.dev: rule: r_id: 9038 rv_id: 1262673 rule_id: AbUz8p version_id: xyTjzNW url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection origin: community - id: generic.nginx.security.header-redefinition.header-redefinition patterns: - pattern-inside: | server { ... add_header ...; ... ... } - pattern-inside: | location ... { ... ... } - pattern: add_header ...; paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: The 'add_header' directive is called in a 'location' block after headers have been set at the server block. Calling 'add_header' in the location block will actually overwrite the headers defined in the server block, no matter which headers are set. To fix this, explicitly set all headers or set all headers in the server block. metadata: cwe: - 'CWE-16: CWE CATEGORY: Configuration' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/addheaderredefinition.md category: security technology: - nginx confidence: LOW owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/generic.nginx.security.header-redefinition.header-redefinition shortlink: https://sg.run/Lwl7 semgrep.dev: rule: r_id: 9039 rv_id: 1262674 rule_id: BYUN58 version_id: O9TpxJD url: https://semgrep.dev/playground/r/O9TpxJD/generic.nginx.security.header-redefinition.header-redefinition origin: community - id: generic.nginx.security.insecure-redirect.insecure-redirect patterns: - pattern-either: - pattern: rewrite ... redirect - pattern: rewrite ... permanent - pattern-not-inside: rewrite ... https ... $host ... redirect - pattern-not-inside: rewrite ... https ... $host ... permanent - pattern-not-regex: (?i)https:\/\/ paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' message: Detected an insecure redirect in this nginx configuration. If no scheme is specified, nginx will forward the request with the incoming scheme. This could result in unencrypted communications. To fix this, include the 'https' scheme. languages: - generic severity: WARNING metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - nginx confidence: LOW owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/generic.nginx.security.insecure-redirect.insecure-redirect shortlink: https://sg.run/8y14 semgrep.dev: rule: r_id: 9040 rv_id: 1262675 rule_id: DbUpJe version_id: e1TyjDz url: https://semgrep.dev/playground/r/e1TyjDz/generic.nginx.security.insecure-redirect.insecure-redirect origin: community - id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version patterns: - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; - pattern-not: ssl_protocols TLSv1.2; - pattern-not: ssl_protocols TLSv1.3; - pattern: ssl_protocols ...; paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 and TLS1.3; older versions are known to be broken and are susceptible to attacks. Prefer use of TLSv1.2 or later. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ category: security technology: - nginx confidence: HIGH owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version shortlink: https://sg.run/gLKy semgrep.dev: rule: r_id: 9041 rv_id: 1262676 rule_id: WAUo9k version_id: vdT06O4 url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version origin: community - id: generic.nginx.security.missing-internal.missing-internal options: generic_ellipsis_max_span: 0 generic_engine: aliengrep patterns: - pattern-inside: | location ... { .... .... } - pattern-not-inside: | location ... { .... internal; .... } - pattern: proxy_pass $...URL; - metavariable-regex: metavariable: $...URL regex: (.*\$.*) paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: This location block contains a 'proxy_pass' directive but does not contain the 'internal' directive. The 'internal' directive restricts access to this location to internal requests. Without 'internal', an attacker could use your server for server-side request forgeries (SSRF). Include the 'internal' directive in this block to limit exposure. metadata: cwe: - 'CWE-16: CWE CATEGORY: Configuration' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md - https://nginx.org/en/docs/http/ngx_http_core_module.html#internal category: security technology: - nginx confidence: LOW owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/generic.nginx.security.missing-internal.missing-internal shortlink: https://sg.run/Q5px semgrep.dev: rule: r_id: 9042 rv_id: 1262677 rule_id: 0oU5BZ version_id: d6TyxKK url: https://semgrep.dev/playground/r/d6TyxKK/generic.nginx.security.missing-internal.missing-internal origin: community - id: generic.nginx.security.missing-ssl-version.missing-ssl-version patterns: - pattern: server { ... listen $PORT ssl; ... } - pattern-not-inside: server { ... ssl_protocols ... } paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: This server configuration is missing the 'ssl_protocols' directive. By default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2 TLSv1.3' to use secure TLS versions. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ - https://nginx.org/en/docs/http/configuring_https_servers.html category: security technology: - nginx confidence: MEDIUM owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version shortlink: https://sg.run/3xzl semgrep.dev: rule: r_id: 9043 rv_id: 1262678 rule_id: KxUbeA version_id: ZRTKAle url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version origin: community - id: generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token pattern-regex: amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12} languages: - regex message: Amazon MWS Auth Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - aws confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token shortlink: https://sg.run/PJzE semgrep.dev: rule: r_id: 9045 rv_id: 1262856 rule_id: lBU9bw version_id: K3TKkGj url: https://semgrep.dev/playground/r/K3TKkGj/generic.secrets.security.detected-amazon-mws-auth-token.detected-amazon-mws-auth-token origin: community - id: generic.secrets.security.detected-artifactory-password.detected-artifactory-password patterns: - pattern-regex: (?\bAP[\dABCDEF][a-zA-Z0-9]{8,}) - pattern-regex: .*(?i)arti[-_]?factory.* - pattern-not-regex: .*(?i)sha(1|2|3|118|256|512).* - pattern-not-regex: (?i)-----\s*?BEGIN[ A-Z0-9_-]*? KEY( BLOCK)?-----[\s\S]*?-----\s*?END[ A-Z0-9_-]*?\s*?----- - metavariable-analysis: analyzer: entropy metavariable: $ITEM - pattern-not-regex: (\w|\.|\*)\1{4} languages: - regex paths: exclude: - '*.svg' - '*go.sum' - '*package.json' - '*cargo.lock' - '*package-lock.json' - '*bundle.js' - '*pnpm-lock*' - '*Podfile.lock' - '**/*/openssl/*.h' - '*.xcscmblueprint' message: Artifactory token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/artifactory.py category: security technology: - secrets - artifactory confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-artifactory-password.detected-artifactory-password shortlink: https://sg.run/J9KZ semgrep.dev: rule: r_id: 9046 rv_id: 1262857 rule_id: YGUR5K version_id: qkTR7BB url: https://semgrep.dev/playground/r/qkTR7BB/generic.secrets.security.detected-artifactory-password.detected-artifactory-password origin: community - id: generic.secrets.security.detected-artifactory-token.detected-artifactory-token patterns: - pattern-regex: | \bAKC[a-zA-Z0-9]{10,} - pattern-not-regex: | sha(128|256|512).* - pattern-not-regex: (?s)---BEGIN.*---\Z languages: - regex paths: exclude: - '*.svg' - '*go.sum' - '*package.json' - '*package-lock.json' - '*bundle.js' - '*pnpm-lock*' - '*Podfile.lock' - '**/*/openssl/*.h' - '*.xcscmblueprint' - '*cargo.lock' message: Artifactory token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/artifactory.py category: security technology: - secrets - artifactory confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-artifactory-token.detected-artifactory-token shortlink: https://sg.run/5Q2l semgrep.dev: rule: r_id: 9047 rv_id: 1262858 rule_id: 6JUj3l version_id: l4TJR6J url: https://semgrep.dev/playground/r/l4TJR6J/generic.secrets.security.detected-artifactory-token.detected-artifactory-token origin: community - id: generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value patterns: - pattern-regex: \b(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}\b - pattern-not-regex: (?i)example|sample|test|fake languages: - regex message: AWS Access Key ID Value detected. This is a sensitive credential and should not be hardcoded here. Instead, read this value from an environment variable or keep it in a separate, private file. severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - aws confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value shortlink: https://sg.run/GeD1 semgrep.dev: rule: r_id: 9048 rv_id: 1262859 rule_id: oqUevO version_id: YDTZenE url: https://semgrep.dev/playground/r/YDTZenE/generic.secrets.security.detected-aws-access-key-id-value.detected-aws-access-key-id-value origin: community - id: generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key pattern-regex: da2-[a-z0-9]{26} languages: - regex message: AWS AppSync GraphQL Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - appsync confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key shortlink: https://sg.run/AvJ6 semgrep.dev: rule: r_id: 9050 rv_id: 1262861 rule_id: pKUOoZ version_id: o5TbD9o url: https://semgrep.dev/playground/r/o5TbD9o/generic.secrets.security.detected-aws-appsync-graphql-key.detected-aws-appsync-graphql-key origin: community - id: generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key patterns: - pattern-regex: (("|'|`)?((?i)aws)_?\w*((?i)secret)_?\w*("|'|`)?\s{0,50}(:|=>|=)\s{0,50}("|'|`)?[A-Za-z0-9/+=]{40}("|'|`)?) - pattern-not-regex: (?i)example|sample|test|fake|xxxxxx languages: - regex message: AWS Secret Access Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - aws confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key shortlink: https://sg.run/Bk39 semgrep.dev: rule: r_id: 9051 rv_id: 1262862 rule_id: 2ZUbe8 version_id: zyTb2Dr url: https://semgrep.dev/playground/r/zyTb2Dr/generic.secrets.security.detected-aws-secret-access-key.detected-aws-secret-access-key origin: community - id: generic.secrets.security.detected-aws-session-token.detected-aws-session-token patterns: - pattern-regex: ((?i)AWS_SESSION_TOKEN)\s*(:|=>|=)\s*(?P[A-Za-z0-9/+=]{16,}) - pattern-not-regex: (?i)example|sample|test|fake - metavariable-analysis: analyzer: entropy metavariable: $TOKEN languages: - regex message: AWS Session Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - aws confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-aws-session-token.detected-aws-session-token shortlink: https://sg.run/DoRW semgrep.dev: rule: r_id: 9052 rv_id: 1262863 rule_id: X5U8Er version_id: pZT03Lx url: https://semgrep.dev/playground/r/pZT03Lx/generic.secrets.security.detected-aws-session-token.detected-aws-session-token origin: community - id: generic.secrets.security.detected-codeclimate.detected-codeclimate pattern-regex: (?i)codeclima.{0,50}["|'|`]?[0-9a-f]{64}["|'|`]? languages: - regex message: CodeClimate detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - codeclimate confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-codeclimate.detected-codeclimate shortlink: https://sg.run/W8yz semgrep.dev: rule: r_id: 9053 rv_id: 1262865 rule_id: j2UvW7 version_id: X0Tzy2o url: https://semgrep.dev/playground/r/X0Tzy2o/generic.secrets.security.detected-codeclimate.detected-codeclimate origin: community - id: generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token pattern-either: - pattern-regex: EAACEdEose0cBA[0-9A-Za-z]+ - pattern-regex: EAAAACZAVC6ygB[0-9A-Za-z]+ - pattern-regex: EAAAAZAw4[0-9A-Za-z]+ languages: - regex message: Facebook Access Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - facebook confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token shortlink: https://sg.run/0QYJ semgrep.dev: rule: r_id: 9054 rv_id: 1262867 rule_id: 10UKBL version_id: 1QTyp7J url: https://semgrep.dev/playground/r/1QTyp7J/generic.secrets.security.detected-facebook-access-token.detected-facebook-access-token origin: community - id: generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth pattern-regex: '[fF][aA][cC][eE][bB][oO][oO][kK].*[tT][oO][kK][eE][nN].*[''|"]?[0-9a-f]{32}[''|"]?' languages: - regex message: Facebook OAuth detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - facebook confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth shortlink: https://sg.run/Klq6 semgrep.dev: rule: r_id: 9055 rv_id: 1262868 rule_id: 9AU127 version_id: 9lT4b5N url: https://semgrep.dev/playground/r/9lT4b5N/generic.secrets.security.detected-facebook-oauth.detected-facebook-oauth origin: community - id: generic.secrets.security.detected-generic-api-key.detected-generic-api-key patterns: - pattern-regex: '[aA][pP][iI]_?[kK][eE][yY][=_:\s-]+[''|"]?(?[0-9a-zA-Z]{32,45})[''|"]?' - metavariable-analysis: analyzer: entropy metavariable: $SECRET languages: - regex message: Generic API Key detected severity: ERROR metadata: source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets confidence: LOW references: - https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-798: Use of Hard-coded Credentials' cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-generic-api-key.detected-generic-api-key shortlink: https://sg.run/qxj8 semgrep.dev: rule: r_id: 9056 rv_id: 1262869 rule_id: yyUn8p version_id: yeTxpZ9 url: https://semgrep.dev/playground/r/yeTxpZ9/generic.secrets.security.detected-generic-api-key.detected-generic-api-key origin: community - id: generic.secrets.security.detected-generic-secret.detected-generic-secret patterns: - pattern-regex: '[sS][eE][cC][rR][eE][tT][:= \t]*[''|\"]?(?[0-9a-zA-Z]{32,45})[''|\"]?' - metavariable-analysis: analyzer: entropy metavariable: $SECRET languages: - regex message: Generic Secret detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-generic-secret.detected-generic-secret shortlink: https://sg.run/l2o5 semgrep.dev: rule: r_id: 9057 rv_id: 1262870 rule_id: r6Urqe version_id: rxTAK4J url: https://semgrep.dev/playground/r/rxTAK4J/generic.secrets.security.detected-generic-secret.detected-generic-secret origin: community - id: generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token pattern-regex: ya29\.[0-9A-Za-z\-_]+ languages: - regex message: Google OAuth Access Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - google confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token shortlink: https://sg.run/ox2n semgrep.dev: rule: r_id: 9060 rv_id: 1262875 rule_id: kxUkpo version_id: xyTjzp6 url: https://semgrep.dev/playground/r/xyTjzp6/generic.secrets.security.detected-google-oauth-access-token.detected-google-oauth-access-token origin: community - id: generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key pattern-regex: '[hH][eE][rR][oO][kK][uU].*[0-9A-Fa-f]{8}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{12}' languages: - regex message: Heroku API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - heroku confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key shortlink: https://sg.run/pxXR semgrep.dev: rule: r_id: 9062 rv_id: 1262877 rule_id: x8UnOB version_id: e1Tyj3N url: https://semgrep.dev/playground/r/e1Tyj3N/generic.secrets.security.detected-heroku-api-key.detected-heroku-api-key origin: community - id: generic.secrets.security.detected-hockeyapp.detected-hockeyapp pattern-regex: (?i)hockey.{0,50}(\\\"|'|`)?[0-9a-f]{32}(\\\"|'|`)? languages: - regex message: HockeyApp detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - hockeyapp confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-hockeyapp.detected-hockeyapp shortlink: https://sg.run/2xoY semgrep.dev: rule: r_id: 9063 rv_id: 1262878 rule_id: OrU3zo version_id: vdT068z url: https://semgrep.dev/playground/r/vdT068z/generic.secrets.security.detected-hockeyapp.detected-hockeyapp origin: community - id: generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key pattern-regex: '[0-9a-f]{32}-us[0-9]{1,2}' languages: - regex message: MailChimp API Key detected severity: ERROR metadata: source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security cwe: - 'CWE-798: Use of Hard-coded Credentials' technology: - secrets - mailchimp confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key shortlink: https://sg.run/XBde semgrep.dev: rule: r_id: 9064 rv_id: 1262881 rule_id: eqU8QR version_id: nWT2LoR url: https://semgrep.dev/playground/r/nWT2LoR/generic.secrets.security.detected-mailchimp-api-key.detected-mailchimp-api-key origin: community - id: generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key pattern-regex: key-[0-9a-zA-Z]{32} languages: - regex message: Mailgun API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - mailgun confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key shortlink: https://sg.run/jRL2 semgrep.dev: rule: r_id: 9065 rv_id: 1262882 rule_id: v8UneY version_id: ExTExAG url: https://semgrep.dev/playground/r/ExTExAG/generic.secrets.security.detected-mailgun-api-key.detected-mailgun-api-key origin: community - id: generic.secrets.security.detected-outlook-team.detected-outlook-team pattern-regex: https://outlook\.office\.com/webhook/[0-9a-f-]{36} languages: - regex message: Outlook Team detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - outlook confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-outlook-team.detected-outlook-team shortlink: https://sg.run/1ZwQ semgrep.dev: rule: r_id: 9066 rv_id: 1262884 rule_id: d8UjXq version_id: LjTkgA1 url: https://semgrep.dev/playground/r/LjTkgA1/generic.secrets.security.detected-outlook-team.detected-outlook-team origin: community - id: generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token pattern-regex: access_token\$production\$[0-9a-z]{16}\$[0-9a-z]{32} languages: - regex message: PayPal Braintree Access Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - paypal - braintree confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token shortlink: https://sg.run/9oBR semgrep.dev: rule: r_id: 9067 rv_id: 1262885 rule_id: ZqU507 version_id: 8KT5ryb url: https://semgrep.dev/playground/r/8KT5ryb/generic.secrets.security.detected-paypal-braintree-access-token.detected-paypal-braintree-access-token origin: community - id: generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block pattern-regex: '-----BEGIN PGP PRIVATE KEY BLOCK-----' languages: - regex message: Something that looks like a PGP private key block is detected. This is a potential hardcoded secret that could be leaked if this code is committed. Instead, remove this code block from the commit. severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block shortlink: https://sg.run/ydKd semgrep.dev: rule: r_id: 9068 rv_id: 1262886 rule_id: nJUzXz version_id: gETB7O4 url: https://semgrep.dev/playground/r/gETB7O4/generic.secrets.security.detected-pgp-private-key-block.detected-pgp-private-key-block origin: community - id: generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key pattern-regex: sk_live_[0-9a-z]{32} languages: - regex message: Picatic API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - picatic confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key shortlink: https://sg.run/rdGA semgrep.dev: rule: r_id: 9069 rv_id: 1262887 rule_id: EwU274 version_id: QkTGqwK url: https://semgrep.dev/playground/r/QkTGqwK/generic.secrets.security.detected-picatic-api-key.detected-picatic-api-key origin: community - id: generic.secrets.security.detected-private-key.detected-private-key patterns: - pattern-either: - patterns: - pattern: '-----BEGIN $TYPE PRIVATE KEY----- $KEY' - metavariable-regex: metavariable: $TYPE regex: (?i)([dr]sa|ec|openssh|encrypted)? - patterns: - pattern: | -----BEGIN PRIVATE KEY----- $KEY - metavariable-analysis: metavariable: $KEY analyzer: entropy languages: - generic message: Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file. severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key shortlink: https://sg.run/b7dr semgrep.dev: rule: r_id: 9070 rv_id: 1262888 rule_id: 7KUQ0p version_id: 3ZT4X4Y url: https://semgrep.dev/playground/r/3ZT4X4Y/generic.secrets.security.detected-private-key.detected-private-key origin: community - id: generic.secrets.security.detected-sauce-token.detected-sauce-token pattern-regex: (?i)sauce.{0,50}(\\\"|'|`)?[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[0-9a-f]{4}-[0-9a-f]{12}(\\\"|'|`)? languages: - regex message: Sauce Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - sauce confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-sauce-token.detected-sauce-token shortlink: https://sg.run/N4k1 semgrep.dev: rule: r_id: 9071 rv_id: 1262889 rule_id: L1UyZ5 version_id: 44TEjER url: https://semgrep.dev/playground/r/44TEjER/generic.secrets.security.detected-sauce-token.detected-sauce-token origin: community - id: generic.secrets.security.detected-slack-token.detected-slack-token pattern-either: - pattern-regex: (xox[pboa]-[0-9]{12}-[0-9]{12}-[0-9]{12}-[a-z0-9]{32}) - pattern-regex: xox.-[0-9]{12}-[0-9]{12}-[0-9a-zA-Z]{24} languages: - regex message: Slack Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json references: - https://github.com/davidburkitt/python-secret-scanner/blob/335a1f6dab8de59cf39063e57aea39a58951e939/patterns.txt#L58 category: security technology: - secrets - slack confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-slack-token.detected-slack-token shortlink: https://sg.run/kXdz semgrep.dev: rule: r_id: 9072 rv_id: 1262891 rule_id: 8GUjRA version_id: JdTzxz3 url: https://semgrep.dev/playground/r/JdTzxz3/generic.secrets.security.detected-slack-token.detected-slack-token origin: community - id: generic.secrets.security.detected-slack-webhook.detected-slack-webhook patterns: - pattern-regex: https://hooks\.slack\.com/services/T[a-zA-Z0-9_]{8,10}/B[a-zA-Z0-9_]{8,10}/[a-zA-Z0-9_]{24} - pattern-not: https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX languages: - regex message: Slack Webhook detected severity: ERROR metadata: references: - https://api.slack.com/messaging/webhooks source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - slack confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-798: Use of Hard-coded Credentials' cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-slack-webhook.detected-slack-webhook shortlink: https://sg.run/weWX semgrep.dev: rule: r_id: 9073 rv_id: 1262892 rule_id: gxU1dy version_id: 5PTo1oO url: https://semgrep.dev/playground/r/5PTo1oO/generic.secrets.security.detected-slack-webhook.detected-slack-webhook origin: community - id: generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key pattern-regex: (?i)sonar.{0,50}(\\\"|'|`)?[0-9a-f]{40}(\\\"|'|`)? languages: - regex message: SonarQube Docs API Key detected severity: ERROR paths: exclude: - '*.svg' - '*go.sum' - '*cargo.lock' - '*package.json' - '*yarn.lock' - '*package-lock.json' - '*bundle.js' - '*pnpm-lock*' - '*Podfile.lock' - '**/*/openssl/*.h' - '*.xcscmblueprint' metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - sonarqube confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key shortlink: https://sg.run/x10P semgrep.dev: rule: r_id: 9074 rv_id: 1262895 rule_id: QrUzP1 version_id: A8TgdgQ url: https://semgrep.dev/playground/r/A8TgdgQ/generic.secrets.security.detected-sonarqube-docs-api-key.detected-sonarqube-docs-api-key origin: community - id: generic.secrets.security.detected-square-access-token.detected-square-access-token pattern-regex: sq0atp-[0-9A-Za-z\-_]{22} languages: - regex message: Square Access Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - square confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-square-access-token.detected-square-access-token shortlink: https://sg.run/OP3b semgrep.dev: rule: r_id: 9075 rv_id: 1262896 rule_id: 3qUPqO version_id: BjTkZkz url: https://semgrep.dev/playground/r/BjTkZkz/generic.secrets.security.detected-square-access-token.detected-square-access-token origin: community - id: generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret pattern-regex: sq0csp-[0-9A-Za-z\\\-_]{43} languages: - regex message: Square OAuth Secret detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json references: - https://github.com/Yelp/detect-secrets/blob/master/tests/plugins/square_oauth_test.py category: security technology: - secrets - square confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret shortlink: https://sg.run/eL7E semgrep.dev: rule: r_id: 9076 rv_id: 1262897 rule_id: 4bUk4l version_id: DkTRbRG url: https://semgrep.dev/playground/r/DkTRbRG/generic.secrets.security.detected-square-oauth-secret.detected-square-oauth-secret origin: community - id: generic.secrets.security.detected-ssh-password.detected-ssh-password pattern-regex: sshpass -p\s*['|\\\"][^%] languages: - regex message: SSH Password detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets - ssh confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-ssh-password.detected-ssh-password shortlink: https://sg.run/vzDR semgrep.dev: rule: r_id: 9077 rv_id: 1262898 rule_id: PeUZ4d version_id: WrTqKqY url: https://semgrep.dev/playground/r/WrTqKqY/generic.secrets.security.detected-ssh-password.detected-ssh-password origin: community - id: generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key pattern-regex: sk_live_[0-9a-zA-Z]{24} languages: - regex message: Stripe API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - stripe confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key shortlink: https://sg.run/dKd5 semgrep.dev: rule: r_id: 9078 rv_id: 1262899 rule_id: JDUy0z version_id: 0bTKzK1 url: https://semgrep.dev/playground/r/0bTKzK1/generic.secrets.security.detected-stripe-api-key.detected-stripe-api-key origin: community - id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key pattern-regex: rk_live_[0-9a-zA-Z]{24} languages: - regex message: Stripe Restricted API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - stripe confidence: MEDIUM owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key shortlink: https://sg.run/ZvdL semgrep.dev: rule: r_id: 9079 rv_id: 1262900 rule_id: 5rUOWq version_id: K3TKkKj url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key origin: community - id: generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key patterns: - pattern-regex: '[0-9]+:AA[0-9A-Za-z\-_]{33}' - pattern-not-regex: go\.mod.* - pattern-not-regex: v[\d]+\.[\d]+\.[\d]+.* languages: - regex message: Telegram Bot API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - telegram confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key shortlink: https://sg.run/nd4b semgrep.dev: rule: r_id: 9080 rv_id: 1262901 rule_id: GdU7Nl version_id: qkTR7RB url: https://semgrep.dev/playground/r/qkTR7RB/generic.secrets.security.detected-telegram-bot-api-key.detected-telegram-bot-api-key origin: community - id: generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key pattern-regex: SK[0-9a-fA-F]{32} languages: - regex message: Twilio API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - twilio confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key shortlink: https://sg.run/Ek2o semgrep.dev: rule: r_id: 9081 rv_id: 1262902 rule_id: ReUgJn version_id: l4TJRJJ url: https://semgrep.dev/playground/r/l4TJRJJ/generic.secrets.security.detected-twilio-api-key.detected-twilio-api-key origin: community - id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly patterns: - pattern-not-inside: | &sessions.Options{ ..., HttpOnly: true, ..., } - pattern: | &sessions.Options{ ..., } message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by setting 'HttpOnly' to 'true' in the Options struct. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly shortlink: https://sg.run/4xJZ semgrep.dev: rule: r_id: 9088 rv_id: 1262911 rule_id: qNUj6g version_id: WrTqKqe url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly origin: community fix-regex: regex: (HttpOnly\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure patterns: - pattern-not-inside: | &sessions.Options{ ..., Secure: true, ..., } - pattern: | &sessions.Options{ ..., } message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in the Options struct. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure shortlink: https://sg.run/PJdE semgrep.dev: rule: r_id: 9089 rv_id: 1262912 rule_id: lBU9kw version_id: 0bTKzKk url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure origin: community fix-regex: regex: (Secure\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection metadata: cwe: - 'CWE-300: Channel Accessible by Non-Endpoint' references: - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption category: security technology: - grpc confidence: HIGH owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection shortlink: https://sg.run/J9yZ semgrep.dev: rule: r_id: 9090 rv_id: 1262916 rule_id: PeUZ4X version_id: YDTZeZB url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection origin: community message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This creates a connection without encryption to a gRPC server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Instead, establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' function. You can create a create credentials using a ''tls.Config{}'' struct with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' languages: - go severity: ERROR pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) fix-regex: regex: (.*)WithInsecure\(.*?\) replacement: \1WithTransportCredentials(credentials.NewTLS()) - id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection metadata: cwe: - 'CWE-300: Channel Accessible by Non-Endpoint' references: - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption category: security technology: - grpc confidence: HIGH owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection shortlink: https://sg.run/5Q5l semgrep.dev: rule: r_id: 9091 rv_id: 1262917 rule_id: JDUy0B version_id: 6xT2923 url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection origin: community message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. This allows for a connection without encryption to this server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Include credentials derived from an SSL certificate in order to create a secure gRPC connection. You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", "cert.key")'. languages: - go severity: ERROR mode: taint pattern-sinks: - requires: OPTIONS and not CREDS pattern: grpc.NewServer($OPT, ...) - requires: EMPTY_CONSTRUCTOR pattern: grpc.NewServer() pattern-sources: - label: OPTIONS pattern: grpc.ServerOption{ ... } - label: CREDS pattern: grpc.Creds(...) - label: EMPTY_CONSTRUCTOR pattern: grpc.NewServer() - id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm shortlink: https://sg.run/Gej1 semgrep.dev: rule: r_id: 9092 rv_id: 1262919 rule_id: 5rUOWQ version_id: zyTb2bz url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm origin: community languages: - go severity: ERROR patterns: - pattern-either: - pattern-inside: | import "github.com/golang-jwt/jwt" ... - pattern-inside: | import "github.com/dgrijalva/jwt-go" ... - pattern-either: - pattern: | jwt.SigningMethodNone - pattern: jwt.UnsafeAllowNoneSignatureType - id: go.jwt-go.security.jwt.hardcoded-jwt-key message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - jwt - secrets confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key shortlink: https://sg.run/Rod2 semgrep.dev: rule: r_id: 9093 rv_id: 1262920 rule_id: GdU7Ny version_id: pZT0305 url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key origin: community severity: WARNING languages: - go mode: taint pattern-sources: - patterns: - pattern-inside: | []byte("$F") pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $TOKEN.SignedString($F) - focus-metavariable: $F - id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` unless you know what you're doing This method parses the token but doesn't validate the signature. It's only ever useful in cases where you know the signature is valid (because it has been checked previously in the stack) and you want to extract values from it. metadata: cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: MEDIUM references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified shortlink: https://sg.run/Av66 semgrep.dev: rule: r_id: 9094 rv_id: 1262918 rule_id: ReUgJJ version_id: o5TbDbq url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified origin: community languages: - go severity: WARNING patterns: - pattern-inside: | import "github.com/dgrijalva/jwt-go" ... - pattern: | $JWT.ParseUnverified(...) - id: go.lang.security.bad_tmp.bad-tmp-file-creation message: File creation in shared tmp directory without using `io.CreateTemp`. languages: - go severity: WARNING metadata: cwe: - 'CWE-377: Insecure Temporary File' source-rule-url: https://github.com/securego/gosec category: security technology: - go confidence: LOW owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control - https://pkg.go.dev/io/ioutil#TempFile - https://pkg.go.dev/os#CreateTemp - https://github.com/securego/gosec/blob/5fd2a370447223541cddb35da8d1bc707b7bb153/rules/tempfiles.go#L67 subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.lang.security.bad_tmp.bad-tmp-file-creation shortlink: https://sg.run/Gejn semgrep.dev: rule: r_id: 9104 rv_id: 1262965 rule_id: 6JUjnL version_id: 2KTv2pJ url: https://semgrep.dev/playground/r/2KTv2pJ/go.lang.security.bad_tmp.bad-tmp-file-creation origin: community pattern-either: - pattern: ioutil.WriteFile("=~//tmp/.*$/", ...) - pattern: os.Create("=~//tmp/.*$/", ...) - pattern: os.WriteFile("=~//tmp/.*$/", ...) - id: go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb message: 'Detected a possible denial-of-service via a zip bomb attack. By limiting the max bytes read, you can mitigate this attack. `io.CopyN()` can specify a size. ' severity: WARNING languages: - go patterns: - pattern-either: - pattern: io.Copy(...) - pattern: io.CopyBuffer(...) - pattern-either: - pattern-inside: | gzip.NewReader(...) ... - pattern-inside: | zlib.NewReader(...) ... - pattern-inside: | zlib.NewReaderDict(...) ... - pattern-inside: | bzip2.NewReader(...) ... - pattern-inside: | flate.NewReader(...) ... - pattern-inside: | flate.NewReaderDict(...) ... - pattern-inside: | lzw.NewReader(...) ... - pattern-inside: | tar.NewReader(...) ... - pattern-inside: | zip.NewReader(...) ... - pattern-inside: | zip.OpenReader(...) ... fix-regex: regex: (.*)(Copy|CopyBuffer)\((.*?),(.*?)(\)|,.*\)) replacement: \1CopyN(\3, \4, 1024*1024*256) metadata: cwe: - 'CWE-400: Uncontrolled Resource Consumption' source-rule-url: https://github.com/securego/gosec references: - https://golang.org/pkg/io/#CopyN - https://github.com/securego/gosec/blob/master/rules/decompression-bomb.go category: security technology: - go confidence: LOW cwe2022-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb shortlink: https://sg.run/RodK semgrep.dev: rule: r_id: 9105 rv_id: 945606 rule_id: oqUeqn version_id: JdTDye5 url: https://semgrep.dev/playground/r/JdTDye5/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb origin: community - id: go.lang.security.zip.path-traversal-inside-zip-extraction message: File traversal when extracting zip archive metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' source_rule_url: https://github.com/securego/gosec/issues/205 category: security technology: - go confidence: LOW owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/go.lang.security.zip.path-traversal-inside-zip-extraction shortlink: https://sg.run/Av64 semgrep.dev: rule: r_id: 9106 rv_id: 1262971 rule_id: zdUkoR version_id: rxTAK1Z url: https://semgrep.dev/playground/r/rxTAK1Z/go.lang.security.zip.path-traversal-inside-zip-extraction origin: community languages: - go severity: WARNING pattern: | reader, $ERR := zip.OpenReader($ARCHIVE) ... for _, $FILE := range reader.File { ... path := filepath.Join($TARGET, $FILE.Name) ... } - id: go.lang.security.audit.dangerous-command-write.dangerous-command-write patterns: - pattern: | $CW.Write($BYTE) - pattern-inside: | $CW,$ERR := $CMD.StdinPipe() ... - pattern-not: | $CW.Write("...") - pattern-not: | $CW.Write([]byte("...")) - pattern-not: | $CW.Write([]byte("..."+"...")) - pattern-not-inside: | $BYTE = []byte("..."); ... - pattern-not-inside: | $BYTE = []byte("..."+"..."); ... - pattern-inside: | import "os/exec" ... message: Detected non-static command inside Write. Audit the input to '$CW.Write'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. severity: ERROR languages: - go metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' category: security technology: - go confidence: LOW owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/go.lang.security.audit.dangerous-command-write.dangerous-command-write shortlink: https://sg.run/Bko5 semgrep.dev: rule: r_id: 9107 rv_id: 1262933 rule_id: pKUOZ9 version_id: O9Tpx8N url: https://semgrep.dev/playground/r/O9Tpx8N/go.lang.security.audit.dangerous-command-write.dangerous-command-write origin: community - id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd patterns: - pattern-either: - patterns: - pattern: | exec.Cmd {...,Path: $CMD,...} - pattern-not: | exec.Cmd {...,Path: "...",...} - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $CMD = "..."; ... - patterns: - pattern: | exec.Cmd {...,Args: $ARGS,...} - pattern-not: | exec.Cmd {...,Args: []string{...},...} - pattern-not-inside: | $ARGS = []string{"...",...}; ... - pattern-not-inside: | $CMD = "..."; ... $ARGS = []string{$CMD,...}; ... - pattern-not-inside: | $CMD = exec.LookPath("..."); ... $ARGS = []string{$CMD,...}; ... - patterns: - pattern: | exec.Cmd {...,Args: []string{$CMD,...},...} - pattern-not: | exec.Cmd {...,Args: []string{"...",...},...} - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $CMD = "..."; ... - patterns: - pattern-either: - pattern: | exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...} - patterns: - pattern: | exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...} - pattern-inside: | $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); ... - pattern-not: | exec.Cmd {...,Args: []string{"...","...","...",...},...} - pattern-not-inside: | $EXE = "..."; ... - pattern-inside: | import "os/exec" ... message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd shortlink: https://sg.run/Dorj semgrep.dev: rule: r_id: 9108 rv_id: 1262934 rule_id: 2ZUb8l version_id: e1Tyjeg url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd origin: community severity: ERROR languages: - go - id: go.lang.security.audit.dangerous-exec-command.dangerous-exec-command patterns: - pattern-either: - patterns: - pattern-either: - pattern: | exec.Command($CMD,...) - pattern: | exec.CommandContext($CTX,$CMD,...) - pattern-not: | exec.Command("...",...) - pattern-not: | exec.CommandContext($CTX,"...",...) - patterns: - pattern-either: - pattern: | exec.Command("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) - pattern: | exec.CommandContext($CTX,"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) - pattern-not: | exec.Command("...","...","...",...) - pattern-not: | exec.CommandContext($CTX,"...","...","...",...) - pattern-either: - pattern: | exec.Command("=~/\/bin\/env/","=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) - pattern: | exec.CommandContext($CTX,"=~/\/bin\/env/","=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$CMD,...) - pattern-inside: | import "os/exec" ... - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $CMD = "..."; ... message: Detected non-static command inside Command. Audit the input to 'exec.Command'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command shortlink: https://sg.run/W8lA semgrep.dev: rule: r_id: 9109 rv_id: 1262935 rule_id: X5U8RQ version_id: vdT06Xp url: https://semgrep.dev/playground/r/vdT06Xp/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command origin: community severity: ERROR languages: - go - id: go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec patterns: - pattern-either: - patterns: - pattern: | syscall.$METHOD($BIN,...) - pattern-not: | syscall.$METHOD("...",...) - pattern-not-inside: | $BIN,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $BIN = "..."; ... - patterns: - pattern: | syscall.$METHOD($BIN,$ARGS,...) - pattern-not: | syscall.$METHOD($BIN,[]string{"...",...},...) - pattern-not-inside: | $ARGS := []string{"...",...}; ... - pattern-not-inside: | $CMD = "..."; ... $ARGS = []string{$CMD,...}; ... - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... $ARGS = []string{$CMD,...}; ... - patterns: - pattern: | syscall.$METHOD($BIN,[]string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...) - pattern-not: | syscall.$METHOD($BIN,[]string{"...","...","...",...},...) - patterns: - pattern: | syscall.$METHOD($BIN,$ARGS,...) - pattern-either: - pattern-inside: | $ARGS := []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...}; ... - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; ... $ARGS = []string{$CMD,"-c",$EXE,...}; ... - pattern-inside: | $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); ... $ARGS = []string{$CMD,"-c",$EXE,...}; ... - pattern-not-inside: | $ARGS := []string{"...","...","...",...}; ... - pattern-not-inside: | $CMD = "..."; ... $ARGS = []string{$CMD,"...","...",...}; ... - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... $ARGS = []string{$CMD,"...","...",...}; ... - pattern-inside: | import "syscall" ... - metavariable-regex: metavariable: $METHOD regex: (Exec|ForkExec) message: Detected non-static command inside Exec. Audit the input to 'syscall.Exec'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec shortlink: https://sg.run/0QRb semgrep.dev: rule: r_id: 9110 rv_id: 1262936 rule_id: j2UvPl version_id: d6Tyx3j url: https://semgrep.dev/playground/r/d6Tyx3j/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec origin: community severity: ERROR languages: - go - id: go.lang.security.audit.reflect-makefunc.reflect-makefunc message: '''reflect.MakeFunc'' detected. This will sidestep protections that are normally afforded by Go''s type system. Audit this call and be sure that user input cannot be used to affect the code generated by MakeFunc; otherwise, you will have a serious security vulnerability.' metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' category: security technology: - go confidence: LOW references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.reflect-makefunc.reflect-makefunc shortlink: https://sg.run/KlPd semgrep.dev: rule: r_id: 9111 rv_id: 1262950 rule_id: 10UKGb version_id: GxTkeqB url: https://semgrep.dev/playground/r/GxTkeqB/go.lang.security.audit.reflect-makefunc.reflect-makefunc origin: community severity: ERROR pattern: reflect.MakeFunc(...) languages: - go - id: go.lang.security.audit.crypto.bad_imports.insecure-module-used message: The package `net/http/cgi` is on the import blocklist. The package is vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http` or a web framework to build a web application instead. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec references: - https://godoc.org/golang.org/x/crypto/sha3 category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used shortlink: https://sg.run/l2gj semgrep.dev: rule: r_id: 9113 rv_id: 1262921 rule_id: yyUnov version_id: 2KTv2vJ url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used origin: community languages: - go severity: WARNING pattern-either: - patterns: - pattern-inside: | import "net/http/cgi" ... - pattern: | cgi.$FUNC(...) - id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key message: Disabled host key verification detected. This allows man-in-the-middle attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to learn more about the problem and how to fix it. metadata: cwe: - 'CWE-322: Key Exchange without Entity Authentication' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec references: - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key shortlink: https://sg.run/Yv6X semgrep.dev: rule: r_id: 9114 rv_id: 1262922 rule_id: r6UrW9 version_id: X0TzyzN url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key origin: community languages: - go severity: WARNING pattern: ssh.InsecureIgnoreHostKey() - id: go.lang.security.audit.crypto.math_random.math-random-used metadata: cwe: - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used shortlink: https://sg.run/6nK6 semgrep.dev: rule: r_id: 9115 rv_id: 1262923 rule_id: bwUwy8 version_id: jQTn5nj url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used origin: community message: Do not use `math/rand`. Use `crypto/rand` instead. languages: - go severity: WARNING patterns: - pattern-either: - pattern: | import $RAND "$MATH" - pattern: | import "$MATH" - metavariable-regex: metavariable: $MATH regex: ^(math/rand(\/v[0-9]+)*)$ - pattern-either: - pattern-inside: | ... rand.$FUNC(...) - pattern-inside: | ... $RAND.$FUNC(...) - focus-metavariable: - $MATH fix: | crypto/rand - id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion message: '`MinVersion` is missing from this TLS configuration. By default, as of Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration to bump the minimum version to TLS 1.3.' metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go references: - https://go.dev/doc/go1.22#minor_library_changes - https://pkg.go.dev/crypto/tls#:~:text=MinVersion - https://www.us-cert.gov/ncas/alerts/TA14-290A category: security technology: - go confidence: HIGH subcategory: - audit likelihood: MEDIUM impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion shortlink: https://sg.run/oxEN semgrep.dev: rule: r_id: 9116 rv_id: 1262924 rule_id: NbUk4X version_id: 1QTypyp url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion origin: community languages: - go severity: WARNING patterns: - pattern: | tls.Config{ $...CONF } - pattern-not: | tls.Config{..., MinVersion: ..., ...} fix: | tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 } - id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go references: - https://golang.org/doc/go1.14#crypto/tls - https://www.us-cert.gov/ncas/alerts/TA14-290A category: security technology: - go confidence: HIGH subcategory: - vuln likelihood: MEDIUM impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure shortlink: https://sg.run/zvE1 semgrep.dev: rule: r_id: 9117 rv_id: 1262926 rule_id: kxUkJ2 version_id: yeTxpxj url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure origin: community languages: - go severity: WARNING fix-regex: regex: VersionSSL30 replacement: VersionTLS13 pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' - id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other cipher suites to use. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go references: - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites category: security technology: - go confidence: HIGH subcategory: - vuln likelihood: HIGH impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher shortlink: https://sg.run/px8N semgrep.dev: rule: r_id: 9118 rv_id: 1262927 rule_id: wdUJYk version_id: rxTAKAZ url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher origin: community languages: - go severity: WARNING pattern-either: - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 shortlink: https://sg.run/2xB5 semgrep.dev: rule: r_id: 9119 rv_id: 1262928 rule_id: x8Un6q version_id: bZT535Y url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 origin: community patterns: - pattern-inside: | import "crypto/md5" ... - pattern-either: - pattern: | md5.New() - pattern: | md5.Sum(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 shortlink: https://sg.run/XBYA semgrep.dev: rule: r_id: 9120 rv_id: 1262929 rule_id: OrU31O version_id: NdTzyz1 url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 origin: community patterns: - pattern-inside: | import "crypto/sha1" ... - pattern-either: - pattern: | sha1.New() - pattern: | sha1.Sum(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES message: Detected DES cipher algorithm which is insecure. The algorithm is considered weak and has been deprecated. Use AES instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES shortlink: https://sg.run/jREA semgrep.dev: rule: r_id: 9121 rv_id: 1262930 rule_id: eqU8B3 version_id: kbTzGzA url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES origin: community patterns: - pattern-inside: | import "crypto/des" ... - pattern-either: - pattern: | des.NewTripleDESCipher(...) - pattern: | des.NewCipher(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 message: Detected RC4 cipher algorithm which is insecure. The algorithm has many known vulnerabilities. Use AES instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 shortlink: https://sg.run/1ZAD semgrep.dev: rule: r_id: 9122 rv_id: 1262931 rule_id: v8Unl0 version_id: w8TRoRQ url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 origin: community patterns: - pattern-inside: | import "crypto/rc4" ... - pattern: rc4.NewCipher(...) - id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits languages: - go severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - go confidence: HIGH subcategory: - audit likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key shortlink: https://sg.run/9oY4 semgrep.dev: rule: r_id: 9123 rv_id: 1262932 rule_id: d8UjY3 version_id: xyTjz8L url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key origin: community patterns: - pattern-either: - pattern: | rsa.GenerateKey(..., $BITS) - pattern: | rsa.GenerateMultiPrimeKey(..., $BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048 - focus-metavariable: - $BITS fix: | 2048 - id: go.lang.security.audit.database.string-formatted-query.string-formatted-query languages: - go message: String-formatted SQL query detected. This could lead to SQL injection if the string is not sanitized properly. Audit this call to ensure the SQL is not manipulable by external data. severity: WARNING metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' source-rule-url: https://github.com/securego/gosec category: security technology: - go confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.audit.database.string-formatted-query.string-formatted-query shortlink: https://sg.run/ydEr semgrep.dev: rule: r_id: 9124 rv_id: 1262937 rule_id: ZqU5bD version_id: ZRTKA2q url: https://semgrep.dev/playground/r/ZRTKA2q/go.lang.security.audit.database.string-formatted-query.string-formatted-query origin: community patterns: - metavariable-regex: metavariable: $OBJ regex: (?i).*(db|database) - pattern-not-inside: | $VAR = "..." + "..." ... $OBJ.$SINK(..., $VAR, ...) - pattern-not: $OBJ.Exec("...") - pattern-not: $OBJ.ExecContext($CTX, "...") - pattern-not: $OBJ.Query("...") - pattern-not: $OBJ.QueryContext($CTX, "...") - pattern-not: $OBJ.QueryRow("...") - pattern-not: $OBJ.QueryRow($CTX, "...") - pattern-not: $OBJ.QueryRowContext($CTX, "...") - pattern-either: - pattern: $OBJ.Exec($X + ...) - pattern: $OBJ.ExecContext($CTX, $X + ...) - pattern: $OBJ.Query($X + ...) - pattern: $OBJ.QueryContext($CTX, $X + ...) - pattern: $OBJ.QueryRow($X + ...) - pattern: $OBJ.QueryRow($CTX, $X + ...) - pattern: $OBJ.QueryRowContext($CTX, $X + ...) - pattern: $OBJ.Exec(fmt.$P("...", ...)) - pattern: $OBJ.ExecContext($CTX, fmt.$P("...", ...)) - pattern: $OBJ.Query(fmt.$P("...", ...)) - pattern: $OBJ.QueryContext($CTX, fmt.$P("...", ...)) - pattern: $OBJ.QueryRow(fmt.$P("...", ...)) - pattern: $OBJ.QueryRow($CTX, fmt.$U("...", ...)) - pattern: $OBJ.QueryRowContext($CTX, fmt.$P("...", ...)) - patterns: - pattern-either: - pattern: $QUERY = fmt.Fprintf($F, "$SQLSTR", ...) - pattern: $QUERY = fmt.Sprintf("$SQLSTR", ...) - pattern: $QUERY = fmt.Printf("$SQLSTR", ...) - pattern: $QUERY = $X + ... - pattern-either: - pattern-inside: | func $FUNC(...) { ... $OBJ.Query($QUERY, ...) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.ExecContext($CTX, $QUERY, ...) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.Exec($QUERY, ...) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.QueryRow($CTX, $QUERY) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.QueryRow($QUERY) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.QueryContext($CTX, $QUERY) ... } - pattern-inside: | func $FUNC(...) { ... $OBJ.QueryRowContext($CTX, $QUERY, ...) ... } - id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces message: Detected a network listener listening on 0.0.0.0 or an empty string. This could unexpectedly expose the server publicly as it binds to all available interfaces. Instead, specify another IP address that is not 0.0.0.0 nor the empty string. languages: - go severity: WARNING metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/securego/gosec category: security technology: - go confidence: HIGH references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces shortlink: https://sg.run/rdE0 semgrep.dev: rule: r_id: 9125 rv_id: 1262939 rule_id: nJUz3J version_id: ExTExoK url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces origin: community pattern-either: - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) - id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly patterns: - pattern-not-inside: | http.Cookie{ ..., HttpOnly: true, ..., } - pattern: | http.Cookie{ ..., } message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by setting 'HttpOnly' to 'true' in the Cookie. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go - https://golang.org/src/net/http/cookie.go category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly shortlink: https://sg.run/b73e semgrep.dev: rule: r_id: 9126 rv_id: 1262940 rule_id: EwU2Z6 version_id: 7ZTE3BW url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly origin: community fix-regex: regex: (HttpOnly\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure patterns: - pattern-not-inside: | http.Cookie{ ..., Secure: true, ..., } - pattern: | http.Cookie{ ..., } message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in the Options struct. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go - https://golang.org/src/net/http/cookie.go category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure shortlink: https://sg.run/N4G7 semgrep.dev: rule: r_id: 9127 rv_id: 1262941 rule_id: 7KUQ8X version_id: LjTkgGE url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure origin: community fix-regex: regex: (Secure\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace message: Detected a potentially dynamic ClientTrace. This occurred because semgrep could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous because they deserialize function code to run when certain Request events occur, which could lead to code being run without your knowledge. Ensure that your ClientTrace is statically defined. metadata: cwe: - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://github.com/returntocorp/semgrep-rules/issues/518 category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace shortlink: https://sg.run/kXEK semgrep.dev: rule: r_id: 9128 rv_id: 1262942 rule_id: L1Uyjp version_id: 8KT5rNv url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace origin: community patterns: - pattern-not-inside: | package $PACKAGE ... &httptrace.ClientTrace { ... } ... - pattern: httptrace.WithClientTrace($ANY, $TRACE) severity: WARNING languages: - go - id: go.lang.security.audit.net.formatted-template-string.formatted-template-string message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' does not escape contents. Be absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may have a XSS vulnerability. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#HTML category: security technology: - go confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string shortlink: https://sg.run/weE0 semgrep.dev: rule: r_id: 9129 rv_id: 1262943 rule_id: 8GUjDW version_id: gETB7Pe url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string origin: community languages: - go severity: WARNING patterns: - pattern-not: template.HTML("..." + "...") - pattern-either: - pattern: template.HTML($T + $X, ...) - pattern: template.HTML(fmt.$P("...", ...), ...) - pattern: | $T = "..." ... $T = $FXN(..., $T, ...) ... template.HTML($T, ...) - pattern: | $T = fmt.$P("...", ...) ... template.HTML($T, ...) - pattern: | $T, $ERR = fmt.$P("...", ...) ... template.HTML($T, ...) - pattern: | $T = $X + $Y ... template.HTML($T, ...) - pattern: |- $T = "..." ... $OTHER, $ERR = fmt.$P(..., $T, ...) ... template.HTML($OTHER, ...) - id: go.lang.security.audit.net.pprof.pprof-debug-exposure metadata: cwe: - 'CWE-489: Active Debug Code' owasp: A06:2017 - Security Misconfiguration source-rule-url: https://github.com/securego/gosec#available-rules references: - https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ category: security technology: - go confidence: LOW subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/go.lang.security.audit.net.pprof.pprof-debug-exposure shortlink: https://sg.run/x1Ep semgrep.dev: rule: r_id: 9130 rv_id: 945583 rule_id: gxU1Kp version_id: 9lTy168 url: https://semgrep.dev/playground/r/9lTy168/go.lang.security.audit.net.pprof.pprof-debug-exposure origin: community message: The profiling 'pprof' endpoint is automatically exposed on /debug/pprof. This could leak information about the server. Instead, use `import "net/http/pprof"`. See https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ for more information and mitigation. languages: - go severity: WARNING patterns: - pattern-inside: | import _ "net/http/pprof" ... - pattern-inside: | func $ANY(...) { ... } - pattern-not-inside: | $MUX = http.NewServeMux(...) ... http.ListenAndServe($ADDR, $MUX) - pattern-not: http.ListenAndServe("=~/^localhost.*/", ...) - pattern-not: http.ListenAndServe("=~/^127[.]0[.]0[.]1.*/", ...) - pattern: http.ListenAndServe(...) - id: go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr message: Found a formatted template string passed to 'template. HTMLAttr()'. 'template.HTMLAttr()' does not escape contents. Be absolutely sure there is no user-controlled data in this template or validate and sanitize the data before passing it into the template. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#HTMLAttr category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr shortlink: https://sg.run/OPRp semgrep.dev: rule: r_id: 9131 rv_id: 1262945 rule_id: QrUz9R version_id: 3ZT4XRr url: https://semgrep.dev/playground/r/3ZT4XRr/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr origin: community languages: - go severity: WARNING pattern-either: - pattern: template.HTMLAttr($T + $X, ...) - pattern: template.HTMLAttr(fmt.$P("...", ...), ...) - pattern: | $T = "..." ... $T = $FXN(..., $T, ...) ... template.HTMLAttr($T, ...) - pattern: | $T = fmt.$P("...", ...) ... template.HTMLAttr($T, ...) - pattern: | $T, $ERR = fmt.$P("...", ...) ... template.HTMLAttr($T, ...) - pattern: | $T = $X + $Y ... template.HTMLAttr($T, ...) - pattern: |- $T = "..." ... $OTHER, $ERR = fmt.$P(..., $T, ...) ... template.HTMLAttr($OTHER, ...) - id: go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js message: Found a formatted template string passed to 'template.JS()'. 'template.JS()' does not escape contents. Be absolutely sure there is no user-controlled data in this template. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#JS category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js shortlink: https://sg.run/eLNl semgrep.dev: rule: r_id: 9132 rv_id: 1262946 rule_id: 3qUP8K version_id: 44TEj9E url: https://semgrep.dev/playground/r/44TEj9E/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js origin: community languages: - go severity: WARNING pattern-either: - pattern: template.JS($T + $X, ...) - pattern: template.JS(fmt.$P("...", ...), ...) - pattern: | $T = "..." ... $T = $FXN(..., $T, ...) ... template.JS($T, ...) - pattern: | $T = fmt.$P("...", ...) ... template.JS($T, ...) - pattern: | $T, $ERR = fmt.$P("...", ...) ... template.JS($T, ...) - pattern: | $T = $X + $Y ... template.JS($T, ...) - pattern: | $T = "..." ... $OTHER, $ERR = fmt.$P(..., $T, ...) ... template.JS($OTHER, ...) - id: go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url message: Found a formatted template string passed to 'template.URL()'. 'template.URL()' does not escape contents, and this could result in XSS (cross-site scripting) and therefore confidential data being stolen. Sanitize data coming into this function or make sure that no user-controlled input is coming into the function. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#URL category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url shortlink: https://sg.run/vzE4 semgrep.dev: rule: r_id: 9133 rv_id: 1262947 rule_id: 4bUkDW version_id: PkTR3zz url: https://semgrep.dev/playground/r/PkTR3zz/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url origin: community languages: - go severity: WARNING pattern-either: - pattern: template.URL($T + $X, ...) - pattern: template.URL(fmt.$P("...", ...), ...) - pattern: | $T = "..." ... $T = $FXN(..., $T, ...) ... template.URL($T, ...) - pattern: | $T = fmt.$P("...", ...) ... template.URL($T, ...) - pattern: | $T, $ERR = fmt.$P("...", ...) ... template.URL($T, ...) - pattern: | $T = $X + $Y ... template.URL($T, ...) - pattern: |- $T = "..." ... $OTHER, $ERR = fmt.$P(..., $T, ...) ... template.URL($OTHER, ...) - id: go.lang.security.audit.net.use-tls.use-tls pattern: http.ListenAndServe($ADDR, $HANDLER) fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://golang.org/pkg/net/http/#ListenAndServeTLS category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls shortlink: https://sg.run/dKbY semgrep.dev: rule: r_id: 9134 rv_id: 1262948 rule_id: PeUZ8X version_id: JdTzxkn url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls origin: community message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. languages: - go severity: WARNING - id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf patterns: - pattern-inside: | func $FUNC(..., $W http.ResponseWriter, ...) { ... var $TEMPLATE = "..." ... $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) ... } - pattern-either: - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $INTERM = $ANYTHING(..., $DATA, ...) ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $INTERM = $DATA[...] ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $DATA, $ERR := r.URL.Query()[...] ... $INTERM = $DATA[...] ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $DATA, $ERR := r.URL.Query()[...] ... $INTERM = $ANYTHING(..., $DATA, ...) ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) message: Found data going from url query parameters into formatted data written to ResponseWriter. This could be XSS and should not be done. If you must do this, ensure your data is sanitized or escaped. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf shortlink: https://sg.run/Zvon semgrep.dev: rule: r_id: 9135 rv_id: 1262949 rule_id: JDUyXB version_id: 5PTo1qr url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf origin: community severity: WARNING languages: - go - id: go.lang.security.audit.xss.import-text-template.import-text-template message: When working with web applications that involve rendering user-generated content, it's important to properly escape any HTML content to prevent Cross-Site Scripting (XSS) attacks. In Go, the `text/template` package does not automatically escape HTML content, which can leave your application vulnerable to these types of attacks. To mitigate this risk, it's recommended to use the `html/template` package instead, which provides built-in functionality for HTML escaping. By using `html/template` to render your HTML content, you can help to ensure that your web application is more secure and less susceptible to XSS vulnerabilities. metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://www.veracode.com/blog/secure-development/use-golang-these-mistakes-could-compromise-your-apps-security category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.import-text-template.import-text-template shortlink: https://sg.run/ndEO semgrep.dev: rule: r_id: 9136 rv_id: 1262956 rule_id: 5rUOZQ version_id: 0bTKzok url: https://semgrep.dev/playground/r/0bTKzok/go.lang.security.audit.xss.import-text-template.import-text-template origin: community severity: WARNING patterns: - pattern: | import "$IMPORT" - metavariable-regex: metavariable: $IMPORT regex: ^(text/template)$ - focus-metavariable: $IMPORT fix: | html/template languages: - go - id: go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter languages: - go message: Detected directly writing or similar in 'http.ResponseWriter.write()'. This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package and render data using 'template.Execute()'. metadata: category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter shortlink: https://sg.run/EkbA semgrep.dev: rule: r_id: 9137 rv_id: 1262957 rule_id: GdU71y version_id: K3TKkoB url: https://semgrep.dev/playground/r/K3TKkoB/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter origin: community patterns: - pattern-either: - pattern-inside: | func $HANDLER(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-inside: | func $HANDLER(..., $WRITER *http.ResponseWriter, ...) { ... } - pattern-inside: | func(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-either: - pattern: $WRITER.Write(...) - pattern: (*$WRITER).Write(...) - pattern-not: $WRITER.Write([]byte("...")) severity: WARNING - id: go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter message: Detected 'Fprintf' or similar writing to 'http.ResponseWriter'. This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter shortlink: https://sg.run/7oqR semgrep.dev: rule: r_id: 9138 rv_id: 1262958 rule_id: ReUgyJ version_id: qkTR7OP url: https://semgrep.dev/playground/r/qkTR7OP/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter origin: community severity: WARNING patterns: - pattern-either: - pattern-inside: | func $HANDLER(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-inside: | func(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-not: fmt.$PRINTF($WRITER, "...") - pattern: fmt.$PRINTF($WRITER, ...) languages: - go - id: go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag message: Detected template variable interpolation in an HTML tag. This is potentially vulnerable to cross-site scripting (XSS) attacks because a malicious actor has control over HTML but without the need to use escaped characters. Use explicit tags instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/golang/go/issues/19669 - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ category: security technology: - generic confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag shortlink: https://sg.run/LwJJ semgrep.dev: rule: r_id: 9139 rv_id: 1262959 rule_id: AbUzBB version_id: l4TJRZK url: https://semgrep.dev/playground/r/l4TJRZK/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag origin: community languages: - generic severity: WARNING paths: include: - '*.html' - '*.thtml' - '*.gohtml' - '*.tmpl' - '*.tpl' pattern: <{{ ... }} ... > - id: go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string message: Detected template variable interpolation in a JavaScript template string. This is potentially vulnerable to cross-site scripting (XSS) attacks because a malicious actor has control over JavaScript but without the need to use escaped characters. Instead, obtain this variable outside of the template string and ensure your template is properly escaped. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/golang/go/issues/9200#issuecomment-66100328 - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ category: security technology: - generic confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string shortlink: https://sg.run/8yl7 semgrep.dev: rule: r_id: 9140 rv_id: 1262960 rule_id: BYUNR6 version_id: YDTZeEB url: https://semgrep.dev/playground/r/YDTZeEB/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string origin: community languages: - generic severity: WARNING paths: include: - '*.html' - '*.thtml' - '*.gohtml' - '*.tmpl' - '*.tpl' patterns: - pattern-inside: - pattern: '` ... {{ ... }} ...`' - id: go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter message: Detected 'io.WriteString()' writing directly to 'http.ResponseWriter'. This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ - https://golang.org/pkg/io/#WriteString category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter shortlink: https://sg.run/gLwn semgrep.dev: rule: r_id: 9141 rv_id: 1262961 rule_id: DbUpEr version_id: 6xT2983 url: https://semgrep.dev/playground/r/6xT2983/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter origin: community severity: WARNING patterns: - pattern-either: - pattern-inside: | func $HANDLER(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-inside: | func(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-not: io.WriteString($WRITER, "...") - pattern: io.WriteString($WRITER, $STRING) languages: - go - id: go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter message: Detected 'printf' or similar in 'http.ResponseWriter.write()'. This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter shortlink: https://sg.run/Q5BP semgrep.dev: rule: r_id: 9142 rv_id: 1262962 rule_id: WAUoLp version_id: o5TbDdq url: https://semgrep.dev/playground/r/o5TbDdq/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter origin: community severity: WARNING patterns: - pattern-either: - pattern-inside: | func $HANDLER(..., $WRITER http.ResponseWriter, ...) { ... } - pattern-inside: | func(..., $WRITER http.ResponseWriter, ...) { ... } - pattern: | $WRITER.Write(<... fmt.$PRINTF(...) ...>, ...) languages: - go - id: go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type message: Semgrep could not determine that the argument to 'template.HTML()' is a constant. 'template.HTML()' and similar does not escape contents. Be absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may have a XSS vulnerability. Instead, do not use this function and use 'template.Execute()'. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#HTML - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/vulnerability/xss/xss.go#L33 category: security technology: - go confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type shortlink: https://sg.run/3xDb semgrep.dev: rule: r_id: 9143 rv_id: 1262963 rule_id: 0oU5n3 version_id: zyTb2Lz url: https://semgrep.dev/playground/r/zyTb2Lz/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type origin: community languages: - go severity: WARNING patterns: - pattern-not: template.$ANY("..." + "...") - pattern-not: template.$ANY("...") - pattern-either: - pattern: template.HTML(...) - pattern: template.CSS(...) - pattern: template.HTMLAttr(...) - pattern: template.JS(...) - pattern: template.JSStr(...) - pattern: template.Srcset(...) - pattern: template.URL(...) - id: go.otto.security.audit.dangerous-execution.dangerous-execution message: Detected non-static script inside otto VM. Audit the input to 'VM.Run'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - otto - vm confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.otto.security.audit.dangerous-execution.dangerous-execution shortlink: https://sg.run/4xWE semgrep.dev: rule: r_id: 9144 rv_id: 1262972 rule_id: KxUbxk version_id: bZT53ZY url: https://semgrep.dev/playground/r/bZT53ZY/go.otto.security.audit.dangerous-execution.dangerous-execution origin: community severity: ERROR patterns: - pattern-inside: | $VM = otto.New(...) ... - pattern-not: $VM.Run("...", ...) - pattern: $VM.Run(...) languages: - go - id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures technology: - java - secrets - jwt category: security cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret shortlink: https://sg.run/RoDK semgrep.dev: rule: r_id: 9149 rv_id: 1262980 rule_id: oqUeAn version_id: d6Tyx8j url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret origin: community languages: - java severity: WARNING patterns: - pattern-either: - pattern: | (Algorithm $ALG) = $ALGO.$HMAC("$Y"); - pattern: | $SECRET = "$Y"; ... (Algorithm $ALG) = $ALGO.$HMAC($SECRET); - pattern: | class $CLASS { ... $TYPE $SECRET = "$Y"; ... $RETURNTYPE $FUNC (...) { ... (Algorithm $ALG) = $ALGO.$HMAC($SECRET); ... } ... } - focus-metavariable: $Y - metavariable-regex: metavariable: $HMAC regex: (HMAC384|HMAC256|HMAC512) - id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg shortlink: https://sg.run/Av14 semgrep.dev: rule: r_id: 9150 rv_id: 1262981 rule_id: zdUkzR version_id: ZRTKADq url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg origin: community languages: - java severity: ERROR pattern-either: - pattern: | $JWT.sign(com.auth0.jwt.algorithms.Algorithm.none()); - pattern: | $NONE = com.auth0.jwt.algorithms.Algorithm.none(); ... $JWT.sign($NONE); - pattern: |- class $CLASS { ... $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none(); ... $RETURNTYPE $FUNC (...) { ... $JWT.sign($NONE); ... } ... } - id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Call '.verify()' before using the token. metadata: cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: MEDIUM references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify shortlink: https://sg.run/Bk95 semgrep.dev: rule: r_id: 9151 rv_id: 1262979 rule_id: pKUOE9 version_id: vdT06Lp url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify origin: community languages: - java severity: WARNING patterns: - pattern: | com.auth0.jwt.JWT.decode(...); - pattern-not-inside: |- class $CLASS { ... $RETURNTYPE $FUNC (...) { ... $VERIFIER.verify(...); ... } } - id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN references: - https://www.owasp.org/index.php/Path_Traversal category: security technology: - jax-rs cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal shortlink: https://sg.run/DoWj semgrep.dev: rule: r_id: 9152 rv_id: 1262984 rule_id: 2ZUb9l version_id: 7ZTE3KW url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal origin: community message: Detected a potential path traversal. A malicious actor could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. severity: WARNING languages: - java pattern-either: - pattern: | $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { ... new File(..., $VAR, ...); ... } - pattern: |- $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { ... new File(..., $VAR, ...); ... } - id: java.jboss.security.session_sqli.find-sql-string-concatenation message: In $METHOD, $X is used to construct a SQL query via string concatenation. languages: - java severity: ERROR pattern-either: - pattern: | $RETURN $METHOD(...,String $X,...){ ... Session $SESSION = ...; ... String $QUERY = ... + $X + ...; ... PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); ... ResultSet $RESULT = $PS.executeQuery(); ... } - pattern: | $RETURN $METHOD(...,String $X,...){ ... String $QUERY = ... + $X + ...; ... Session $SESSION = ...; ... PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); ... ResultSet $RESULT = $PS.executeQuery(); ... } metadata: category: security technology: - jboss confidence: MEDIUM cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation shortlink: https://sg.run/W8kA semgrep.dev: rule: r_id: 9153 rv_id: 1262986 rule_id: X5U8rQ version_id: 8KT5r3v url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation origin: community - id: java.jjwt.security.jwt-none-alg.jjwt-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.3 Insecue Stateless Session Tokens control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jwt confidence: LOW references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.jjwt.security.jwt-none-alg.jjwt-none-alg shortlink: https://sg.run/0Q7b semgrep.dev: rule: r_id: 9154 rv_id: 1262987 rule_id: j2Uvol version_id: gETB7re url: https://semgrep.dev/playground/r/gETB7re/java.jjwt.security.jwt-none-alg.jjwt-none-alg origin: community languages: - java severity: ERROR patterns: - pattern: | io.jsonwebtoken.Jwts.builder(); - pattern-not-inside: |- $RETURNTYPE $FUNC(...) { ... $JWTS.signWith(...); ... } - id: java.lang.security.do-privileged-use.do-privileged-use severity: WARNING languages: - java metadata: cwe: - 'CWE-269: Improper Privilege Management' references: - https://docs.oracle.com/javase/8/docs/technotes/guides/security/doprivileged.html - https://wiki.sei.cmu.edu/confluence/display/java/Privilege+Escalation - http://phrack.org/papers/escaping_the_java_sandbox.html category: security technology: - java owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/java.lang.security.do-privileged-use.do-privileged-use shortlink: https://sg.run/6n76 semgrep.dev: rule: r_id: 9159 rv_id: 1263063 rule_id: bwUw28 version_id: o5TbDoY url: https://semgrep.dev/playground/r/o5TbDoY/java.lang.security.do-privileged-use.do-privileged-use origin: community message: Marking code as privileged enables a piece of trusted code to temporarily enable access to more resources than are available directly to the code that called it. Be very careful in your use of the privileged construct, and always remember to make the privileged code section as small as possible. patterns: - pattern-inside: | import java.security.*; ... - pattern-either: - pattern: AccessController.doPrivileged(...); - pattern: class $ACTION implements PrivilegedAction { ... } - id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN references: - https://www.owasp.org/index.php/Path_Traversal category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal shortlink: https://sg.run/oxXN semgrep.dev: rule: r_id: 9160 rv_id: 1263064 rule_id: NbUk7X version_id: zyTb2rq url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal origin: community message: Detected a potential path traversal. A malicious actor could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) - patterns: - pattern-inside: | $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); ... - pattern: | $PARAM = $VALS[$INDEX]; pattern-sanitizers: - pattern: org.apache.commons.io.FilenameUtils.getName(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (java.io.File $FILE) = ... - pattern: | (java.io.FileOutputStream $FOS) = ... - pattern: | new java.io.FileInputStream(...) severity: ERROR languages: - java - id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization severity: WARNING languages: - java metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.3 Insecue Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization shortlink: https://sg.run/zvO1 semgrep.dev: rule: r_id: 9161 rv_id: 1263065 rule_id: kxUk12 version_id: pZT03A1 url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization origin: community message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling of the message payload when ObjectMessage.getObject() is called. Deserialization of untrusted data can lead to security flaws; a remote attacker could via a crafted JMS ObjectMessage to execute arbitrary code with the permissions of the application listening/consuming JMS Messages. In this case, the JMS MessageListener consume an ObjectMessage type received inside the onMessage method, which may lead to arbitrary code execution when calling the $Y.getObject method. patterns: - pattern-inside: | public class $JMS_LISTENER implements MessageListener { ... public void onMessage(Message $JMS_MSG) { ... } } - pattern-either: - pattern-inside: $X = $Y.getObject(...); - pattern-inside: $X = ($Z) $Y.getObject(...); - id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss message: 'Cross-site scripting detected in HttpServletResponse writer with variable ''$VAR''. User input was detected going directly from the HttpServletRequest into output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: ''Encode.forHtml($VAR)''.' metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss shortlink: https://sg.run/pxjN semgrep.dev: rule: r_id: 9162 rv_id: 1263066 rule_id: wdUJOk version_id: 2KTv2EG url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss origin: community severity: ERROR patterns: - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } - pattern-inside: $VAR = $REQ.getParameter(...); ... - pattern-either: - pattern: $RESP.getWriter(...).write(..., $VAR, ...); - pattern: | $WRITER = $RESP.getWriter(...); ... $WRITER.write(..., $VAR, ...); languages: - java - id: java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled shortlink: https://sg.run/2x75 semgrep.dev: rule: r_id: 9163 rv_id: 1263068 rule_id: x8Unkq version_id: jQTn5Jv url: https://semgrep.dev/playground/r/jQTn5Jv/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled origin: community message: XML external entities are enabled for this XMLInputFactory. This is vulnerable to XML external entity attacks. Disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" to false. patterns: - pattern-either: - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", true); - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, true); - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, true); - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.TRUE); - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.TRUE); - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, Boolean.TRUE); languages: - java - id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe shortlink: https://sg.run/XBwA semgrep.dev: rule: r_id: 9164 rv_id: 1263069 rule_id: OrU35O version_id: 1QTypQZ url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe origin: community message: XML external entities are not explicitly disabled for this XMLInputFactory. This could be vulnerable to XML external entity vulnerabilities. Explicitly disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" to false. patterns: - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); ... } - pattern-either: - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) - pattern: new XMLInputFactory(...) languages: - java - id: java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind metadata: cwe: - 'CWE-287: Improper Authentication' owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS category: security technology: - java references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind shortlink: https://sg.run/jR6A semgrep.dev: rule: r_id: 9165 rv_id: 1262988 rule_id: eqU8J3 version_id: QkTGqE0 url: https://semgrep.dev/playground/r/QkTGqE0/java.lang.security.audit.anonymous-ldap-bind.anonymous-ldap-bind origin: community message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html for more information. severity: WARNING pattern: | $ENV.put($CTX.SECURITY_AUTHENTICATION, "none"); ... $DCTX = new InitialDirContext($ENV, ...); languages: - java - id: java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion metadata: cwe: - 'CWE-704: Incorrect Type Conversion or Cast' owasp: A03:2017 - Sensitive Data Exposure source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BAD_HEXA_CONVERSION category: security technology: - java references: - https://cwe.mitre.org/data/definitions/704.html subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion shortlink: https://sg.run/1Z7D semgrep.dev: rule: r_id: 9166 rv_id: 945646 rule_id: v8Uny0 version_id: QkTZzgy url: https://semgrep.dev/playground/r/QkTZzgy/java.lang.security.audit.bad-hexa-conversion.bad-hexa-conversion origin: community message: '''Integer.toHexString()'' strips leading zeroes from each byte if read byte-by-byte. This mistake weakens the hash value computed since it introduces more collisions. Use ''String.format("%02X", ...)'' instead.' severity: WARNING languages: - java pattern: |- $X $METHOD(...) { ... MessageDigest $MD = ...; ... $MD.digest(...); ... Integer.toHexString(...); } - id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size shortlink: https://sg.run/9o74 semgrep.dev: rule: r_id: 9167 rv_id: 1262989 rule_id: d8UjJ3 version_id: 3ZT4X2r url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size origin: community message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits or more, or switch to use AES instead. severity: WARNING languages: - java patterns: - pattern: | $KEYGEN = KeyGenerator.getInstance("Blowfish"); ... $KEYGEN.init($SIZE); - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 128 - id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A malicious actor could discern the difference between plaintext with valid or invalid padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' instead. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE references: - https://capec.mitre.org/data/definitions/463.html - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY category: security technology: - java subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle shortlink: https://sg.run/ydxr semgrep.dev: rule: r_id: 9168 rv_id: 1262990 rule_id: ZqU5oD version_id: 44TEjbE url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle origin: community severity: WARNING fix: | "AES/GCM/NoPadding" languages: - java patterns: - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") - pattern: | "=~/.*\/CBC\/PKCS5Padding/" - id: java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call patterns: - metavariable-pattern: metavariable: $RUNTIME patterns: - pattern-either: - pattern: (java.lang.Runtime $R) - pattern: java.lang.Runtime.getRuntime(...) - pattern-either: - pattern: $RUNTIME.exec($X + $Y); - pattern: $RUNTIME.exec(String.format(...)); - pattern: $RUNTIME.loadLibrary($X + $Y); - pattern: $RUNTIME.loadLibrary(String.format(...)); - patterns: - pattern-either: - pattern: | $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $ARG,...) - pattern: | $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...),...) - pattern: | $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...},...) - patterns: - pattern-either: - pattern: | $RUNTIME.exec($CMD,"-c",$ARG,...) - pattern: | $RUNTIME.exec(Arrays.asList($CMD,"-c",$ARG,...),...) - pattern: | $RUNTIME.exec(new String[]{$CMD,"-c",$ARG,...},...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; ... - patterns: - pattern-either: - pattern: | $RUNTIME.exec($CMD, $EXECUTE, $ARG, ...) - pattern-inside: | $CMD = new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/", ...}; ... - patterns: - pattern-either: - pattern: | $RUNTIME.exec("=~/(sh|bash|ksh|csh|tcsh|zsh)/", $BASH, $ARG,...) - pattern: | $RUNTIME.exec(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...),...) - pattern: | $RUNTIME.exec(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/",$BASH,$ARG,...},...) - pattern-inside: | $BASH = new String[]{"=~/(-c)/", ...}; ... - pattern-not-inside: | $ARG = "..."; ... - pattern-not: | $RUNTIME.exec("...","...","...",...) - pattern-not: | $RUNTIME.exec(new String[]{"...","...","...",...},...) - pattern-not: | $RUNTIME.exec(Arrays.asList("...","...","...",...),...) message: A formatted or concatenated string was detected as input to a java.lang.Runtime call. This is dangerous if a variable is controlled by user input and could result in a command injection. Ensure your variables are not controlled by users or sufficiently sanitized. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#COMMAND_INJECTION. category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call shortlink: https://sg.run/rd90 semgrep.dev: rule: r_id: 9169 rv_id: 1262991 rule_id: nJUzvJ version_id: PkTR3ez url: https://semgrep.dev/playground/r/PkTR3ez/java.lang.security.audit.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call origin: community severity: ERROR languages: - java - id: java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTPONLY_COOKIE asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.4.2 Missing Cookie Attribute control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management version: '4' category: security technology: - java references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly shortlink: https://sg.run/b7Be semgrep.dev: rule: r_id: 9170 rv_id: 1262993 rule_id: EwU2z6 version_id: 5PTo17r url: https://semgrep.dev/playground/r/5PTo17r/java.lang.security.audit.cookie-missing-httponly.cookie-missing-httponly origin: community message: A cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie. Set the 'HttpOnly' flag by calling 'cookie.setHttpOnly(true);' severity: WARNING languages: - java patterns: - pattern-not-inside: $COOKIE.setValue(""); ... - pattern-either: - pattern: $COOKIE.setHttpOnly(false); - patterns: - pattern-not-inside: $COOKIE.setHttpOnly(...); ... - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... - pattern: $RESPONSE.addCookie($COOKIE); - id: java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_COOKIE asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.4.1 Missing Cookie Attribute control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v34-cookie-based-session-management version: '4' category: security technology: - java references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag shortlink: https://sg.run/kXoK semgrep.dev: rule: r_id: 9172 rv_id: 1262994 rule_id: L1Uyvp version_id: GxTkelB url: https://semgrep.dev/playground/r/GxTkelB/java.lang.security.audit.cookie-missing-secure-flag.cookie-missing-secure-flag origin: community message: A cookie was detected without setting the 'secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'secure' flag by calling '$COOKIE.setSecure(true);' severity: WARNING languages: - java patterns: - pattern-not-inside: $COOKIE.setValue(""); ... - pattern-either: - pattern: $COOKIE.setSecure(false); - patterns: - pattern-not-inside: $COOKIE.setSecure(...); ... - pattern-not-inside: $COOKIE = ResponseCookie.from(...). ...; ... - pattern: $RESPONSE.addCookie($COOKIE); - id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs message: When data from an untrusted source is put into a logger and not neutralized correctly, an attacker could forge log entries or include malicious content. metadata: cwe: - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs shortlink: https://sg.run/wek0 semgrep.dev: rule: r_id: 9173 rv_id: 1262995 rule_id: 8GUjwW version_id: RGT0LEr url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs origin: community severity: WARNING languages: - java patterns: - pattern-either: - patterns: - pattern-inside: | class $CLASS { ... Logger $LOG = ...; ... } - pattern-either: - pattern-inside: | $X $METHOD(...,HttpServletRequest $REQ,...) { ... } - pattern-inside: | $X $METHOD(...,ServletRequest $REQ,...) { ... } - pattern-inside: | $X $METHOD(...) { ... HttpServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... ServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... Logger $LOG = ...; ... HttpServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... Logger $LOG = ...; ... ServletRequest $REQ = ...; ... } - pattern-either: - pattern: | String $VAL = $REQ.getParameter(...); ... $LOG.$LEVEL(<... $VAL ...>); - pattern: | String $VAL = $REQ.getParameter(...); ... $LOG.log($LEVEL,<... $VAL ...>); - pattern: | $LOG.$LEVEL(<... $REQ.getParameter(...) ...>); - pattern: | $LOG.log($LEVEL,<... $REQ.getParameter(...) ...>); - id: java.lang.security.audit.el-injection.el-injection metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#EL_INJECTION category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.lang.security.audit.el-injection.el-injection shortlink: https://sg.run/x1wp semgrep.dev: rule: r_id: 9174 rv_id: 1263021 rule_id: gxU1Np version_id: pZT03e1 url: https://semgrep.dev/playground/r/pZT03e1/java.lang.security.audit.el-injection.el-injection origin: community message: An expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. severity: WARNING languages: - java patterns: - pattern-either: - pattern: | class $CLASS { ... ExpressionFactory $EF; ... $X $METHOD(...) { ... $EF.createValueExpression($CTX,$INPUT,...); ... } ... } - pattern: | class $CLASS { ... ExpressionFactory $EF = ...; ... $X $METHOD(...) { ... $EF.createValueExpression($CTX,$INPUT,...); ... } ... } - pattern: | $X $METHOD(...) { ... ExpressionFactory $EF = ...; ... $EF.createValueExpression($CTX,$INPUT,...); ... } - pattern: | $X $METHOD(...,ExpressionFactory $EF,...) { ... $EF.createValueExpression($CTX,$INPUT,...); ... } - pattern: | class $CLASS { ... ExpressionFactory $EF; ... $X $METHOD(...) { ... $EF.createMethodExpression($CTX,$INPUT,...); ... } ... } - pattern: | class $CLASS { ... ExpressionFactory $EF = ...; ... $X $METHOD(...) { ... $EF.createMethodExpression($CTX,$INPUT,...); ... } ... } - pattern: | $X $METHOD(...) { ... ExpressionFactory $EF = ...; ... $EF.createMethodExpression($CTX,$INPUT,...); ... } - pattern: | $X $METHOD(...,ExpressionFactory $EF,...) { ... $EF.createMethodExpression($CTX,$INPUT,...); ... } - pattern: | $X $METHOD(String $INPUT, ...) { ... $OBJECT.buildConstraintViolationWithTemplate($INPUT, ...); ... } - pattern-not: | $X $METHOD(...) { ... $EF.createValueExpression($CTX,"...",...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $EF.createValueExpression($CTX,$S,...); ... } - pattern-not: | $X $METHOD(...) { ... $EF.createMethodExpression($CTX,"...",...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $EF.createMethodExpression($CTX,$S,...); ... } - id: java.lang.security.audit.formatted-sql-string.formatted-sql-string metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.5 Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string shortlink: https://sg.run/OPXp semgrep.dev: rule: r_id: 9175 rv_id: 1409389 rule_id: QrUzxR version_id: ExTeyBP url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string origin: community options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | $ANNOT $FUNC (..., $INPUT, ...) { ... } - pattern: (String $INPUT) - focus-metavariable: $INPUT label: INPUT - patterns: - pattern-either: - pattern: $X + $INPUT - pattern: $X += $INPUT - pattern: String.format(..., $INPUT, ...) - pattern: String.join(..., $INPUT, ...) - pattern: (String $STR).concat($INPUT) - pattern: $INPUT.concat(...) - patterns: - pattern-either: - pattern: $STRB.append($INPUT) - pattern: new $STRB(..., $INPUT, ...) - metavariable-type: metavariable: $STRB type: StringBuilder label: CONCAT requires: INPUT pattern-propagators: - pattern: (StringBuffer $S).append($X) from: $X to: $S - pattern: (StringBuilder $S).append($X) from: $X to: $S pattern-sinks: - patterns: - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) - pattern-either: - pattern: (Statement $S).$SQLFUNC(...) - pattern: (PreparedStatement $P).$SQLFUNC(...) - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) - pattern: (EntityManager $EM).$SQLFUNC(...) - metavariable-regex: metavariable: $SQLFUNC regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare requires: CONCAT pattern-sanitizers: - patterns: - pattern: (CriteriaBuilder $CB).$ANY(...) severity: ERROR languages: - java - id: java.lang.security.audit.http-response-splitting.http-response-splitting metadata: cwe: - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP Request/Response Splitting'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING references: - https://www.owasp.org/index.php/HTTP_Response_Splitting category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting shortlink: https://sg.run/eL0l semgrep.dev: rule: r_id: 9176 rv_id: 1263023 rule_id: 3qUPyK version_id: X0Tzykw url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting origin: community message: Older Java application servers are vulnerable to HTTP response splitting, which may occur if an HTTP request can be injected with CRLF characters. This finding is reported for completeness; it is recommended to ensure your environment is not affected by testing this yourself. severity: INFO languages: - java pattern-either: - pattern: | $VAR = $REQ.getParameter(...); ... $COOKIE = new Cookie(..., $VAR, ...); ... $RESP.addCookie($COOKIE, ...); - patterns: - pattern-inside: | $RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) { ... } - pattern: | $COOKIE = new Cookie(..., $VAR, ...); ... $RESP.addCookie($COOKIE, ...); - id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection metadata: cwe: - 'CWE-297: Improper Validation of Certificate with Host Mismatch' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL category: security technology: - java references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection shortlink: https://sg.run/vzN4 semgrep.dev: rule: r_id: 9177 rv_id: 1263024 rule_id: 4bUkrW version_id: jQTn5Dv url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection origin: community message: Insecure SMTP connection detected. This connection will trust any SSL certificate. Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'. severity: WARNING patterns: - pattern-not-inside: | $EMAIL.setSSLCheckServerIdentity(true); ... - pattern-inside: | $EMAIL = new SimpleEmail(...); ... - pattern: $EMAIL.send(...); languages: - java - id: java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION_SPRING_JDBC asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.5 Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - jdbc references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string shortlink: https://sg.run/dKWY semgrep.dev: rule: r_id: 9178 rv_id: 1263026 rule_id: PeUZNX version_id: 9lT4bqk url: https://semgrep.dev/playground/r/9lT4bqk/java.lang.security.audit.jdbc-sql-formatted-string.jdbc-sql-formatted-string origin: community message: 'Possible JDBC injection detected. Use the parameterized query feature available in queryForObject instead of concatenating or formatting strings: ''jdbc.queryForObject("select * from table where name = ?", Integer.class, parameterName);''' patterns: - pattern-inside: | $JDBC = new JdbcTemplate(...); ... - pattern-either: - pattern: $JDBC.queryForObject($STR + $VAR, ...); - pattern: $JDBC.queryForObject(String.format(...), ...); - pattern: | String $Q = $STR + $VAR; ... $JDBC.queryForObject($Q, ...); - pattern: | String $Q = String.format(...); ... $JDBC.queryForObject($Q, ...); - pattern: | StringBuilder $Q = new StringBuilder(...); ... $Q.append($STR + $VAR); ... $JDBC.queryForObject($Q, ...); - pattern: $JDBC.queryForList($STR + $VAR); - pattern: $JDBC.queryForList(String.format(...)); - pattern: | String $Q = $STR + $VAR; ... $JDBC.queryForList($Q); - pattern: | String $Q = String.format(...); ... $JDBC.queryForList($Q); - pattern: | StringBuilder $Q = new StringBuilder(...); ... $Q.append($STR + $VAR); ... $JDBC.queryForList($Q, ...); - pattern: $JDBC.update($STR + $VAR); - pattern: $JDBC.update(String.format(...)); - pattern: | String $Q = $STR + $VAR; ... $JDBC.update($Q); - pattern: | String $Q = String.format(...); ... $JDBC.update($Q); - pattern: | StringBuilder $Q = new StringBuilder(...); ... $Q.append($STR + $VAR); ... $JDBC.update($Q, ...); - pattern: $JDBC.execute($STR + $VAR); - pattern: $JDBC.execute(String.format(...)); - pattern: | String $Q = $STR + $VAR; ... $JDBC.execute($Q); - pattern: | String $Q = String.format(...); ... $JDBC.execute($Q); - pattern: | StringBuilder $Q = new StringBuilder(...); ... $Q.append($STR + $VAR); ... $JDBC.execute($Q, ...); - pattern: $JDBC.insert($STR + $VAR); - pattern: $JDBC.insert(String.format(...)); - pattern: | String $Q = $STR + $VAR; ... $JDBC.insert($Q); - pattern: | String $Q = String.format(...); ... $JDBC.insert($Q); - pattern: | StringBuilder $Q = new StringBuilder(...); ... $Q.append($STR + $VAR); ... $JDBC.insert($Q, ...); severity: WARNING languages: - java - id: java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP Injection'')' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ENTRY_POISONING asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.7 Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html category: security technology: - java subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - LDAP Injection source: https://semgrep.dev/r/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning shortlink: https://sg.run/ZvOn semgrep.dev: rule: r_id: 9179 rv_id: 1263027 rule_id: JDUy8B version_id: yeTxpGP url: https://semgrep.dev/playground/r/yeTxpGP/java.lang.security.audit.ldap-entry-poisoning.ldap-entry-poisoning origin: community message: An object-returning LDAP search will allow attackers to control the LDAP response. This could lead to Remote Code Execution. severity: WARNING pattern-either: - pattern: | new SearchControls($S, $CL, $TL, $AT, true, $DEREF) - pattern: | SearchControls $VAR = new SearchControls(); ... $VAR.setReturningObjFlag(true); languages: - java - id: java.lang.security.audit.ldap-injection.ldap-injection message: Detected non-constant data passed into an LDAP query. If this data can be controlled by an external user, this is an LDAP injection. Ensure data passed to an LDAP query is not controllable; or properly sanitize the data. metadata: cwe: - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_INJECTION asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.7 Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - LDAP Injection source: https://semgrep.dev/r/java.lang.security.audit.ldap-injection.ldap-injection shortlink: https://sg.run/nd2O semgrep.dev: rule: r_id: 9180 rv_id: 1263028 rule_id: 5rUObQ version_id: rxTAKl2 url: https://semgrep.dev/playground/r/rxTAKl2/java.lang.security.audit.ldap-injection.ldap-injection origin: community severity: WARNING languages: - java patterns: - pattern-either: - pattern-inside: | $X $METHOD(...) { ... InitialDirContext $CTX = ...; ... } - pattern-inside: | $X $METHOD(...) { ... DirContext $CTX = ...; ... } - pattern-inside: | $X $METHOD(...) { ... InitialLdapContext $CTX = ...; ... } - pattern-inside: | $X $METHOD(...) { ... LdapContext $CTX = ...; ... } - pattern-inside: | $X $METHOD(...) { ... LdapCtx $CTX = ...; ... } - pattern-inside: | $X $METHOD(...) { ... EventDirContext $CTX = ...; ... } - pattern: | $X $METHOD(...) { ... $CTX.search($Y,$INPUT,...); ... } - pattern-not: | $X $METHOD(...) { ... $CTX.search($Y,"...",...); ... } - id: java.lang.security.audit.object-deserialization.object-deserialization metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OBJECT_DESERIALIZATION references: - https://www.owasp.org/index.php/Deserialization_of_untrusted_data - https://www.oracle.com/java/technologies/javase/seccodeguide.html#8 category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.audit.object-deserialization.object-deserialization shortlink: https://sg.run/Ek0A semgrep.dev: rule: r_id: 9181 rv_id: 1263030 rule_id: GdU7py version_id: NdTzyGe url: https://semgrep.dev/playground/r/NdTzyGe/java.lang.security.audit.object-deserialization.object-deserialization origin: community message: Found object deserialization using ObjectInputStream. Deserializing entire Java objects is dangerous because malicious actors can create Java object streams with unintended consequences. Ensure that the objects being deserialized are not user-controlled. If this must be done, consider using HMACs to sign the data stream to make sure it is not tampered with, or consider only transmitting object fields and populating a new object. severity: WARNING languages: - java pattern: new ObjectInputStream(...); - id: java.lang.security.audit.ognl-injection.ognl-injection message: A expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OGNL_INJECTION category: security technology: - ognl references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.lang.security.audit.ognl-injection.ognl-injection shortlink: https://sg.run/7o7R semgrep.dev: rule: r_id: 9182 rv_id: 1263031 rule_id: ReUgjJ version_id: kbTzG3Y url: https://semgrep.dev/playground/r/kbTzG3Y/java.lang.security.audit.ognl-injection.ognl-injection origin: community severity: WARNING languages: - java patterns: - pattern-either: - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.getGetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.getSetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.getField($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlReflectionProvider $P,...) { ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.getGetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.getSetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.getField($T, $INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...,ReflectionProvider $P,...) { ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...,TextParseUtil $P,...) { ... $P.translateVariables($INPUT,...); ... } - pattern: | $X $METHOD(...,TextParseUtil $P,...) { ... $P.translateVariablesCollection($INPUT,...); ... } - pattern: | $X $METHOD(...,TextParseUtil $P,...) { ... $P.shallBeIncluded($INPUT,...); ... } - pattern: | $X $METHOD(...,TextParseUtil $P,...) { ... $P.commaDelimitedStringToSet($INPUT,...); ... } - pattern: | $X $METHOD(...,TextParser $P,...) { ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlTextParser $P,...) { ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.callMethod($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlUtil $P,...) { ... $P.compile($INPUT,...); ... } - pattern: | $X $METHOD(...,VelocityStrutsUtil $P,...) { ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.isTrue($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.findString($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.getText($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.translateVariables($INPUT,...); ... } - pattern: | $X $METHOD(...,StrutsUtil $P,...) { ... $P.makeSelectList($INPUT,...); ... } - pattern: | $X $METHOD(...,OgnlTool $P,...) { ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...,ValueStack $P,...) { ... $P.findString($INPUT,...); ... } - pattern: | $X $METHOD(...,ValueStack $P,...) { ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...,ValueStack $P,...) { ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...,ValueStack $P,...) { ... $P.setParameter($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.getGetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.getSetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.getField($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlReflectionProvider $P = ...; ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.getGetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.getSetMethod($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.getField($T, $INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ReflectionProvider $P = ...; ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... TextParseUtil $P = ...; ... $P.translateVariables($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... TextParseUtil $P = ...; ... $P.translateVariablesCollection($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... TextParseUtil $P = ...; ... $P.shallBeIncluded($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... TextParseUtil $P = ...; ... $P.commaDelimitedStringToSet($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... TextParser $P = ...; ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlTextParser $P = ...; ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.setProperties($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.setProperty($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.getValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.callMethod($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlUtil $P = ...; ... $P.compile($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... VelocityStrutsUtil $P = ...; ... $P.evaluate($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.isTrue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.findString($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.getText($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.translateVariables($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... StrutsUtil $P = ...; ... $P.makeSelectList($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... OgnlTool $P = ...; ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ValueStack $P = ...; ... $P.findString($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ValueStack $P = ...; ... $P.findValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ValueStack $P = ...; ... $P.setValue($INPUT,...); ... } - pattern: | $X $METHOD(...) { ... ValueStack $P = ...; ... $P.setParameter($INPUT,...); ... } - pattern-not: | $X $METHOD(...) { ... $P.getGetMethod($T,"...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.getSetMethod($T,"...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.getField($T,"...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.setProperties("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.setProperty("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.getValue("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.setValue("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.translateVariables("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.translateVariablesCollection("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.shallBeIncluded("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.commaDelimitedStringToSet("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.evaluate("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.callMethod("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.compile("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.isTrue("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.findString("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.findValue("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.getText("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.makeSelectList("...",...); ... } - pattern-not: | $X $METHOD(...) { ... $P.setParameter("...",...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.getGetMethod($T,$S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.getSetMethod($T,$S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.getField($T,$S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.setProperties($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.setProperty($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.getValue($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.setValue($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.translateVariables($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.translateVariablesCollection($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.shallBeIncluded($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.commaDelimitedStringToSet($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.evaluate($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.callMethod($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.compile($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.isTrue($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.findString($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.findValue($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.getText($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.makeSelectList($S,...); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $P.setParameter($S,...); ... } - id: java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission message: Detected file permissions that are overly permissive (read, write, and execute). It is generally a bad practices to set overly permissive file permission such as read+write+exec for all users. If the file affected is a configuration, a binary, a script or sensitive data, it can lead to privilege escalation or information leakage. Instead, follow the principle of least privilege and give users only the permissions they need. severity: WARNING languages: - java metadata: cwe: - 'CWE-276: Incorrect Default Permissions' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#OVERLY_PERMISSIVE_FILE_PERMISSION category: security technology: - java references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission shortlink: https://sg.run/LwzJ semgrep.dev: rule: r_id: 9183 rv_id: 1263032 rule_id: AbUzwB version_id: w8TRoNn url: https://semgrep.dev/playground/r/w8TRoNn/java.lang.security.audit.overly-permissive-file-permission.overly-permissive-file-permission origin: community pattern-either: - pattern: java.nio.file.Files.setPosixFilePermissions($FILE, java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/")); - pattern: | $TYPE $P = java.nio.file.attribute.PosixFilePermissions.fromString("=~/(^......r..$)|(^.......w.$)|(^........x$)/"); ... java.nio.file.Files.setPosixFilePermissions($FILE, $P); - pattern: | $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_READ); ... java.nio.file.Files.setPosixFilePermissions($FILE, $P); - pattern: | $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_WRITE); ... java.nio.file.Files.setPosixFilePermissions($FILE, $P); - pattern: |- $P.add(java.nio.file.attribute.PosixFilePermission.OTHERS_EXECUTE); ... java.nio.file.Files.setPosixFilePermissions($FILE, $P); - id: java.lang.security.audit.permissive-cors.permissive-cors message: https://find-sec-bugs.github.io/bugs.htm#PERMISSIVE_CORS Permissive CORS policy will allow a malicious application to communicate with the victim application in an inappropriate way, leading to spoofing, data theft, relay and other attacks. metadata: cwe: - 'CWE-183: Permissive List of Allowed Inputs' asvs: section: 'V14: Configuration Verification Requirements' control_id: 14.4.8 Permissive CORS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x22-V14-Config.md#v144-http-security-headers-requirements version: '4' category: security technology: - java owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.permissive-cors.permissive-cors shortlink: https://sg.run/8y77 semgrep.dev: rule: r_id: 9184 rv_id: 1263033 rule_id: BYUN66 version_id: xyTjz0p url: https://semgrep.dev/playground/r/xyTjz0p/java.lang.security.audit.permissive-cors.permissive-cors origin: community severity: WARNING languages: - java pattern-either: - pattern: | HttpServletResponse $RES = ...; ... $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); - pattern: | HttpServletResponse $RES = ...; ... $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); - pattern: | ServerHttpResponse $RES = ...; ... $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); - pattern: | HttpHeaders $HEADERS = ...; ... $HEADERS.set("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); - pattern: | ServerWebExchange $SWE = ...; ... $SWE.getResponse().getHeaders().add("Access-Control-Allow-Origin", "*"); - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.addHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.setHeader("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); ... } - pattern: | $X $METHOD(...,ServerHttpResponse $RES,...) { ... $RES.getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); ... } - pattern: | $X $METHOD(...,ServerWebExchange $SWE,...) { ... $SWE.getResponse().getHeaders().add("=~/access-control-allow-origin/i", "=~/^\*|null$/i"); ... } - pattern: ResponseEntity.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") - pattern: ServerResponse.$RES().header("=~/access-control-allow-origin/i", "=~/^\*|null$/i") - id: java.lang.security.audit.script-engine-injection.script-engine-injection message: Detected potential code injection using ScriptEngine. Ensure user-controlled data cannot enter '.eval()', otherwise, this is a code injection vulnerability. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SCRIPT_ENGINE_INJECTION category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.lang.security.audit.script-engine-injection.script-engine-injection shortlink: https://sg.run/gLqn semgrep.dev: rule: r_id: 9185 rv_id: 1263034 rule_id: DbUpAr version_id: O9TpxEp url: https://semgrep.dev/playground/r/O9TpxEp/java.lang.security.audit.script-engine-injection.script-engine-injection origin: community severity: WARNING languages: - java patterns: - pattern-either: - pattern-inside: | class $CLASS { ... ScriptEngine $SE; ... } - pattern-inside: | class $CLASS { ... ScriptEngine $SE = ...; ... } - pattern-inside: | $X $METHOD(...) { ... ScriptEngine $SE = ...; ... } - pattern: | $X $METHOD(...) { ... $SE.eval(...); ... } - pattern-not: | $X $METHOD(...) { ... $SE.eval("..."); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $SE.eval($S); ... } - id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect message: Application redirects to a destination URL specified by a user-supplied parameter that is not validated. This could direct users to malicious locations. Consider using an allowlist to validate URLs. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.1.5 Open Redirect control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements version: '4' category: security technology: - java references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln impact: LOW likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect shortlink: https://sg.run/Q51P semgrep.dev: rule: r_id: 9186 rv_id: 1263048 rule_id: WAUo0p version_id: PkTR329 url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect origin: community severity: WARNING languages: - java pattern-either: - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... String $URL = $REQ.getParameter(...); ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... String $URL = $REQ.getParameter(...); ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,String $URL,...) { ... HttpServletResponse $RES = ...; ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... $RES.sendRedirect($REQ.getParameter(...)); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... $RES.sendRedirect($REQ.getParameter(...)); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... String $URL = $REQ.getParameter(...); ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... String $URL = $REQ.getParameter(...); ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,String $URL,...) { ... HttpServletResponse $RES = ...; ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... $RES.addHeader("Location",$REQ.getParameter(...)); ... } - pattern: |- $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... $RES.addHeader("Location",$REQ.getParameter(...)); ... } - id: java.lang.security.audit.url-rewriting.url-rewriting message: URL rewriting has significant security risks. Since session ID appears in the URL, it may be easily seen by third parties. metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#URL_REWRITING category: security technology: - java references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.lang.security.audit.url-rewriting.url-rewriting shortlink: https://sg.run/3x7b semgrep.dev: rule: r_id: 9187 rv_id: 1263049 rule_id: 0oU5j3 version_id: JdTzxGb url: https://semgrep.dev/playground/r/JdTzxGb/java.lang.security.audit.url-rewriting.url-rewriting origin: community severity: WARNING languages: - java pattern-either: - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.encodeURL(...); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.encodeUrl(...); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.encodeRedirectURL(...); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...) { ... $RES.encodeRedirectUrl(...); ... } - pattern: | $X $METHOD(...) { ... HttpServletResponse $RES = ...; ... $RES.encodeURL(...); ... } - pattern: | $X $METHOD(...) { ... HttpServletResponse $RES = ...; ... $RES.encodeUrl(...); ... } - pattern: | $X $METHOD(...) { ... HttpServletResponse $RES = ...; ... $RES.encodeRedirectURL(...); ... } - pattern: |- $X $METHOD(...) { ... HttpServletResponse $RES = ...; ... $RES.encodeRedirectUrl(...); ... } - id: java.lang.security.audit.weak-ssl-context.weak-ssl-context metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT references: - https://tools.ietf.org/html/rfc7568 - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html category: security technology: - java subcategory: - audit likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context shortlink: https://sg.run/4x7E semgrep.dev: rule: r_id: 9188 rv_id: 1263050 rule_id: KxUb1k version_id: 5PTo1rW url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context origin: community message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") for the best security. severity: WARNING languages: - java patterns: - pattern-not: SSLContext.getInstance("TLSv1.3") - pattern-not: SSLContext.getInstance("TLSv1.2") - pattern: SSLContext.getInstance("...") fix-regex: regex: (.*?)\.getInstance\(.*?\) replacement: \1.getInstance("TLSv1.2") - id: java.lang.security.audit.xml-decoder.xml-decoder message: XMLDecoder should not be used to parse untrusted data. Deserializing user input can lead to arbitrary code execution. Use an alternative and explicitly disable external entities. See https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html for alternatives and vulnerability prevention. metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XML_DECODER references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xml-decoder.xml-decoder shortlink: https://sg.run/PJjq semgrep.dev: rule: r_id: 9189 rv_id: 1263051 rule_id: qNUj3y version_id: GxTkeY1 url: https://semgrep.dev/playground/r/GxTkeY1/java.lang.security.audit.xml-decoder.xml-decoder origin: community severity: WARNING languages: - java patterns: - pattern: | $X $METHOD(...) { ... new XMLDecoder(...); ... } - pattern-not: | $X $METHOD(...) { ... new XMLDecoder("..."); ... } - pattern-not: |- $X $METHOD(...) { ... String $STR = "..."; ... new XMLDecoder($STR); ... } - id: java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_REQUEST_WRAPPER category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure shortlink: https://sg.run/J96Q semgrep.dev: rule: r_id: 9190 rv_id: 1263056 rule_id: lBU9Gj version_id: WrTqKGK url: https://semgrep.dev/playground/r/WrTqKGK/java.lang.security.audit.xssrequestwrapper-is-insecure.xssrequestwrapper-is-insecure origin: community message: It looks like you're using an implementation of XSSRequestWrapper from dzone. (https://www.javacodegeeks.com/2012/07/anti-cross-site-scripting-xss-filter.html) The XSS filtering in this code is not secure and can be bypassed by malicious actors. It is recommended to use a stack that automatically escapes in your view or templates instead of filtering yourself. severity: WARNING languages: - java pattern-either: - pattern: | class XSSRequestWrapper extends HttpServletRequestWrapper { ... } - pattern: |- $P = $X.compile("", $X.CASE_INSENSITIVE); $V = $P.matcher(...).replaceAll(""); - id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated message: DES is considered deprecated. AES is the recommended cipher. Upgrade to use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard for more information. metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated shortlink: https://sg.run/5Q73 semgrep.dev: rule: r_id: 9191 rv_id: 1262996 rule_id: PeUZNg version_id: A8TgdEn url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated origin: community severity: WARNING patterns: - pattern-either: - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") - pattern-inside: $CIPHER.getInstance("DES") - pattern-either: - pattern: | "=~/DES/.*/" - pattern: | "DES" fix: | "AES/GCM/NoPadding" languages: - java - kt - id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended cipher. Upgrade to use AES. metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE references: - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated shortlink: https://sg.run/Geqn semgrep.dev: rule: r_id: 9192 rv_id: 1262997 rule_id: JDUy8J version_id: BjTkZyQ url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated origin: community severity: WARNING patterns: - pattern-either: - pattern: | $CIPHER.getInstance("=~/DESede.*/") - pattern: | $CRYPTO.KeyGenerator.getInstance("DES") languages: - java - kt - id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher shortlink: https://sg.run/Ro9K semgrep.dev: rule: r_id: 9193 rv_id: 1262998 rule_id: 5rUOb6 version_id: DkTRbwL url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher origin: community message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. severity: WARNING languages: - java patterns: - pattern: | Cipher $VAR = $CIPHER.getInstance($MODE); - metavariable-regex: metavariable: $MODE regex: .*ECB.* - id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher patterns: - pattern-either: - pattern: new NullCipher(...); - pattern: new javax.crypto.NullCipher(...); metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher shortlink: https://sg.run/AvA4 semgrep.dev: rule: r_id: 9194 rv_id: 1263001 rule_id: GdU7pw version_id: K3TKkgB url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher origin: community message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector message: Initialization Vectors (IVs) for block ciphers should be randomly generated each time they are used. Using a static IV means the same plaintext encrypts to the same ciphertext every time, weakening the strength of the encryption. metadata: cwe: - 'CWE-329: Generation of Predictable IV with CBC Mode' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cwe.mitre.org/data/definitions/329.html category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector shortlink: https://sg.run/BkB5 semgrep.dev: rule: r_id: 9195 rv_id: 1263002 rule_id: ReUgj1 version_id: qkTR7vP url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector origin: community severity: WARNING languages: - java pattern-either: - pattern: | byte[] $IV = { ... }; ... new IvParameterSpec($IV, ...); - pattern: | class $CLASS { byte[] $IV = { ... }; ... $METHOD(...) { ... new IvParameterSpec($IV, ...); ... } } - id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING references: - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java - kotlin subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding shortlink: https://sg.run/DoOj semgrep.dev: rule: r_id: 9196 rv_id: 1263003 rule_id: AbUzoj version_id: l4TJRpK url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding origin: community message: Using RSA without OAEP mode weakens the encryption. severity: WARNING languages: - java - kt pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") - id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket metadata: functional-categories: - net::search::crypto-config::java.net cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket shortlink: https://sg.run/W8zA semgrep.dev: rule: r_id: 9197 rv_id: 1263008 rule_id: BYUN3X version_id: RGT0LEj url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket origin: community message: Detected use of a Java socket that is not encrypted. As a result, the traffic could be read by an attacker intercepting the network traffic. Use an SSLSocket created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. severity: WARNING languages: - java pattern-either: - pattern: new ServerSocket(...) - pattern: new Socket(...) - id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits based on NIST recommendation. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::key-length::java.security cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key shortlink: https://sg.run/4x6x semgrep.dev: rule: r_id: 9200 rv_id: 1263019 rule_id: 0oU5P5 version_id: o5TbDLY url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key origin: community patterns: - pattern: | KeyPairGenerator $KEY = $G.getInstance("RSA"); ... $KEY.initialize($BITS); - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048 - id: java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CUSTOM_MESSAGE_DIGEST asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.2 Insecure Custom Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#custom-algorithms category: security technology: - java subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests shortlink: https://sg.run/PJ0p semgrep.dev: rule: r_id: 9201 rv_id: 1263004 rule_id: KxUbW4 version_id: YDTZewB url: https://semgrep.dev/playground/r/YDTZewB/java.lang.security.audit.crypto.ssl.avoid-implementing-custom-digests.avoid-implementing-custom-digests origin: community message: 'Cryptographic algorithms are notoriously difficult to get right. By implementing a custom message digest, you risk introducing security issues into your program. Use one of the many sound message digests already available to you: MessageDigest sha256Digest = MessageDigest.getInstance("SHA256");' severity: WARNING languages: - java pattern: |- class $CLASS extends MessageDigest { ... } - id: java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DEFAULT_HTTP_CLIENT asvs: section: V9 Communications Verification Requirements control_id: 9.1.3 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated shortlink: https://sg.run/J9Gj semgrep.dev: rule: r_id: 9202 rv_id: 1263005 rule_id: qNUj8b version_id: JdTzxnb url: https://semgrep.dev/playground/r/JdTzxnb/java.lang.security.audit.crypto.ssl.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated origin: community message: DefaultHttpClient is deprecated. Further, it does not support connections using TLS1.2, which makes using DefaultHttpClient a security hazard. Use HttpClientBuilder instead. severity: WARNING languages: - java pattern: new DefaultHttpClient(...); fix-regex: regex: DefaultHttpClient replacement: HttpClientBuilder - id: java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier message: Insecure HostnameVerifier implementation detected. This will accept any SSL certificate with any hostname, which creates the possibility for man-in-the-middle attacks. metadata: cwe: - 'CWE-295: Improper Certificate Validation' owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_HOSTNAME_VERIFIER asvs: section: V9 Communications Verification Requirements control_id: 9.2.1 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements version: '4' category: security technology: - java references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier shortlink: https://sg.run/5QoD semgrep.dev: rule: r_id: 9203 rv_id: 1263006 rule_id: lBU9n8 version_id: 5PTo17W url: https://semgrep.dev/playground/r/5PTo17W/java.lang.security.audit.crypto.ssl.insecure-hostname-verifier.insecure-hostname-verifier origin: community severity: WARNING languages: - java pattern-either: - pattern: | class $CLASS implements HostnameVerifier { ... public boolean verify(...) { return true; } } - pattern: |- new HostnameVerifier(...){ public boolean verify(...) { return true; } } - pattern: import org.apache.http.conn.ssl.NoopHostnameVerifier; - id: java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager metadata: cwe: - 'CWE-295: Improper Certificate Validation' owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_TRUST_MANAGER asvs: section: V9 Communications Verification Requirements control_id: 9.2.1 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements version: '4' references: - https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https category: security technology: - java subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager shortlink: https://sg.run/GePy semgrep.dev: rule: r_id: 9204 rv_id: 1263007 rule_id: YGUR9A version_id: GxTkel1 url: https://semgrep.dev/playground/r/GxTkel1/java.lang.security.audit.crypto.ssl.insecure-trust-manager.insecure-trust-manager origin: community message: Detected empty trust manager implementations. This is dangerous because it accepts any certificate, enabling man-in-the-middle attacks. Consider using a KeyStore and TrustManagerFactory instead. See https://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https for more information. severity: WARNING languages: - java patterns: - pattern-either: - pattern-inside: | class $CLASS implements X509TrustManager { ... } - pattern-inside: | new X509TrustManager() { ... } - pattern-inside: | class $CLASS implements X509ExtendedTrustManager { ... } - pattern-inside: | new X509ExtendedTrustManager() { ... } - pattern-not: public void checkClientTrusted(...) { $SOMETHING; } - pattern-not: public void checkServerTrusted(...) { $SOMETHING; } - pattern-either: - pattern: public void checkClientTrusted(...) {} - pattern: public void checkServerTrusted(...) {} - pattern: public X509Certificate[] getAcceptedIssuers(...) { return null; } - id: java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $VAL $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: org.hibernate.criterion.Restrictions.sqlRestriction($SQL,...) - pattern: org.hibernate.criterion.Restrictions.sqlRestriction(String.format(...),...) - patterns: - pattern: org.hibernate.criterion.Restrictions.sqlRestriction($X + $Y,...) - pattern-not: org.hibernate.criterion.Restrictions.sqlRestriction("..." + "...",...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $TYPE $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $SESSION.$METHOD($SQL,...) - pattern: | $SESSION.$METHOD(String.format(...),...); - pattern: | $SESSION.$METHOD($X + $Y,...); - pattern-either: - pattern-inside: | org.hibernate.Session $SESSION = ...; ... - pattern-inside: | $TYPE $FUNC(...,org.hibernate.Session $SESSION,...) { ... } - pattern-not: | $SESSION.$METHOD("..." + "...",...); - metavariable-regex: metavariable: $METHOD regex: ^(createQuery|createSQLQuery)$ message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION_HIBERNATE asvs: section: V5 Stored Cryptography Verification Requirements control_id: 5.3.5 Insecure Custom Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - hibernate owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli shortlink: https://sg.run/Roqg semgrep.dev: rule: r_id: 9205 rv_id: 1263035 rule_id: 6JUjPD version_id: e1Tyjbe url: https://semgrep.dev/playground/r/e1Tyjbe/java.lang.security.audit.sqli.hibernate-sqli.hibernate-sqli origin: community languages: - java severity: WARNING - id: java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $VAL $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $S.$METHOD($SQL,...) - pattern: | $S.$METHOD(String.format(...),...); - pattern: | $S.$METHOD($X + $Y,...); - pattern-either: - pattern-inside: | java.sql.Statement $S = ...; ... - pattern-inside: | $TYPE $FUNC(...,java.sql.Statement $S,...) { ... } - pattern-not: | $S.$METHOD("..." + "...",...); - metavariable-regex: metavariable: $METHOD regex: ^(executeQuery|execute|executeUpdate|executeLargeUpdate|addBatch|nativeSQL)$ metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - jdbc owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli shortlink: https://sg.run/AvkL semgrep.dev: rule: r_id: 9206 rv_id: 1263036 rule_id: oqUe8K version_id: vdT06oL url: https://semgrep.dev/playground/r/vdT06oL/java.lang.security.audit.sqli.jdbc-sqli.jdbc-sqli origin: community - id: java.lang.security.audit.sqli.jdo-sqli.jdo-sqli pattern-either: - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $TYPE $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $Q.$METHOD($SQL,...) - pattern: | $Q.$METHOD(String.format(...),...); - pattern: | $Q.$METHOD($X + $Y,...); - pattern-either: - pattern-inside: | javax.jdo.Query $Q = ...; ... - pattern-inside: | $TYPE $FUNC(...,javax.jdo.Query $Q,...) { ... } - pattern-not: | $Q.$METHOD("..." + "...",...); - metavariable-regex: metavariable: $METHOD regex: ^(setFilter|setGrouping)$ - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $VAL $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $PM.newQuery(...,$SQL,...) - pattern: | $PM.newQuery(...,String.format(...),...); - pattern: | $PM.newQuery(...,$X + $Y,...); - pattern-either: - pattern-inside: | javax.jdo.PersistenceManager $PM = ...; ... - pattern-inside: | $TYPE $FUNC(...,javax.jdo.PersistenceManager $PM,...) { ... } - pattern-not: | $PM.newQuery(...,"..." + "...",...); message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - java owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.jdo-sqli.jdo-sqli shortlink: https://sg.run/Bkwx semgrep.dev: rule: r_id: 9207 rv_id: 1263037 rule_id: zdUk7l version_id: d6Tyx77 url: https://semgrep.dev/playground/r/d6Tyx77/java.lang.security.audit.sqli.jdo-sqli.jdo-sqli origin: community - id: java.lang.security.audit.sqli.jpa-sqli.jpa-sqli message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $TYPE $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $EM.$METHOD($SQL,...) - pattern: | $EM.$METHOD(String.format(...),...); - pattern: | $EM.$METHOD($X + $Y,...); - pattern-either: - pattern-inside: | EntityManager $EM = ...; ... - pattern-inside: | $TYPE $FUNC(...,EntityManager $EM,...) { ... } - pattern-not: | $EM.$METHOD("..." + "...",...); - metavariable-regex: metavariable: $METHOD regex: ^(createQuery|createNativeQuery)$ metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - jpa owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.jpa-sqli.jpa-sqli shortlink: https://sg.run/DoOd semgrep.dev: rule: r_id: 9208 rv_id: 1263038 rule_id: pKUO7y version_id: ZRTKAxW url: https://semgrep.dev/playground/r/ZRTKAxW/java.lang.security.audit.sqli.jpa-sqli.jpa-sqli origin: community - id: java.lang.security.audit.sqli.turbine-sqli.turbine-sqli pattern-either: - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $VAL $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $PEER.executeQuery($SQL,...) - pattern: | $PEER.executeQuery(String.format(...),...) - pattern: | $PEER.executeQuery($X + $Y,...) - pattern-not: | $PEER.executeQuery("..." + "...",...) - metavariable-regex: metavariable: $PEER regex: (BasePeer|GroupPeer) - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $VAL $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $P.executeQuery($SQL,...) - pattern: | $P.executeQuery(String.format(...),...) - pattern: | $P.executeQuery($X + $Y,...) - pattern-either: - pattern-inside: | BasePeer $P = ...; ... - pattern-inside: | GroupPeer $P = ...; ... - pattern-inside: | $VAL $FUNC(...,GroupPeer $P,...) { ... } - pattern-inside: | $VAL $FUNC(...,BasePeer $P,...) { ... } - pattern-not: | $P.executeQuery("..." + "...",...) message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - turbine owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.turbine-sqli.turbine-sqli shortlink: https://sg.run/W8zL semgrep.dev: rule: r_id: 9209 rv_id: 1263040 rule_id: 2ZUbJ3 version_id: ExTExvY url: https://semgrep.dev/playground/r/ExTExvY/java.lang.security.audit.sqli.turbine-sqli.turbine-sqli origin: community - id: java.lang.security.audit.sqli.vertx-sqli.vertx-sqli message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | String $SQL = $X + $Y; ... - pattern-inside: | String $SQL = String.format(...); ... - pattern-inside: | $TYPE $FUNC(...,String $SQL,...) { ... } - pattern-not-inside: | String $SQL = "..." + "..."; ... - pattern: $SC.$METHOD($SQL,...) - pattern: | $SC.$METHOD(String.format(...),...); - pattern: | $SC.$METHOD($X + $Y,...); - pattern-either: - pattern-inside: | SqlClient $SC = ...; ... - pattern-inside: | SqlConnection $SC = ...; ... - pattern-inside: | $TYPE $FUNC(...,SqlClient $SC,...) { ... } - pattern-inside: | $TYPE $FUNC(...,SqlConnection $SC,...) { ... } - pattern-not: | $SC.$METHOD("..." + "...",...); - metavariable-regex: metavariable: $METHOD regex: ^(query|preparedQuery|prepare)$ metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - vertx owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.vertx-sqli.vertx-sqli shortlink: https://sg.run/0QKB semgrep.dev: rule: r_id: 9210 rv_id: 1263041 rule_id: X5U86z version_id: 7ZTE3Z5 url: https://semgrep.dev/playground/r/7ZTE3Z5/java.lang.security.audit.sqli.vertx-sqli.vertx-sqli origin: community - id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer message: Detected a request with potential user-input going into a OutputStream or Writer object. This bypasses any view or template environments, including HTML escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. Consider using a view technology such as JavaServer Faces (JSFs) which automatically escapes HTML views. severity: WARNING options: interfile: true metadata: likelihood: HIGH impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' cwe2021-top25: true cwe2022-top25: true owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html subcategory: - vuln technology: - java - servlets interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer shortlink: https://sg.run/KlRL semgrep.dev: rule: r_id: 9211 rv_id: 1263055 rule_id: j2Uv7B version_id: DkTRbXy url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer origin: community languages: - java mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ).$REQFUNC(...) - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" - metavariable-regex: metavariable: $REQFUNC regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) pattern-sinks: - patterns: - pattern-either: - pattern: | (HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...) - pattern: | (HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...) - pattern: | (java.io.PrintWriter $WRITER).$WRITE(...) - pattern: | (PrintWriter $WRITER).$WRITE(...) - pattern: | (javax.servlet.ServletOutputStream $WRITER).$WRITE(...) - pattern: | (ServletOutputStream $WRITER).$WRITE(...) - pattern: | (java.io.OutputStream $WRITER).$WRITE(...) - pattern: | (OutputStream $WRITER).$WRITE(...) pattern-sanitizers: - pattern-either: - pattern: Encode.forHtml(...) - pattern: (PolicyFactory $POLICY).sanitize(...) - pattern: (AntiSamy $AS).scan(...) - pattern: JSoup.clean(...) - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) - id: java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled message: Detected an element with disabled HTML escaping. If external data can reach this, this is a cross-site scripting (XSS) vulnerability. Ensure no external data can reach here, or remove 'escape=false' from this element. metadata: owasp: A07:2017 - Cross-Site Scripting (XSS) cwe: - 'CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences' references: - https://stackoverflow.com/a/7442668 category: security technology: - jsf subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled shortlink: https://sg.run/qxne semgrep.dev: rule: r_id: 9212 rv_id: 945709 rule_id: 10UKqE version_id: GxTP74Y url: https://semgrep.dev/playground/r/GxTP74Y/java.lang.security.audit.xss.jsf.autoescape-disabled.autoescape-disabled origin: community pattern-regex: .*escape.*?=.*?false.* paths: include: - '*.html' - '*.xhtml' languages: - regex severity: WARNING - id: java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization severity: WARNING languages: - java metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://mogwailabs.de/blog/2019/03/attacking-java-rmi-services-after-jep-290/ category: security technology: - rmi cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization shortlink: https://sg.run/oxg6 semgrep.dev: rule: r_id: 9216 rv_id: 1263071 rule_id: bwUwj4 version_id: yeTxpeP url: https://semgrep.dev/playground/r/yeTxpeP/java.rmi.security.server-dangerous-class-deserialization.server-dangerous-class-deserialization origin: community message: Using a non-primitive class with Java RMI may be an insecure deserialization vulnerability. Depending on the underlying implementation. This object could be manipulated by a malicious actor allowing them to execute code on your system. Instead, use an integer ID to look up your object, or consider alternative serialization schemes such as JSON. patterns: - pattern: | interface $INTERFACE extends Remote { $RETURNTYPE $METHOD($CLASS $PARAM) throws RemoteException; } - metavariable-regex: metavariable: $CLASS regex: (?!int|boolean|short|long|byte|char|float|double) - id: java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization severity: ERROR metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://frohoff.github.io/appseccali-marshalling-pickles/ - https://book.hacktricks.xyz/network-services-pentesting/1099-pentesting-java-rmi - https://youtu.be/t_aw1mDNhzI - https://github.com/qtc-de/remote-method-guesser - https://github.com/openjdk/jdk/blob/master/src/java.rmi/share/classes/sun/rmi/server/UnicastRef.java#L303C4-L331 category: security technology: - rmi cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization shortlink: https://sg.run/zvnl semgrep.dev: rule: r_id: 9217 rv_id: 1263072 rule_id: NbUkw5 version_id: rxTAKN2 url: https://semgrep.dev/playground/r/rxTAKN2/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization origin: community message: Using an arbitrary object ('$PARAMTYPE $PARAM') with Java RMI is an insecure deserialization vulnerability. This object can be manipulated by a malicious actor allowing them to execute code on your system. Instead, use an integer ID to look up your object, or consider alternative serialization schemes such as JSON. languages: - java patterns: - pattern: | interface $INTERFACE extends Remote { $RETURNTYPE $METHOD($PARAMTYPE $PARAM) throws RemoteException; } - metavariable-pattern: metavariable: $PARAMTYPE language: generic patterns: - pattern-not: String - pattern-not: java.lang.String - pattern-not: boolean - pattern-not: Boolean - pattern-not: java.lang.Boolean - pattern-not: byte - pattern-not: Byte - pattern-not: java.lang.Byte - pattern-not: char - pattern-not: Character - pattern-not: java.lang.Character - pattern-not: double - pattern-not: Double - pattern-not: java.lang.Double - pattern-not: float - pattern-not: Float - pattern-not: java.lang.Float - pattern-not: int - pattern-not: Integer - pattern-not: java.lang.Integer - pattern-not: long - pattern-not: Long - pattern-not: java.lang.Long - pattern-not: short - pattern-not: Short - pattern-not: java.lang.Short - id: java.servlets.security.cookie-issecure-false.cookie-issecure-false patterns: - pattern: $COOKIE = new Cookie($...ARGS); - pattern-not-inside: | $COOKIE = new Cookie(...); ... $COOKIE.setSecure(...); message: 'Default session middleware settings: `setSecure` not set to true. This ensures that the cookie is sent only over HTTPS to prevent cross-site scripting attacks.' fix: | $COOKIE = new Cookie($...ARGS); $COOKIE.setSecure(true); metadata: vulnerability: Insecure Transport owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://docs.oracle.com/javaee/6/api/javax/servlet/http/Cookie.html#setSecure(boolean) - https://owasp.org/www-community/controls/SecureCookieAttribute category: security technology: - java - cookie subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.servlets.security.cookie-issecure-false.cookie-issecure-false shortlink: https://sg.run/pxn0 semgrep.dev: rule: r_id: 9218 rv_id: 1263073 rule_id: kxUkn9 version_id: bZT53lB url: https://semgrep.dev/playground/r/bZT53lB/java.servlets.security.cookie-issecure-false.cookie-issecure-false origin: community languages: - java severity: WARNING - id: java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping patterns: - pattern-inside: | @RequestMapping(...) $RETURNTYPE $METHOD(...) { ... } - pattern-not-inside: | @RequestMapping(..., method = $X, ...) $RETURNTYPE $METHOD(...) { ... } - pattern: | RequestMapping message: Detected a method annotated with 'RequestMapping' that does not specify the HTTP method. CSRF protections are not enabled for GET, HEAD, TRACE, or OPTIONS, and by default all HTTP methods are allowed when the HTTP method is not explicitly specified. This means that a method that performs state changes could be vulnerable to CSRF attacks. To mitigate, add the 'method' field and specify the HTTP method (such as 'RequestMethod.POST'). severity: WARNING metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING references: - https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING category: security technology: - spring cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping shortlink: https://sg.run/2xlq semgrep.dev: rule: r_id: 9219 rv_id: 1263089 rule_id: wdUJ7q version_id: QkTGq2l url: https://semgrep.dev/playground/r/QkTGq2l/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping origin: community languages: - java - id: java.spring.security.audit.spel-injection.spel-injection message: A Spring expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPEL_INJECTION category: security technology: - spring references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.spring.security.audit.spel-injection.spel-injection shortlink: https://sg.run/XBp4 semgrep.dev: rule: r_id: 9220 rv_id: 1263075 rule_id: x8Un7b version_id: kbTzG5Y url: https://semgrep.dev/playground/r/kbTzG5Y/java.spring.security.audit.spel-injection.spel-injection origin: community severity: WARNING languages: - java patterns: - pattern-either: - pattern-inside: | class $CLASS { ... ExpressionParser $PARSER; ... } - pattern-inside: | class $CLASS { ... ExpressionParser $PARSER = ...; ... } - pattern-inside: | $X $METHOD(...) { ... ExpressionParser $PARSER = ...; ... } - pattern-inside: | class $CLASS { ... SpelExpressionParser $PARSER; ... } - pattern-inside: | class $CLASS { ... SpelExpressionParser $PARSER = ...; ... } - pattern-inside: | $X $METHOD(...) { ... SpelExpressionParser $PARSER = ...; ... } - pattern-inside: | class $CLASS { ... TemplateAwareExpressionParser $PARSER; ... } - pattern-inside: | class $CLASS { ... TemplateAwareExpressionParser $PARSER = ...; ... } - pattern-inside: | $X $METHOD(...) { ... TemplateAwareExpressionParser $PARSER = ...; ... } - pattern: | $X $METHOD(...) { ... $PARSER.parseExpression(...); ... } - pattern-not: | $X $METHOD(...) { ... $PARSER.parseExpression("..."); ... } - pattern-not: | $X $METHOD(...) { ... String $S = "..."; ... $PARSER.parseExpression($S); ... } - id: java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled message: CSRF protection is disabled for this configuration. This is a security risk. metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_PROTECTION_DISABLED asvs: section: V4 Access Control control_id: 4.2.2 CSRF control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control version: '4' category: security technology: - spring references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled shortlink: https://sg.run/jRnl semgrep.dev: rule: r_id: 9221 rv_id: 1263080 rule_id: OrU3gK version_id: vdT06dL url: https://semgrep.dev/playground/r/vdT06dL/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled origin: community severity: WARNING languages: - java pattern: $OBJ.csrf(...).disable(...) - id: java.spring.security.audit.spring-sqli.spring-sqli mode: taint pattern-sources: - patterns: - pattern: $ARG - pattern-inside: | public $T $M (..., String $ARG,...){...} pattern-sanitizers: - not_conflicting: true pattern-either: - patterns: - focus-metavariable: $A - pattern-inside: | new $TYPE(...,$A,...); pattern-sinks: - patterns: - pattern-either: - patterns: - focus-metavariable: $A - pattern: | new PreparedStatementCreatorFactory($A,...); - patterns: - focus-metavariable: $A - pattern: | (JdbcTemplate $T).$M($A,...) - patterns: - pattern: (String $A) - pattern-inside: | (JdbcTemplate $T).batchUpdate(...) - patterns: - focus-metavariable: $A - pattern: | NamedParameterBatchUpdateUtils.$M($A,...) - patterns: - focus-metavariable: $A - pattern: | BatchUpdateUtils.$M($A,...) message: Detected a string argument from a public method contract in a raw SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - spring owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli shortlink: https://sg.run/1Z3x semgrep.dev: rule: r_id: 9222 rv_id: 1263082 rule_id: eqU8N2 version_id: ZRTKAWW url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli origin: community - id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect message: Application redirects a user to a destination URL specified by a user supplied parameter that is not validated. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT category: security technology: - spring references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect shortlink: https://sg.run/9oXz semgrep.dev: rule: r_id: 9223 rv_id: 1263083 rule_id: v8Un7w version_id: nWT2Lk0 url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect origin: community severity: WARNING languages: - java pattern-either: - pattern: | $X $METHOD(...,String $URL,...) { return "redirect:" + $URL; } - pattern: | $X $METHOD(...,String $URL,...) { ... String $REDIR = "redirect:" + $URL; ... return $REDIR; ... } - pattern: | $X $METHOD(...,String $URL,...) { ... new ModelAndView("redirect:" + $URL); ... } - pattern: |- $X $METHOD(...,String $URL,...) { ... String $REDIR = "redirect:" + $URL; ... new ModelAndView($REDIR); ... } - id: javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods message: Use of angular.element can lead to XSS if user-input is treated as part of the HTML element within `$SINK`. It is recommended to contextually output encode user-input, before inserting into `$SINK`. If the HTML needs to be preserved it is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. metadata: confidence: LOW references: - https://docs.angularjs.org/api/ng/function/angular.element - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' technology: - angularjs owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods shortlink: https://sg.run/ydnO semgrep.dev: rule: r_id: 9224 rv_id: 1263090 rule_id: d8Ujdo version_id: 3ZT4Xbz url: https://semgrep.dev/playground/r/3ZT4Xbz/javascript.angular.security.detect-angular-element-methods.detect-angular-element-methods origin: community languages: - javascript - typescript severity: INFO mode: taint pattern-sources: - patterns: - pattern-either: - patterns: - pattern-inside: | function(..., $SCOPE, ...) { ... } - focus-metavariable: $SCOPE - metavariable-regex: metavariable: $SCOPE regex: ^\$scope$ - pattern: $rootScope - pattern: $injector.get('$rootScope') - pattern: $injector.get('$scope') pattern-sinks: - patterns: - pattern-either: - pattern-inside: | angular.element(...). ... .$SINK($QUERY) - pattern-inside: | $ANGULAR = angular.element(...) ... $ANGULAR. ... .$SINK($QUERY) - metavariable-regex: metavariable: $SINK regex: ^(after|append|html|prepend|replaceWith|wrap)$ - focus-metavariable: $QUERY pattern-sanitizers: - patterns: - pattern-either: - pattern: $sce.getTrustedHtml(...) - pattern: $sanitize(...) - pattern: DOMPurify.sanitize(...) - id: javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading message: $sceDelegateProvider allowlisting can introduce security issues if wildcards are used. metadata: references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsJs - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' technology: - angular owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading shortlink: https://sg.run/b7kd semgrep.dev: rule: r_id: 9226 rv_id: 1263093 rule_id: nJUzgX version_id: JdTzxKb url: https://semgrep.dev/playground/r/JdTzxKb/javascript.angular.security.detect-angular-resource-loading.detect-angular-resource-loading origin: community languages: - javascript - typescript severity: WARNING pattern-either: - pattern: | $sceDelegateProvider.resourceUrlWhitelist([...,'**',...]); - patterns: - pattern: | $sceDelegateProvider.resourceUrlWhitelist([...,$DOM,...]); - metavariable-regex: metavariable: $DOM regex: ^'.*\*\*.+'$ - id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) in an AngularJS application could provide additional attack surface for XSS vulnerabilities. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://docs.angularjs.org/api/ng/service/$sce - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled shortlink: https://sg.run/N4DG semgrep.dev: rule: r_id: 9227 rv_id: 1263094 rule_id: EwU20Z version_id: 5PTo1EW url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled origin: community languages: - javascript - typescript severity: ERROR pattern: | $sceProvider.enabled(false); - id: javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method message: The use of $sce.trustAsCss can be dangerous if unsanitized user input flows through this API. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsCss - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method shortlink: https://sg.run/kXgo semgrep.dev: rule: r_id: 9228 rv_id: 1263095 rule_id: 7KUQ4k version_id: GxTkeB1 url: https://semgrep.dev/playground/r/GxTkeB1/javascript.angular.security.detect-angular-trust-as-css.detect-angular-trust-as-css-method origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $SOURCE = $scope.$INPUT; $sce.trustAsCss($SOURCE); - pattern: | $sce.trustAsCss($scope.$INPUT); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method message: The use of $sce.trustAsHtml can be dangerous if unsanitized user input flows through this API. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsHtml - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method shortlink: https://sg.run/wenn semgrep.dev: rule: r_id: 9229 rv_id: 1263096 rule_id: L1Uy88 version_id: RGT0L9j url: https://semgrep.dev/playground/r/RGT0L9j/javascript.angular.security.detect-angular-trust-as-html-method.detect-angular-trust-as-html-method origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $SOURCE = $scope.$INPUT; $sce.trustAsHtml($SOURCE); - pattern: | $sce.trustAsHtml($scope.$INPUT); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method message: The use of $sce.trustAsJs can be dangerous if unsanitized user input flows through this API. metadata: owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsJs - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' category: security technology: - angular cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method shortlink: https://sg.run/x1nA semgrep.dev: rule: r_id: 9230 rv_id: 1263097 rule_id: 8GUj8k version_id: A8Tgdpo url: https://semgrep.dev/playground/r/A8Tgdpo/javascript.angular.security.detect-angular-trust-as-js-method.detect-angular-trust-as-js-method origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $SOURCE = $scope.$INPUT; $sce.trustAsJs($SOURCE); - pattern: | $sce.trustAsJs($scope.$INPUT); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method message: The use of $sce.trustAs can be dangerous if unsanitized user input flows through this API. metadata: references: - https://docs.angularjs.org/api/ng/service/$sce - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' technology: - angular owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method shortlink: https://sg.run/OPW2 semgrep.dev: rule: r_id: 9231 rv_id: 1263098 rule_id: gxU1QX version_id: BjTkZv0 url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | app.controller(..., function($scope,$sce) { ... }); - pattern: $scope.$X pattern-sinks: - pattern: $sce.trustAs(...) - pattern: $sce.trustAsHtml(...) - id: javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method message: The use of $sce.trustAsResourceUrl can be dangerous if unsanitized user input flows through this API. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsResourceUrl - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method shortlink: https://sg.run/eLOd semgrep.dev: rule: r_id: 9232 rv_id: 1263099 rule_id: QrUzeq version_id: DkTRb7y url: https://semgrep.dev/playground/r/DkTRb7y/javascript.angular.security.detect-angular-trust-as-resourceurl-method.detect-angular-trust-as-resourceurl-method origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $SOURCE = $scope.$INPUT; $sce.trustAsResourceUrl($SOURCE); - pattern: | $sce.trustAsResourceUrl($scope.$INPUT); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method message: The use of $sce.trustAsUrl can be dangerous if unsanitized user input flows through this API. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsUrl - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method shortlink: https://sg.run/vznl semgrep.dev: rule: r_id: 9233 rv_id: 1263100 rule_id: 3qUP01 version_id: WrTqKJK url: https://semgrep.dev/playground/r/WrTqKJK/javascript.angular.security.detect-angular-trust-as-url-method.detect-angular-trust-as-url-method origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $SOURCE = $scope.$INPUT; $sce.trustAsUrl($SOURCE); - pattern: | $sce.trustAsUrl($scope.$INPUT); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method message: The use of $translateProvider.translations method can be dangerous if user input is provided to this API. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://docs.angularjs.org/api/ng/service/$sce#trustAsUrl - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular - typescript owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method shortlink: https://sg.run/ZvXp semgrep.dev: rule: r_id: 9235 rv_id: 1263101 rule_id: PeUZPg version_id: 0bTKzqX url: https://semgrep.dev/playground/r/0bTKzqX/javascript.angular.security.detect-third-party-angular-translate.detect-angular-translateprovider-translations-method origin: community languages: - javascript severity: WARNING patterns: - pattern: | $translateProvider.translations(...,$SOURCE); - pattern-inside: | app.controller(..., function($scope,$sce){ ... }); - id: javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution message: Potential arbitrary code execution, whatever is provided to `toFastProperties` is sent straight to eval() metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - bluebird references: - http://bluebirdjs.com/docs/getting-started.html cwe2022-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution shortlink: https://sg.run/ndnZ semgrep.dev: rule: r_id: 9236 rv_id: 1263115 rule_id: JDUy9J version_id: K3TKkQ7 url: https://semgrep.dev/playground/r/K3TKkQ7/javascript.bluebird.security.audit.tofastproperties-code-execution.tofastproperties-code-execution origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: function ... (..., $ARG,...) {...} - focus-metavariable: $ARG pattern-sinks: - patterns: - pattern-either: - pattern: $UTIL.toFastProperties($SINK,...) - pattern: toFastProperties($SINK,...) - pattern-either: - pattern-inside: | $BB = require('bluebird'); ... - pattern-inside: | import 'bluebird'; ... - focus-metavariable: $SINK - id: javascript.browser.security.eval-detected.eval-detected message: Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.2.4 Dynamic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing version: '4' category: security technology: - browser subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.browser.security.eval-detected.eval-detected shortlink: https://sg.run/7ope semgrep.dev: rule: r_id: 9238 rv_id: 1263117 rule_id: GdU7dw version_id: l4TJR2y url: https://semgrep.dev/playground/r/l4TJR2y/javascript.browser.security.eval-detected.eval-detected origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-not: eval("...") - pattern: eval(...) - id: javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation message: No validation of origin is done by the addEventListener API. It may be possible to exploit this flaw to perform Cross Origin attacks such as Cross-Site Scripting(XSS). metadata: owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' category: security technology: - browser subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation shortlink: https://sg.run/gL9x semgrep.dev: rule: r_id: 9241 rv_id: 1263120 rule_id: BYUN0X version_id: o5TbDRl url: https://semgrep.dev/playground/r/o5TbDRl/javascript.browser.security.insufficient-postmessage-origin-validation.insufficient-postmessage-origin-validation origin: community languages: - javascript - typescript severity: WARNING pattern-either: - patterns: - pattern: | window.addEventListener('message', $FUNC, ...) - metavariable-pattern: patterns: - pattern: | function($OBJ) { ... } - pattern-not: | function($OBJ) { ... if (<... $OBJ.origin ...>) { ... } ... } metavariable: $FUNC - patterns: - pattern-either: - pattern-inside: | function $FNAME($OBJ) { $CONTEXT } ... - pattern-inside: | $FNAME = (...) => { $CONTEXT } ... - pattern: | window.addEventListener('message', $FNAME,...) - metavariable-pattern: patterns: - pattern-not: | ... if (<... $OBJ.origin ...>) { ... } ... metavariable: $CONTEXT - id: javascript.browser.security.open-redirect.js-open-redirect message: The application accepts potentially user-controlled input `$PROP` which can control the location of the current window context. This can lead two types of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript URIs. It is recommended to validate user-controllable input before allowing it to control the redirection. options: interfile: true metadata: interfile: true cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.1 Insecue Redirect control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation version: '4' category: security confidence: HIGH references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html technology: - browser subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect shortlink: https://sg.run/3xRe semgrep.dev: rule: r_id: 9243 rv_id: 1263122 rule_id: WAUopl version_id: pZT03x0 url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | new URLSearchParams($WINDOW. ... .location.search).get('...') - pattern: | new URLSearchParams(location.search).get('...') - pattern: | new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') - pattern: | new URLSearchParams(location.hash.substring(1)).get('...') - patterns: - pattern-either: - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.search) ... - pattern-inside: | $PROPS = new URLSearchParams(location.search) ... - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) ... - pattern-inside: | $PROPS = new URLSearchParams(location.hash.substring(1)) ... - pattern: $PROPS.get('...') - patterns: - pattern-either: - pattern-inside: | $PROPS = new URL($WINDOW. ... .location.href) ... - pattern-inside: | $PROPS = new URL(location.href) ... - pattern: $PROPS.searchParams.get('...') - patterns: - pattern-either: - pattern: | new URL($WINDOW. ... .location.href).searchParams.get('...') - pattern: | new URL(location.href).searchParams.get('...') pattern-sinks: - patterns: - pattern-either: - pattern: location.href = $SINK - pattern: $THIS. ... .location.href = $SINK - pattern: location.replace($SINK) - pattern: $THIS. ... .location.replace($SINK) - pattern: location = $SINK - pattern: $WINDOW. ... .location = $SINK - focus-metavariable: $SINK - metavariable-pattern: patterns: - pattern-not: | "..." + $VALUE - pattern-not: | `...${$VALUE}` metavariable: $SINK - id: javascript.browser.security.raw-html-concat.raw-html-concat message: User controlled data in a HTML string may result in XSS metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/xss/ category: security technology: - browser cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat shortlink: https://sg.run/4xAx semgrep.dev: rule: r_id: 9244 rv_id: 1263123 rule_id: 0oU5b5 version_id: 2KTv2wp url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: location.href - pattern: location.hash - pattern: location.search - pattern: $WINDOW. ... .location.href - pattern: $WINDOW. ... .location.hash - pattern: $WINDOW. ... .location.search pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $STRING + $EXPR - pattern-not: $STRING + "..." - metavariable-pattern: patterns: - pattern: <$TAG ... - pattern-not: <$TAG ...>...... metavariable: $STRING language: generic - patterns: - pattern: $EXPR + $STRING - pattern-not: '"..." + $STRING' - metavariable-pattern: patterns: - pattern: '... {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $XML = require('node-expat') ... - pattern-inside: | import $XML from 'node-expat' ... - pattern-inside: | import * as $XML from 'node-expat' ... - pattern-either: - pattern-inside: | $PARSER = new $XML.Parser(...); ... - pattern-either: - pattern: $PARSER.parse($QUERY) - pattern: $PARSER.write($QUERY) - focus-metavariable: $QUERY - id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: interfile: true cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - express - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret shortlink: https://sg.run/Do1d semgrep.dev: rule: r_id: 9252 rv_id: 1263166 rule_id: pKUOjy version_id: pZT03Q0 url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern-inside: | $JWT = require('express-jwt'); ... - pattern-inside: | import $JWT from 'express-jwt'; ... - pattern-inside: | import * as $JWT from 'express-jwt'; ... - pattern-inside: | import { ..., $JWT, ... } from 'express-jwt'; ... - pattern-either: - pattern: | $JWT({...,secret: "$Y",...},...) - pattern: | $OPTS = "$Y"; ... $JWT({...,secret: $OPTS},...); - focus-metavariable: $Y - id: javascript.express.security.express-phantom-injection.express-phantom-injection message: If unverified user data can reach the `phantom` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://phantomjs.org/page-automation.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection shortlink: https://sg.run/W8BL semgrep.dev: rule: r_id: 9253 rv_id: 1263167 rule_id: 2ZUbx3 version_id: 2KTv26p url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('phantom'); ... - pattern-inside: | import 'phantom'; ... - pattern-either: - pattern: $PAGE.open($SINK,...) - pattern: $PAGE.setContent($SINK,...) - pattern: $PAGE.openUrl($SINK,...) - pattern: $PAGE.evaluateJavaScript($SINK,...) - pattern: $PAGE.property("content",$SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection message: If unverified user data can reach the `puppeteer` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://pptr.dev/api/puppeteer.page cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection shortlink: https://sg.run/0QJB semgrep.dev: rule: r_id: 9254 rv_id: 1263168 rule_id: X5U8Nz version_id: X0TzyJY url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('puppeteer'); ... - pattern-inside: | import 'puppeteer'; ... - pattern-either: - pattern: $PAGE.goto($SINK,...) - pattern: $PAGE.setContent($SINK,...) - pattern: $PAGE.evaluate($SINK,...) - pattern: $PAGE.evaluate($CODE,$SINK,...) - pattern: $PAGE.evaluateHandle($SINK,...) - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) - pattern: $PAGE.evaluateOnNewDocument($SINK,...) - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection message: Make sure that unverified user data can not reach `sandbox`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection shortlink: https://sg.run/KlwL semgrep.dev: rule: r_id: 9255 rv_id: 1263169 rule_id: j2UvXB version_id: jQTn59D url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | $SANDBOX = require('sandbox'); ... - pattern-either: - patterns: - pattern-inside: | $S = new $SANDBOX(...); ... - pattern: | $S.run(...) - pattern: | new $SANDBOX($OPTS).run(...) - pattern: new $SANDBOX().run(...) - id: javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection message: If unverified user data can reach the `phantom` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://www.npmjs.com/package/wkhtmltopdf cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection shortlink: https://sg.run/pxe0 semgrep.dev: rule: r_id: 9262 rv_id: 1263172 rule_id: kxUkl9 version_id: yeTxpdd url: https://semgrep.dev/playground/r/yeTxpdd/javascript.express.security.express-wkhtml-injection.express-wkhtmltoimage-injection origin: community severity: ERROR languages: - javascript - typescript mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern: $WK.generate($SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection message: If unverified user data can reach the `wkhtmltopdf` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://www.npmjs.com/package/wkhtmltopdf cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection shortlink: https://sg.run/2xGq semgrep.dev: rule: r_id: 9263 rv_id: 1263173 rule_id: wdUJxq version_id: rxTAK8b url: https://semgrep.dev/playground/r/rxTAK8b/javascript.express.security.express-wkhtml-injection.express-wkhtmltopdf-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | $WK = require('wkhtmltopdf'); ... - pattern: $WK($SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or Internal Entity (XXE) Processing vulnerabilities metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' category: security technology: - express references: - https://www.npmjs.com/package/xml2json cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe shortlink: https://sg.run/XBD4 semgrep.dev: rule: r_id: 9264 rv_id: 1263174 rule_id: x8Uneb version_id: bZT534J url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('xml2json'); ... - pattern-inside: | import 'xml2json'; ... - pattern: $EXPAT.toJson($SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.require-request.require-request message: If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. options: interfile: true metadata: interfile: true owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/javascript.express.security.require-request.require-request shortlink: https://sg.run/jRbl semgrep.dev: rule: r_id: 9265 rv_id: 1263177 rule_id: OrU3WK version_id: w8TRo0d url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern: require($SINK) - focus-metavariable: $SINK - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name message: "Don\u2019t use the default session cookie name Using the default session cookie name can open your app to attacks. The security issue posed is similar to X-Powered-By: a potential attacker can use it to fingerprint the server and target attacks accordingly." severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name shortlink: https://sg.run/1Z5x semgrep.dev: rule: r_id: 9266 rv_id: 1263130 rule_id: eqU8k2 version_id: bZT536J url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {name:...} ...>,...) - pattern-not-inside: | $OPTS = <... {name:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.name = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure message: 'Default session middleware settings: `secure` not set. It ensures the browser only sends the cookie over HTTPS.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure shortlink: https://sg.run/9oKz semgrep.dev: rule: r_id: 9267 rv_id: 1263131 rule_id: v8Unzw version_id: NdTzyrv url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{secure:true}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {secure:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {secure:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.secure = true; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.secure = true; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly message: 'Default session middleware settings: `httpOnly` not set. It ensures the cookie is sent only over HTTP(S), not client JavaScript, helping to protect against cross-site scripting attacks.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly shortlink: https://sg.run/ydBO semgrep.dev: rule: r_id: 9268 rv_id: 1263132 rule_id: d8UjGo version_id: kbTzGev url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{httpOnly:true}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {httpOnly:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {httpOnly:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.httpOnly = true; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.httpOnly = true; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain message: 'Default session middleware settings: `domain` not set. It indicates the domain of the cookie; use it to compare against the domain of the server in which the URL is being requested. If they match, then check the path attribute next.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain shortlink: https://sg.run/rd41 semgrep.dev: rule: r_id: 9269 rv_id: 1263133 rule_id: ZqU5Pn version_id: w8TRoyd url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{domain:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {domain:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {domain:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.domain = ...; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.domain = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path message: 'Default session middleware settings: `path` not set. It indicates the path of the cookie; use it to compare against the request path. If this and domain match, then send the cookie in the request.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path shortlink: https://sg.run/b7pd semgrep.dev: rule: r_id: 9270 rv_id: 1263134 rule_id: nJUz4X version_id: xyTjzQD url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{path:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {path:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {path:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.path = ...; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.path = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires message: 'Default session middleware settings: `expires` not set. Use it to set expiration date for persistent cookies.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires shortlink: https://sg.run/N4eG semgrep.dev: rule: r_id: 9271 rv_id: 1263135 rule_id: EwU2DZ version_id: O9TpxRq url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{expires:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {expires:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {expires:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.expires = ...; ... $SESSION($OPTS,...); - pattern-not-inside: |- $OPTS = ...; ... $OPTS.cookie.expires = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked message: No token revoking configured for `express-jwt`. A leaked token could still be used and unable to be revoked. Consider using function as the `isRevoked` option. metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.3 Insecure Stateless Session Tokens control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked shortlink: https://sg.run/kXNo semgrep.dev: rule: r_id: 9272 rv_id: 1263137 rule_id: 7KUQ9k version_id: vdT06Bg url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | $JWT = require('express-jwt'); ... - pattern: $JWT(...) - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) - pattern-not-inside: |- $OPTS = <... {isRevoked:...} ...>; ... $JWT($OPTS,...); - id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal message: Possible writing outside of the destination, make sure that the target path is nested in the intended destination metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' category: security references: - https://owasp.org/www-community/attacks/Path_Traversal technology: - express - node.js cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal shortlink: https://sg.run/weRn semgrep.dev: rule: r_id: 9273 rv_id: 1263141 rule_id: L1Uyb8 version_id: ExTExX0 url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern-inside: | $PATH = require('path'); ... - pattern-inside: | import $PATH from 'path'; ... - pattern-either: - pattern: $PATH.join(...,$SINK,...) - pattern: $PATH.resolve(...,$SINK,...) - patterns: - focus-metavariable: $SINK - pattern-inside: | import 'path'; ... - pattern-either: - pattern: path.join(...,$SINK,...) - pattern: path.resolve(...,$SINK,...) pattern-sanitizers: - pattern: $Y.replace(...) - pattern: $Y.indexOf(...) - pattern: | function ... (...) { ... <... $Y.indexOf(...) ...> ... } - patterns: - pattern: $FUNC(...) - metavariable-regex: metavariable: $FUNC regex: sanitize - id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event message: Xml Parser is used inside Request Event. Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or Internal Entity (XXE) Processing vulnerabilities metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' category: security technology: - express references: - https://www.npmjs.com/package/xml2json cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event shortlink: https://sg.run/x1AA semgrep.dev: rule: r_id: 9274 rv_id: 1263146 rule_id: 8GUjkk version_id: QkTGqgo url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('xml2json'); ... - pattern-inside: | import 'xml2json'; ... - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) - focus-metavariable: $INPUT - id: javascript.express.security.audit.res-render-injection.res-render-injection message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to the loading of other HTML/templating pages that they may not be authorized to render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index` to access other HTML pages on the file system. Where possible, do not allow users to define what should be loaded in $RES.render or use an allow list for the existing application. options: interfile: true metadata: interfile: true owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' category: security technology: - express references: - http://expressjs.com/en/4x/api.html#res.render subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection shortlink: https://sg.run/eLjd semgrep.dev: rule: r_id: 9276 rv_id: 1263149 rule_id: QrUzrq version_id: PkTR3OY url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.render($SINK, ...) - focus-metavariable: $SINK - id: javascript.express.security.audit.xss.direct-response-write.direct-response-write message: Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML. options: interfile: true metadata: interfile: true references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM vulnerability_class: - Cross-Site-Scripting (XSS) license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write shortlink: https://sg.run/vzGl semgrep.dev: rule: r_id: 9277 rv_id: 1263150 rule_id: 3qUPA1 version_id: JdTzxeg url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options) - pattern-not-inside: | function ... ($REQ, $RES) { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | $APP.$METHOD(..., function $FUNC($REQ, $RES) { ... $RES.$SET('Content-Type', '$TYPE') }) - pattern-not-inside: | function ... ($REQ, $RES, $NEXT) { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | function ... ($REQ, $RES) { ... $RES.set('$TYPE') } - pattern-not-inside: | $APP.$METHOD(..., function $FUNC($REQ, $RES) { ... $RES.set('$TYPE') }) - pattern-not-inside: | function ... ($REQ, $RES, $NEXT) { ... $RES.set('$TYPE') } - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - pattern-not-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | ({ $REQ }: Request,$RES: Response) => { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => { ... $RES.set('$TYPE') } - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: body pattern-sinks: - patterns: - pattern-inside: function ... (..., $RES,...) {...} - pattern-either: - pattern: $RES.write($ARG) - pattern: $RES.send($ARG) - pattern-not: $RES. ... .set('...'). ... .send($ARG) - pattern-not: $RES. ... .type('...'). ... .send($ARG) - pattern-not-inside: $RES.$METHOD({ ... }) - focus-metavariable: $ARG pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'express-xss-sanitizer'; ... - pattern-inside: | import * as $S from "express-xss-sanitizer"; ... - pattern-inside: | const { ..., $S, ... } = require('express-xss-sanitizer'); ... - pattern-inside: | var { ..., $S, ... } = require('express-xss-sanitizer'); ... - pattern-inside: | let { ...,$S,... } = require('express-xss-sanitizer'); ... - pattern-inside: | $S = require("express-xss-sanitizer") ... - pattern: $S(...) - patterns: - pattern: $RES. ... .type('$F'). ... .send(...) - metavariable-regex: metavariable: $F regex: (?!.*text/html) - patterns: - pattern-inside: | $X = [...]; ... - pattern: | if(<... !$X.includes($SOURCE)...>) { ... return ... } ... - pattern: $SOURCE - id: javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape message: Detected an explicit unescape in an EJS template, using '<%- ... %>' If external data can reach these locations, your application is exposed to a cross-site scripting (XSS) vulnerability. Use '<%= ... %>' to escape this data. If you need escaping, ensure no external data can reach this location. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - http://www.managerjs.com/blog/2015/05/will-ejs-escape-save-me-from-xss-sorta/ category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape shortlink: https://sg.run/dKXQ semgrep.dev: rule: r_id: 9278 rv_id: 1263151 rule_id: 4bUkPO version_id: 5PTo13n url: https://semgrep.dev/playground/r/5PTo13n/javascript.express.security.audit.xss.ejs.explicit-unescape.template-explicit-unescape origin: community languages: - regex severity: WARNING paths: include: - '*.ejs' - '*.html' pattern-regex: <%-((?!include).)*?%> fix-regex: regex: <%-(.*?)%> replacement: <%=\1%> - id: javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src message: Detected a template variable used as the 'src' in a script tag. Although template variables are HTML escaped, HTML escaping does not always prevent malicious URLs from being injected and could results in a cross-site scripting (XSS) vulnerability. Prefer not to dynamically generate the 'src' attribute and use static URLs instead. If you must do this, carefully check URLs against an allowlist and be sure to URL-encode the result. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://www.veracode.com/blog/secure-development/nodejs-template-engines-why-default-encoders-are-not-enough - https://github.com/ESAPI/owasp-esapi-js category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src shortlink: https://sg.run/ndxZ semgrep.dev: rule: r_id: 9280 rv_id: 1263153 rule_id: JDUyrJ version_id: RGT0LwD url: https://semgrep.dev/playground/r/RGT0LwD/javascript.express.security.audit.xss.ejs.var-in-script-src.var-in-script-src origin: community languages: - generic severity: WARNING patterns: - pattern-inside: - pattern-not-inside: - pattern-not: <%= j ... > - pattern-not: <%= escape_javascript ... > - pattern: <%= ... > - id: terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push patterns: - pattern: resource - pattern-not-inside: | resource "aws_ecr_repository" "..." { ... image_scanning_configuration { ... scan_on_push=true ... } ... } - pattern-inside: | resource "aws_ecr_repository" "..." { ... } languages: - hcl message: The ECR Repository isn't configured to scan images on push severity: WARNING metadata: cwe: - 'CWE-1104: Use of Unmaintained Third Party Components' category: security technology: - terraform - aws owasp: - A06:2021 - Vulnerable and Outdated Components - A03:2025 - Software Supply Chain Failures references: - https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push shortlink: https://sg.run/R8eE semgrep.dev: rule: r_id: 9749 rv_id: 1263885 rule_id: 0oUELR version_id: xyTjzzO url: https://semgrep.dev/playground/r/xyTjzzO/terraform.lang.security.ecr-image-scan-on-push.ecr-image-scan-on-push origin: community - id: terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled patterns: - pattern: | resource - pattern-inside: | resource "aws_eks_cluster" "..." {...} - pattern-not-inside: | resource "aws_eks_cluster" "..."{ ... vpc_config{ ... endpoint_public_access = false ... } ... } languages: - hcl message: The vpc_config resource inside the eks cluster has not explicitly disabled public endpoint access severity: WARNING metadata: category: security cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled shortlink: https://sg.run/Albg semgrep.dev: rule: r_id: 9750 rv_id: 1263887 rule_id: KxU4v6 version_id: e1TyjjB url: https://semgrep.dev/playground/r/e1TyjjB/terraform.lang.security.eks-public-endpoint-enabled.eks-public-endpoint-enabled origin: community - id: terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest patterns: - pattern: | resource - pattern-not-inside: | resource "aws_elasticsearch_domain" "..."{ ... encrypt_at_rest{ ... enabled = true ... } ... } - pattern-inside: | resource "aws_elasticsearch_domain" "..." {...} languages: - hcl message: Encryption at rest is not enabled for the elastic search domain resource severity: WARNING metadata: category: security cwe: - 'CWE-311: Missing Encryption of Sensitive Data' technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest shortlink: https://sg.run/B4Yb semgrep.dev: rule: r_id: 9751 rv_id: 1263888 rule_id: qNUo2d version_id: vdT066y url: https://semgrep.dev/playground/r/vdT066y/terraform.lang.security.elastic-search-encryption-at-rest.elastic-search-encryption-at-rest origin: community - id: terraform.lang.security.s3-cors-all-origins.all-origins-allowed patterns: - pattern-inside: cors_rule { ... } - pattern: allowed_origins = ["*"] languages: - hcl severity: WARNING message: CORS rule on bucket permits any origin metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#using-cors cwe: - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' category: security technology: - terraform - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/terraform.lang.security.s3-cors-all-origins.all-origins-allowed shortlink: https://sg.run/DJb2 semgrep.dev: rule: r_id: 9752 rv_id: 1263898 rule_id: lBUd4g version_id: 3ZT4XXJ url: https://semgrep.dev/playground/r/3ZT4XXJ/terraform.lang.security.s3-cors-all-origins.all-origins-allowed origin: community - id: terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket patterns: - pattern-either: - pattern: acl = "public-read" - pattern: acl = "authenticated-read" - pattern-not-inside: | resource "aws_s3_bucket" "..." { ... website { ... } ... } languages: - hcl severity: WARNING message: S3 bucket with public read access detected. metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket shortlink: https://sg.run/WgAy semgrep.dev: rule: r_id: 9753 rv_id: 1263899 rule_id: YGUrp5 version_id: 44TEjjv url: https://semgrep.dev/playground/r/44TEjjv/terraform.lang.security.s3-public-read-bucket.s3-public-read-bucket origin: community - id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket pattern: acl = "public-read-write" languages: - hcl severity: ERROR message: S3 bucket with public read-write access detected. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket shortlink: https://sg.run/0nok semgrep.dev: rule: r_id: 9754 rv_id: 1263900 rule_id: 6JUqvn version_id: PkTR3y5 url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket origin: community - id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. If you have to use `$TRUST`, ensure it does not come from user-input or use the appropriate prevention mechanism e.g. input validation or sanitization depending on the context. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://angular.io/api/platform-browser/DomSanitizer - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection confidence: MEDIUM category: security technology: - angular - browser cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust shortlink: https://sg.run/KWxP semgrep.dev: rule: r_id: 9755 rv_id: 1263902 rule_id: oqUzgA version_id: 5PTo1zk url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust origin: community languages: - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X: string, ...}) { ... } - pattern-inside: | function ...(..., $X: string, ...) { ... } - focus-metavariable: $X pattern-sinks: - patterns: - pattern-either: - pattern: $X.$TRUST($Y) - focus-metavariable: $Y - pattern-not: | $X.$TRUST(`...`) - pattern-not: | $X.$TRUST("...") - metavariable-regex: metavariable: $TRUST regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern: sanitizer.sanitize(...) - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); - id: typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any message: Access-Control-Allow-Origin response header is set to "*". This will disable CORS Same Origin Policy restrictions. metadata: cwe: - 'CWE-183: Permissive List of Allowed Inputs' asvs: section: 'V14: Configuration Verification Requirements' control_id: 14.4.8 Permissive CORS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x22-V14-Config.md#v144-http-security-headers-requirements version: '4' category: security technology: - nestjs owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any shortlink: https://sg.run/ljBL semgrep.dev: rule: r_id: 9757 rv_id: 1263909 rule_id: pKUG17 version_id: 0bTKzXw url: https://semgrep.dev/playground/r/0bTKzXw/typescript.nestjs.security.audit.nestjs-header-cors-any.nestjs-header-cors-any origin: community languages: - typescript severity: WARNING pattern-either: - pattern: | class $CN { @Header("=~/[Aa][Cc][Cc][Ee][Ss][Ss]-[Cc][Oo][Nn][Tt][Rr][Oo][Ll]-[Aa][Ll][Ll][Oo][Ww]-[Oo][Rr][Ii][Gg][Ii][Nn]/", '*') $FN(...) { ... } } - pattern: | NestFactory.create($MODULE, {cors: true}) - pattern: | NestFactory.create($MODULE, {cors: {origin: '*'}}) - pattern: | $APP.enableCors() - pattern: | $APP.enableCors({origin: '*'}) - id: typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled message: X-XSS-Protection header is set to 0. This will disable the browser's XSS Filter. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' category: security technology: - nestjs owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled shortlink: https://sg.run/YgGW semgrep.dev: rule: r_id: 9758 rv_id: 1263910 rule_id: 2ZU4zx version_id: K3TKkXw url: https://semgrep.dev/playground/r/K3TKkXw/typescript.nestjs.security.audit.nestjs-header-xss-disabled.nestjs-header-xss-disabled origin: community languages: - typescript severity: WARNING pattern: | class $CN { ... @Header("=~/[Xx]-[Xx][Ss][Ss]-[Pp][Rr][Oo][Tt][Ee][Cc][Tt][Ii][Oo][Nn]/", '0') $FN(...) { ... } ... } - id: typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect message: 'Untrusted user input in {url: ...} can result in Open Redirect vulnerability.' metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' category: security technology: - nestjs owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect shortlink: https://sg.run/6rJw semgrep.dev: rule: r_id: 9759 rv_id: 1263911 rule_id: X5UZQK version_id: qkTR7y4 url: https://semgrep.dev/playground/r/qkTR7y4/typescript.nestjs.security.audit.nestjs-open-redirect.nestjs-open-redirect origin: community languages: - typescript severity: WARNING patterns: - pattern: | return {url: $URL} - pattern-inside: | class $CN { @Redirect(...) $FN(...) { ... } } - pattern-not: | return {url: "..."} - id: typescript.react.security.react-insecure-request.react-insecure-request message: Unencrypted request over HTTP detected. metadata: vulnerability: Insecure Transport owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://www.npmjs.com/package/axios category: security technology: - react subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request shortlink: https://sg.run/1n0b semgrep.dev: rule: r_id: 9766 rv_id: 1263918 rule_id: NbUA3O version_id: A8Tgd2p url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request origin: community languages: - typescript - javascript severity: ERROR patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | import $AXIOS from 'axios'; ... $AXIOS.$METHOD(...) - pattern-inside: | $AXIOS = require('axios'); ... $AXIOS.$METHOD(...) - pattern: $AXIOS.$VERB("$URL",...) - metavariable-regex: metavariable: $VERB regex: ^(get|post|delete|head|patch|put|options) - patterns: - pattern-either: - pattern-inside: | import $AXIOS from 'axios'; ... $AXIOS(...) - pattern-inside: | $AXIOS = require('axios'); ... $AXIOS(...) - pattern-either: - pattern: '$AXIOS({url: "$URL"}, ...)' - pattern: | $OPTS = {url: "$URL"} ... $AXIOS($OPTS, ...) - pattern: fetch("$URL", ...) - metavariable-regex: metavariable: $URL regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) - id: typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html message: Overwriting `transformLinkUri` or `transformImageUri` to something insecure, or turning `allowDangerousHtml` on, or turning `escapeHtml` off, will open the code up to XSS vectors. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://www.npmjs.com/package/react-markdown#security category: security technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html shortlink: https://sg.run/9qAk semgrep.dev: rule: r_id: 9767 rv_id: 1263919 rule_id: kxURd4 version_id: BjTkZA8 url: https://semgrep.dev/playground/r/BjTkZA8/typescript.react.security.react-markdown-insecure-html.react-markdown-insecure-html origin: community languages: - typescript - javascript severity: WARNING patterns: - pattern-either: - pattern-inside: | $X = require('react-markdown/with-html'); ... - pattern-inside: | $X = require('react-markdown'); ... - pattern-inside: | import 'react-markdown/with-html'; ... - pattern-inside: | import 'react-markdown'; ... - pattern-either: - pattern: | <$EL allowDangerousHtml /> - pattern: | <$EL escapeHtml={false} /> - pattern: | <$EL transformLinkUri=... /> - pattern: | <$EL transformImageUri=... /> - id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml message: Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html category: security confidence: MEDIUM technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml shortlink: https://sg.run/rAx6 semgrep.dev: rule: r_id: 9769 rv_id: 1263912 rule_id: x8UWvK version_id: l4TJR0v url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml origin: community languages: - typescript - javascript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X, ...}) { ... } - pattern-inside: | function ...(..., $X, ...) { ... } - focus-metavariable: $X - pattern-not-inside: | $F. ... .$SANITIZEUNC(...) pattern-sinks: - patterns: - focus-metavariable: $X - pattern-either: - pattern: | {...,dangerouslySetInnerHTML: {__html: $X},...} - pattern: | <$Y ... dangerouslySetInnerHTML={{__html: $X}} /> - pattern-not: | <$Y ... dangerouslySetInnerHTML={{__html: "..."}} /> - pattern-not: | {...,dangerouslySetInnerHTML:{__html: "..."},...} - metavariable-pattern: patterns: - pattern-not: | {...} metavariable: $X - pattern-not: | <... {__html: "..."} ...> - pattern-not: | <... {__html: `...`} ...> pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - id: typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property message: Property decoded from JWT token without verifying and cannot be trustworthy. metadata: cwe: - 'CWE-922: Insecure Storage of Sensitive Information' references: - https://pragmaticwebsecurity.com/articles/oauthoidc/localstorage-xss.html category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - react subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property shortlink: https://sg.run/wx8x semgrep.dev: rule: r_id: 9773 rv_id: 1263914 rule_id: d8Uzqz version_id: JdTzxjz url: https://semgrep.dev/playground/r/JdTzxjz/typescript.react.security.audit.react-jwt-decoded-property.react-jwt-decoded-property origin: community languages: - typescript - javascript severity: INFO patterns: - pattern-inside: | import jwt_decode from "jwt-decode"; ... - pattern-inside: | $DECODED = jwt_decode($TOKEN,...); ... - pattern: $DECODED.$PROPERTY - id: typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage message: Storing JWT tokens in localStorage known to be a bad practice, consider moving your tokens from localStorage to a HTTP cookie. metadata: cwe: - 'CWE-922: Insecure Storage of Sensitive Information' references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - react subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage shortlink: https://sg.run/xYye semgrep.dev: rule: r_id: 9774 rv_id: 1263915 rule_id: ZqUq6g version_id: 5PTo1zq url: https://semgrep.dev/playground/r/5PTo1zq/typescript.react.security.audit.react-jwt-in-localstorage.react-jwt-in-localstorage origin: community languages: - typescript - javascript severity: INFO patterns: - pattern-inside: | import jwt_decode from "jwt-decode"; ... - pattern-either: - pattern: | $DECODED = jwt_decode($TOKEN,...); ... localStorage.setItem($NAME, <... $TOKEN ...>); - pattern: | $DECODED = jwt_decode(...); ... localStorage.setItem($NAME, <... $DECODED ...>); - id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln - https://developer.mozilla.org/en-US/docs/Web/API/Document/write - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML category: security confidence: MEDIUM technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method shortlink: https://sg.run/E5x8 semgrep.dev: rule: r_id: 9781 rv_id: 1263916 rule_id: QrU68w version_id: GxTkeRl url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method origin: community languages: - typescript - javascript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X, ...}) { ... } - pattern-inside: | function ...(..., $X, ...) { ... } - focus-metavariable: $X - pattern-either: - pattern: $X.$Y - pattern: $X[...] pattern-sinks: - patterns: - pattern-either: - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" - pattern: "window.document. ... .$HTML('...',$SINK) \n" - pattern: "document.$HTML($SINK) \n" - metavariable-regex: metavariable: $HTML regex: (writeln|write) - focus-metavariable: $SINK - patterns: - pattern-either: - pattern: "$PROP. ... .$HTML('...',$SINK) \n" - metavariable-regex: metavariable: $HTML regex: (insertAdjacentHTML) - focus-metavariable: $SINK pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - id: ruby.lang.security.dangerous-exec.dangerous-exec mode: taint pattern-sources: - patterns: - pattern: | def $F(...,$ARG,...) ... end - focus-metavariable: $ARG - pattern: params - pattern: cookies pattern-sinks: - patterns: - pattern: | $EXEC(...) - pattern-not: | $EXEC("...","...","...",...) - pattern-not: | $EXEC(["...","...","...",...],...) - pattern-not: | $EXEC({...},"...","...","...",...) - pattern-not: | $EXEC({...},["...","...","...",...],...) - metavariable-regex: metavariable: $EXEC regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby - rails references: - https://guides.rubyonrails.org/security.html#command-line-injection cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec shortlink: https://sg.run/R8GY semgrep.dev: rule: r_id: 9805 rv_id: 1409405 rule_id: WAUZOw version_id: WrT7erb url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec origin: community severity: WARNING languages: - ruby - id: ruby.lang.security.dangerous-open.dangerous-open patterns: - pattern: | open($CMD,...) - pattern-not: | open("...",...) - metavariable-regex: metavariable: $CMD regex: '|' message: Detected non-static command inside 'open'. Audit the input to 'open'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-open.dangerous-open shortlink: https://sg.run/Al8Q semgrep.dev: rule: r_id: 9806 rv_id: 1263599 rule_id: 0oUEyd version_id: 5PTo1WL url: https://semgrep.dev/playground/r/5PTo1WL/ruby.lang.security.dangerous-open.dangerous-open origin: community severity: WARNING languages: - ruby - id: ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline patterns: - pattern: | Open3.$PIPE(...) - pattern-not: | Open3.$PIPE(...,"...",...) - metavariable-regex: metavariable: $PIPE regex: ^(pipeline|pipeline_r|pipeline_rw|pipeline_start|pipeline_w)$ message: Detected non-static command inside $PIPE. Audit the input to '$PIPE'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline shortlink: https://sg.run/B4jv semgrep.dev: rule: r_id: 9807 rv_id: 1263600 rule_id: KxU4nd version_id: GxTkeNz url: https://semgrep.dev/playground/r/GxTkeNz/ruby.lang.security.dangerous-open3-pipeline.dangerous-open3-pipeline origin: community severity: WARNING languages: - ruby - id: ruby.lang.security.dangerous-syscall.dangerous-syscall pattern: | syscall message: '''syscall'' is essentially unsafe and unportable. The DL (https://apidock.com/ruby/Fiddle) library is preferred for safer and a bit more portable programming.' metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-syscall.dangerous-syscall shortlink: https://sg.run/DJkv semgrep.dev: rule: r_id: 9808 rv_id: 1263602 rule_id: qNUo50 version_id: A8TgdDN url: https://semgrep.dev/playground/r/A8TgdDN/ruby.lang.security.dangerous-syscall.dangerous-syscall origin: community severity: WARNING languages: - ruby - id: ruby.lang.security.dangerous-subshell.dangerous-subshell patterns: - pattern: | `...#{$VAL}...` - pattern-not: | `...#{"..."}...` - pattern-not-inside: | $VAL = "..." ... message: Detected non-static command inside `...`. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-subshell.dangerous-subshell shortlink: https://sg.run/NrxL semgrep.dev: rule: r_id: 9827 rv_id: 1263601 rule_id: OrUGn8 version_id: RGT0LJK url: https://semgrep.dev/playground/r/RGT0LJK/ruby.lang.security.dangerous-subshell.dangerous-subshell origin: community severity: WARNING languages: - ruby - id: javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell message: Detected non-literal calls to $EXEC(). This could lead to a command injection vulnerability. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-child-process.js category: security technology: - javascript references: - https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html#do-not-use-dangerous-functions cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell shortlink: https://sg.run/DJ8v semgrep.dev: rule: r_id: 9852 rv_id: 1263193 rule_id: qNUo10 version_id: PkTR3nY url: https://semgrep.dev/playground/r/PkTR3nY/javascript.lang.security.audit.dangerous-spawn-shell.dangerous-spawn-shell origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: | function ... (...,$FUNC,...) { ... } - focus-metavariable: $FUNC pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('child_process') ... - pattern-inside: | import 'child_process' ... - pattern-either: - pattern: spawn(...) - pattern: spawnSync(...) - pattern: $CP.spawn(...) - pattern: $CP.spawnSync(...) - pattern-either: - pattern: | $EXEC("=~/(sh|bash|ksh|csh|tcsh|zsh)/",["-c", $ARG, ...],...) - patterns: - pattern: $EXEC($CMD,["-c", $ARG, ...],...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" ... - pattern: | $EXEC("=~/(sh|bash|ksh|csh|tcsh|zsh)/",[$ARG, ...],...) - patterns: - pattern: $EXEC($CMD,[$ARG, ...],...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" ... - focus-metavariable: $ARG - id: javascript.lang.security.audit.spawn-shell-true.spawn-shell-true message: 'Found ''$SPAWN'' with ''{shell: $SHELL}''. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use ''{shell: false}'' instead.' metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' category: security technology: - javascript cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.lang.security.audit.spawn-shell-true.spawn-shell-true shortlink: https://sg.run/Wgeo semgrep.dev: rule: r_id: 9853 rv_id: 1263204 rule_id: lBUdr5 version_id: qkTR79W url: https://semgrep.dev/playground/r/qkTR79W/javascript.lang.security.audit.spawn-shell-true.spawn-shell-true origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern-either: - pattern: | spawn(...,{shell: $SHELL}) - pattern: | spawnSync(...,{shell: $SHELL}) - pattern: | $CP.spawn(...,{shell: $SHELL}) - pattern: | $CP.spawnSync(...,{shell: $SHELL}) - pattern-not: | spawn(...,{shell: false}) - pattern-not: | spawnSync(...,{shell: false}) - pattern-not: | $CP.spawn(...,{shell: false}) - pattern-not: | $CP.spawnSync(...,{shell: false}) - id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run message: Detected non-literal calls to Deno.run(). This could lead to a command injection vulnerability. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - deno references: - https://deno.land/manual/examples/subprocess#simple-example cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run shortlink: https://sg.run/Nrrn semgrep.dev: rule: r_id: 9927 rv_id: 1409397 rule_id: x8UWWg version_id: PkTe7AP url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: function ... (..., $ARG,...) {...} - focus-metavariable: $ARG pattern-sinks: - patterns: - pattern-either: - pattern: | Deno.run({cmd: [$INPUT,...]},...) - pattern: | Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...) - patterns: - pattern: | Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" ... - focus-metavariable: $INPUT - id: java.lang.security.audit.command-injection-process-builder.command-injection-process-builder pattern-either: - patterns: - pattern: | new ProcessBuilder($CMD,...) - pattern-not-inside: | $CMD = "..."; ... - pattern-not-inside: | $CMD = Arrays.asList("...",...); ... - pattern-not-inside: | $CMD = new String[]{"...",...}; ... - pattern-not: | new ProcessBuilder("...",...) - pattern-not: | new ProcessBuilder(new String[]{"...",...},...) - pattern-not: | new ProcessBuilder(Arrays.asList("...",...),...) - patterns: - pattern: | $PB.command($CMD,...) - pattern-inside: | $TYPE $PB = new ProcessBuilder(...); ... - pattern-not-inside: | $CMD = "..."; ... - pattern-not-inside: | $CMD = Arrays.asList("...",...); ... - pattern-not-inside: | $CMD = new String[]{"...",...}; ... - pattern-not: | $PB.command("...",...) - pattern-not: | $PB.command(new String[]{"...",...},...) - pattern-not: | $PB.command(Arrays.asList("...",...),...) - patterns: - pattern-either: - pattern: | new ProcessBuilder("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...) - pattern: | new ProcessBuilder("cmd","/c",$ARG,...) - pattern: | new ProcessBuilder(Arrays.asList("cmd","/c",$ARG,...),...) - pattern: | new ProcessBuilder(new String[]{"cmd","/c",$ARG,...},...) - patterns: - pattern-either: - pattern: | new ProcessBuilder($CMD,"/c",$ARG,...) - pattern: | new ProcessBuilder(Arrays.asList($CMD,"/c",$ARG,...),...) - pattern: | new ProcessBuilder(new String[]{$CMD,"/c",$ARG,...},...) - pattern-inside: | $CMD = "cmd"; ... - pattern-not-inside: | $ARG = "..."; ... - pattern-not: | new ProcessBuilder("...","...","...",...) - pattern-not: | new ProcessBuilder(new String[]{"...","...","...",...},...) - pattern-not: | new ProcessBuilder(Arrays.asList("...","...","...",...),...) - patterns: - pattern-either: - pattern: | $PB.command("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...) - pattern: | $PB.command("cmd","/c",$ARG,...) - pattern: | $PB.command(Arrays.asList("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...),...) - pattern: | $PB.command(Arrays.asList("cmd","/c",$ARG,...),...) - pattern: | $PB.command(new String[]{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$ARG,...},...) - pattern: | $PB.command(new String[]{"cmd","/c",$ARG,...},...) - patterns: - pattern-either: - pattern: | $PB.command($CMD,"-c",$ARG,...) - pattern: | $PB.command(Arrays.asList($CMD,"-c",$ARG,...),...) - pattern: | $PB.command(new String[]{$CMD,"-c",$ARG,...},...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/"; ... - patterns: - pattern-either: - pattern: | $PB.command($CMD,"/c",$ARG,...) - pattern: | $PB.command(Arrays.asList($CMD,"/c",$ARG,...),...) - pattern: | $PB.command(new String[]{$CMD,"/c",$ARG,...},...) - pattern-inside: | $CMD = "cmd"; ... - pattern-inside: | $TYPE $PB = new ProcessBuilder(...); ... - pattern-not-inside: | $ARG = "..."; ... - pattern-not: | $PB.command("...","...","...",...) - pattern-not: | $PB.command(new String[]{"...","...","...",...},...) - pattern-not: | $PB.command(Arrays.asList("...","...","...",...),...) message: A formatted or concatenated string was detected as input to a ProcessBuilder call. This is dangerous if a variable is controlled by user input and could result in a command injection. Ensure your variables are not controlled by users or sufficiently sanitized. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.lang.security.audit.command-injection-process-builder.command-injection-process-builder shortlink: https://sg.run/gJJe semgrep.dev: rule: r_id: 9941 rv_id: 1262992 rule_id: 4bUzzo version_id: JdTzxnn url: https://semgrep.dev/playground/r/JdTzxnn/java.lang.security.audit.command-injection-process-builder.command-injection-process-builder origin: community severity: ERROR languages: - java - id: java.spring.security.audit.spring-jsp-eval.spring-jsp-eval pattern: | message: A Spring expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. severity: WARNING languages: - generic metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#JSP_SPRING_EVAL category: security technology: - spring references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.spring.security.audit.spring-jsp-eval.spring-jsp-eval shortlink: https://sg.run/Q88o semgrep.dev: rule: r_id: 9942 rv_id: 1263081 rule_id: PeUkkL version_id: d6TyxL7 url: https://semgrep.dev/playground/r/d6TyxL7/java.spring.security.audit.spring-jsp-eval.spring-jsp-eval origin: community paths: include: - '*.jsp' - id: javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls message: 'If TLS is disabled on server side (Postgresql server), Sequelize establishes connection without TLS and no error will be thrown. To prevent MITN (Man In The Middle) attack, TLS must be enforce by Sequelize. Set "ssl: true" or define settings "ssl: {...}"' metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://node-postgres.com/features/ssl - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options - https://nodejs.org/api/tls.html#tls_tls_default_min_version category: security technology: - sequelize subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls shortlink: https://sg.run/yz6Z semgrep.dev: rule: r_id: 9968 rv_id: 1263240 rule_id: NbUAYW version_id: ZRTKAJ4 url: https://semgrep.dev/playground/r/ZRTKAJ4/javascript.sequelize.security.audit.sequelize-enforce-tls.sequelize-enforce-tls origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern: | { host: $HOST, database: $DATABASE, dialect: $DIALECT } - pattern-not: | { host: $HOST, database: $DATABASE, dialect: "postgres", dialectOptions: { ssl: true } } - pattern-not: | { host: $HOST, database: $DATABASE, dialect: $DIALECT, dialectOptions: { ssl: { ... } } } - metavariable-regex: metavariable: $DIALECT regex: '[''"](mariadb|mysql|postgres)[''"]' - id: javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation message: Set "rejectUnauthorized" to false is a convenient way to resolve certificate error. But this method is unsafe because it disables the server certificate verification, making the Node app open to MITM attack. "rejectUnauthorized" option must be alway set to True (default value). With self -signed certificate or custom CA, use "ca" option to define Root Certificate. This rule checks TLS configuration only for Postgresql, MariaDB and MySQL. SQLite is not really concerned by TLS configuration. This rule could be extended for MSSQL, but the dialectOptions is specific for Tedious. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://node-postgres.com/features/ssl - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options category: security technology: - sequelize cwe2022-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation shortlink: https://sg.run/rAkj semgrep.dev: rule: r_id: 9969 rv_id: 1263243 rule_id: kxUR80 version_id: 7ZTE3w1 url: https://semgrep.dev/playground/r/7ZTE3w1/javascript.sequelize.security.audit.sequelize-tls-disabled-cert-validation.sequelize-tls-disabled-cert-validation origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern: | { host: $HOST, database: $DATABASE, dialect: $DIALECT, dialectOptions: { ssl: { rejectUnauthorized: false } } } - metavariable-regex: metavariable: $DIALECT regex: '[''"](mariadb|mysql|postgres)[''"]' - id: javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version message: TLS1.0 and TLS1.1 are deprecated and should not be used anymore. By default, NodeJS used TLSv1.2. So, TLS min version must not be downgrade to TLS1.0 or TLS1.1. Enforce TLS1.3 is highly recommended This rule checks TLS configuration only for PostgreSQL, MariaDB and MySQL. SQLite is not really concerned by TLS configuration. This rule could be extended for MSSQL, but the dialectOptions is specific for Tedious. metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://node-postgres.com/features/ssl - https://nodejs.org/api/tls.html#tls_class_tls_tlssocket - https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options - https://nodejs.org/api/tls.html#tls_tls_default_min_version category: security technology: - sequelize subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version shortlink: https://sg.run/bDrq semgrep.dev: rule: r_id: 9970 rv_id: 1263244 rule_id: wdU8GB version_id: LjTkgJy url: https://semgrep.dev/playground/r/LjTkgJy/javascript.sequelize.security.audit.sequelize-weak-tls-version.sequelize-weak-tls-version origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | { host: $HOST, database: $DATABASE, dialect: $DIALECT, dialectOptions: { ssl: ... } } - pattern-either: - pattern: | { minVersion: 'TLSv1' } - pattern: | { minVersion: 'TLSv1.1' } - metavariable-regex: metavariable: $DIALECT regex: '[''"](mariadb|mysql|postgres)[''"]' - id: java.jboss.security.seam-log-injection.seam-log-injection patterns: - pattern: | $LOG.$INFO($X + $Y,...) - pattern-either: - pattern-inside: | import org.jboss.seam.log.Log; ... - pattern-inside: | org.jboss.seam.log.Log $LOG = ...; ... - metavariable-regex: metavariable: $INFO regex: (debug|error|fatal|info|trace|warn) languages: - java message: Seam Logging API support an expression language to introduce bean property to log messages. The expression language can also be the source to unwanted code execution. In this context, an expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SEAM_LOG_INJECTION category: security technology: - jboss confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.jboss.security.seam-log-injection.seam-log-injection shortlink: https://sg.run/3A4o semgrep.dev: rule: r_id: 9987 rv_id: 1262985 rule_id: JDUPQ7 version_id: LjTkgRE url: https://semgrep.dev/playground/r/LjTkgRE/java.jboss.security.seam-log-injection.seam-log-injection origin: community severity: ERROR - id: java.lang.security.audit.unsafe-reflection.unsafe-reflection patterns: - pattern: | Class.forName($CLASS,...) - pattern-not: | Class.forName("...",...) - pattern-not-inside: | $CLASS = "..."; ... message: If an attacker can supply values that the application then uses to determine which class to instantiate or which method to invoke, the potential exists for the attacker to create control flow paths through the application that were not intended by the application developers. This attack vector may allow the attacker to bypass authentication or access control checks or otherwise cause the application to behave in an unexpected manner. metadata: cwe: - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe Reflection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://owasp.org/www-community/vulnerabilities/Unsafe_use_of_Reflection category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/java.lang.security.audit.unsafe-reflection.unsafe-reflection shortlink: https://sg.run/R8X8 semgrep.dev: rule: r_id: 9993 rv_id: 1263047 rule_id: DbUW1W version_id: 44TEj5L url: https://semgrep.dev/playground/r/44TEj5L/java.lang.security.audit.unsafe-reflection.unsafe-reflection origin: community severity: WARNING languages: - java - id: go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name patterns: - pattern-either: - pattern: | $SMTH.MethodByName($NAME,...) - pattern: | $SMTH.FieldByName($NAME,...) - pattern-not: | $SMTH.MethodByName("...",...) - pattern-not: | $SMTH.FieldByName("...",...) - pattern-inside: | import "reflect" ... message: If an attacker can supply values that the application then uses to determine which method or field to invoke, the potential exists for the attacker to create control flow paths through the application that were not intended by the application developers. This attack vector may allow the attacker to bypass authentication or access control checks or otherwise cause the application to behave in an unexpected manner. metadata: cwe: - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe Reflection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name shortlink: https://sg.run/R8Xv semgrep.dev: rule: r_id: 10005 rv_id: 1262955 rule_id: BYUBdJ version_id: WrTqK8e url: https://semgrep.dev/playground/r/WrTqK8e/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name origin: community severity: WARNING languages: - go - id: yaml.docker-compose.security.privileged-service.privileged-service patterns: - pattern-inside: | version: ... ... services: ... $SERVICE: ... privileged: $TRUE - focus-metavariable: $TRUE - metavariable-regex: metavariable: $TRUE regex: (true) fix: | false message: Service '$SERVICE' is running in privileged mode. This grants the container the equivalent of root capabilities on the host machine. This can lead to container escapes, privilege escalation, and other security concerns. Remove the 'privileged' key to disable this capability. metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ category: security technology: - docker-compose subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service shortlink: https://sg.run/AlX0 semgrep.dev: rule: r_id: 10006 rv_id: 1263922 rule_id: DbUW17 version_id: 0bTKzXZ url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service origin: community languages: - yaml severity: WARNING - id: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash pattern-regex: \$2[aby]?\$[\d]+\$[./A-Za-z0-9]{53} languages: - regex message: bcrypt hash detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets - bcrypt confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash shortlink: https://sg.run/3A8G semgrep.dev: rule: r_id: 10043 rv_id: 1262864 rule_id: PeUk0Q version_id: 2KTv236 url: https://semgrep.dev/playground/r/2KTv236/generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash origin: community - id: generic.secrets.security.detected-etc-shadow.detected-etc-shadow patterns: - pattern-regex: ^(\s*)(?Proot:[x!*]*:[0-9]*:[0-9]*) - focus-metavariable: $ROOT languages: - regex message: linux shadow file detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-etc-shadow.detected-etc-shadow shortlink: https://sg.run/4ylL semgrep.dev: rule: r_id: 10044 rv_id: 1262866 rule_id: JDUP6p version_id: jQTn5yp url: https://semgrep.dev/playground/r/jQTn5yp/generic.secrets.security.detected-etc-shadow.detected-etc-shadow origin: community - id: generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token patterns: - pattern: $AUTHTOKEN = $VALUE - metavariable-regex: metavariable: $AUTHTOKEN regex: _(authToken|auth|password) - pattern-not: $AUTHTOKEN = ${...} languages: - generic message: NPM registry authentication token detected paths: include: - '*npmrc*' severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets - npm confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token shortlink: https://sg.run/Ppg3 semgrep.dev: rule: r_id: 10045 rv_id: 1262883 rule_id: 5rU4pe version_id: 7ZTE3n2 url: https://semgrep.dev/playground/r/7ZTE3n2/generic.secrets.security.detected-npm-registry-auth-token.detected-npm-registry-auth-token origin: community - id: javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket message: Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections. metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' asvs: section: 'V13: API and Web Service Verification Requirements' control_id: 13.5.1 Insecure WebSocket control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x21-V13-API.md#v135-websocket-security-requirements version: '4' category: security technology: - regex owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket shortlink: https://sg.run/GWyz semgrep.dev: rule: r_id: 10048 rv_id: 1263215 rule_id: AbUWeE version_id: 0bTKzQ9 url: https://semgrep.dev/playground/r/0bTKzQ9/javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket origin: community languages: - regex severity: ERROR patterns: - pattern-regex: \bws:\/\/ - pattern-not-inside: \bws:\/\/localhost.* - pattern-not-inside: \bws:\/\/127.0.0.1.* - id: yaml.docker-compose.security.no-new-privileges.no-new-privileges patterns: - pattern-inside: | version: ... ... services: ... - pattern: | $SERVICE: ... image: ... - pattern-not: | $SERVICE: ... image: ... ... security_opt: - ... - no-new-privileges:true - ... - focus-metavariable: $SERVICE message: Service '$SERVICE' allows for privilege escalation via setuid or setgid binaries. Add 'no-new-privileges:true' in 'security_opt' to prevent this. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://raesene.github.io/blog/2019/06/01/docker-capabilities-and-no-new-privs/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - docker-compose cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.no-new-privileges.no-new-privileges shortlink: https://sg.run/0n8q semgrep.dev: rule: r_id: 10054 rv_id: 1263921 rule_id: qNUoWr version_id: WrTqKwk url: https://semgrep.dev/playground/r/WrTqKwk/yaml.docker-compose.security.no-new-privileges.no-new-privileges origin: community languages: - yaml severity: WARNING - id: yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled patterns: - pattern-inside: | version: ... ... services: ... - pattern: | $SERVICE: ... image: ... ... security_opt: - ... - seccomp:unconfined message: Service '$SERVICE' is explicitly disabling seccomp confinement. This runs the service in an unrestricted state. Remove 'seccomp:unconfined' to prevent this. metadata: cwe: - 'CWE-284: Improper Access Control' references: - https://docs.docker.com/engine/security/seccomp/ category: security technology: - docker-compose owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled shortlink: https://sg.run/KWkY semgrep.dev: rule: r_id: 10055 rv_id: 1263923 rule_id: lBUdW3 version_id: K3TKkXA url: https://semgrep.dev/playground/r/K3TKkXA/yaml.docker-compose.security.seccomp-confinement-disabled.seccomp-confinement-disabled origin: community languages: - yaml severity: WARNING - id: yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled patterns: - pattern-inside: | version: ... ... services: ... - pattern: | $SERVICE: ... image: ... ... security_opt: - ... - label:disable message: Service '$SERVICE' is explicitly disabling SELinux separation. This runs the service as an unconfined type. Remove 'label:disable' to prevent this. metadata: cwe: - 'CWE-284: Improper Access Control' references: - https://www.projectatomic.io/blog/2016/03/dwalsh_selinux_containers/ - https://docs.docker.com/engine/reference/run/#security-configuration category: security technology: - docker-compose owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled shortlink: https://sg.run/qryb semgrep.dev: rule: r_id: 10056 rv_id: 1263924 rule_id: YGUrAG version_id: qkTR7yg url: https://semgrep.dev/playground/r/qkTR7yg/yaml.docker-compose.security.selinux-separation-disabled.selinux-separation-disabled origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation patterns: - pattern-inside: | containers: ... - pattern-inside: | - name: $CONTAINER ... - pattern: | image: ... ... - pattern-inside: | image: ... ... $SC: ... - metavariable-regex: metavariable: $SC regex: ^(securityContext)$ - pattern-not-inside: | image: ... ... securityContext: ... allowPrivilegeEscalation: $VAL - focus-metavariable: $SC fix: | securityContext: allowPrivilegeEscalation: false # message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation` parameter to your the `securityContext`, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation shortlink: https://sg.run/ljp6 semgrep.dev: rule: r_id: 10057 rv_id: 1263933 rule_id: 6JUqEO version_id: jQTn527 url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.privileged-container.privileged-container pattern-either: - patterns: - pattern-inside: | containers: ... - pattern: | image: ... ... securityContext: ... privileged: true - patterns: - pattern-inside: | spec: ... - pattern-not-inside: | image: ... ... - pattern: | privileged: true message: Container or pod is running in privileged mode. This grants the container the equivalent of root capabilities on the host machine. This can lead to container escapes, privilege escalation, and other security concerns. Remove the 'privileged' key to disable this capability. metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privileged - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html category: security technology: - kubernetes subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.privileged-container.privileged-container shortlink: https://sg.run/Ygr5 semgrep.dev: rule: r_id: 10058 rv_id: 947059 rule_id: oqUz2p version_id: gETeWJA url: https://semgrep.dev/playground/r/gETeWJA/yaml.kubernetes.security.privileged-container.privileged-container origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled patterns: - pattern-inside: | containers: ... - pattern: | image: ... ... securityContext: ... seccompProfile: unconfined message: 'Container is explicitly disabling seccomp confinement. This runs the service in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.' metadata: cwe: - 'CWE-284: Improper Access Control' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ category: security technology: - kubernetes owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled shortlink: https://sg.run/6rgY semgrep.dev: rule: r_id: 10059 rv_id: 1263941 rule_id: zdUynw version_id: w8TRoL3 url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled origin: community languages: - yaml severity: WARNING - id: python.lang.security.dangerous-globals-use.dangerous-globals-use patterns: - pattern-either: - pattern: globals().get(...) - pattern: locals().get(...) - pattern: globals()[...] - pattern: locals()[...] - patterns: - pattern-either: - pattern-inside: | $G = globals() ... - pattern-inside: | $G = locals() ... - pattern-either: - pattern: $G.get(...) - pattern: $G[...] - pattern: $FUNC.__globals__[...] - pattern-not: globals().get("...") - pattern-not: locals().get("...") - pattern-not: globals()["..."] - pattern-not: locals()["..."] - pattern-not: $G.get("...") - pattern-not: $G.get["..."] - pattern-not: $G["..."] - pattern-not: $FUNC.__globals__["..."] - pattern-not-inside: globals()[...] = ... - pattern-not-inside: locals()[...] = ... - pattern-not-inside: $G[...] = ... - pattern-not-inside: $FUNC.__globals__[...] = ... message: Found non static data as an index to 'globals()'. This is extremely dangerous because it allows an attacker to execute arbitrary code on the system. Refactor your code not to use 'globals()'. metadata: cwe: - 'CWE-96: Improper Neutralization of Directives in Statically Saved Code (''Static Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/mpirnat/lets-be-bad-guys/blob/d92768fb3ade32956abd53bd6bb06e19d634a084/badguys/vulnerable/views.py#L181-L186 category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-globals-use.dangerous-globals-use shortlink: https://sg.run/jNzn semgrep.dev: rule: r_id: 10065 rv_id: 1263522 rule_id: 9AUOZP version_id: YDTZeB4 url: https://semgrep.dev/playground/r/YDTZeB4/python.lang.security.dangerous-globals-use.dangerous-globals-use origin: community severity: WARNING languages: - python - id: java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell patterns: - pattern-either: - pattern: | $SHELL.parse(...) - pattern: | $SHELL.evaluate(...) - pattern: | $SHELL.parseClass(...) - pattern-either: - pattern-inside: | groovy.lang.GroovyShell $SHELL = ...; ... - pattern-inside: | groovy.lang.GroovyClassLoader $SHELL = ...; ... - pattern-not: | $SHELL.parse("...",...) - pattern-not: | $SHELL.evaluate("...",...) - pattern-not: | $SHELL.parseClass("...",...) message: A expression is built with a dynamic value. The source of the value(s) should be verified to avoid that unfiltered values fall into this risky code evaluation. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#GROOVY_SHELL category: security technology: - groovy references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell shortlink: https://sg.run/58LK semgrep.dev: rule: r_id: 10091 rv_id: 1263020 rule_id: ReUPKp version_id: zyTb2Nq url: https://semgrep.dev/playground/r/zyTb2Nq/java.lang.security.audit.dangerous-groovy-shell.dangerous-groovy-shell origin: community languages: - java severity: WARNING - id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster pattern: | cluster: ... insecure-skip-tls-verify: true message: 'Cluster is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify: true'' key to secure communication.' metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster category: security technology: - kubernetes owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster shortlink: https://sg.run/okyn semgrep.dev: rule: r_id: 10116 rv_id: 1263943 rule_id: zdUyWx version_id: O9Tpxbo url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service pattern: | spec: ... insecureSkipTLSVerify: true message: 'Service is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify: true'' key to secure communication.' metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io category: security technology: - kubernetes owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service shortlink: https://sg.run/zk10 semgrep.dev: rule: r_id: 10117 rv_id: 1263944 rule_id: pKUGXr version_id: e1TyjnR url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service origin: community languages: - yaml severity: WARNING - id: python.flask.security.flask-api-method-string-format.flask-api-method-string-format patterns: - pattern-either: - pattern: | def $METHOD(...,$ARG,...): ... $STRING = "...".format(...,$ARG,...) ... ... = requests.$REQMETHOD($STRING,...) - pattern: | def $METHOD(...,$ARG,...): ... ... = requests.$REQMETHOD("...".format(...,$ARG,...),...) - pattern-inside: | class $CLASS(...): method_decorators = ... ... message: Method $METHOD in API controller $CLASS provides user arg $ARG to requests method $REQMETHOD severity: ERROR languages: - python metadata: cwe: - 'CWE-134: Use of Externally-Controlled Format String' category: security technology: - flask references: - https://cwe.mitre.org/data/definitions/134.html subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.flask.security.flask-api-method-string-format.flask-api-method-string-format shortlink: https://sg.run/bDWr semgrep.dev: rule: r_id: 10126 rv_id: 946219 rule_id: NbUAeY version_id: WrTEo0r url: https://semgrep.dev/playground/r/WrTEo0r/python.flask.security.flask-api-method-string-format.flask-api-method-string-format origin: community - id: yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume patterns: - pattern-inside: | version: ... ... - pattern-either: - pattern: | volumes: - ... - /var/run/docker.sock:/var/run/docker.sock - ... - pattern: | volumes: - ... - /run/docker.sock:/run/docker.sock - ... - pattern: | volumes: - ... - /var/run/docker.sock:/run/docker.sock - ... - pattern: | volumes: - ... - /run/docker.sock:/var/run/docker.sock - ... - pattern: | volumes: - ... - /var/run/docker.sock - ... - pattern: | volumes: - ... - /run/docker.sock - ... - pattern: | volumes: - ... - ... source: /var/run/docker.sock ... - ... - pattern: | volumes: - ... - ... source: /run/docker.sock ... - ... message: Exposing host's Docker socket to containers via a volume. The owner of this socket is root. Giving someone access to it is equivalent to giving unrestricted root access to your host. Remove 'docker.sock' from volumes to prevent this. metadata: references: - https://docs.docker.com/compose/compose-file/compose-file-v3/#volume-configuration-reference - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-1-do-not-expose-the-docker-daemon-socket-even-to-the-containers category: security technology: - docker-compose cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume shortlink: https://sg.run/O14b semgrep.dev: rule: r_id: 10131 rv_id: 1263920 rule_id: eqUvZ9 version_id: DkTRbje url: https://semgrep.dev/playground/r/DkTRbje/yaml.docker-compose.security.exposing-docker-socket-volume.exposing-docker-socket-volume origin: community languages: - yaml severity: WARNING - id: yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service patterns: - pattern-inside: | version: ... ... services: ... - pattern: | $SERVICE: ... image: ... ... - pattern-not: | $SERVICE: ... image: ... ... read_only: true - focus-metavariable: $SERVICE message: 'Service ''$SERVICE'' is running with a writable root filesystem. This may allow malicious applications to download and run additional payloads, or modify container files. If an application inside a container has to save something temporarily consider using a tmpfs. Add ''read_only: true'' to this service to prevent this.' metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://docs.docker.com/compose/compose-file/compose-file-v3/#domainname-hostname-ipc-mac_address-privileged-read_only-shm_size-stdin_open-tty-user-working_dir - https://blog.atomist.com/security-of-docker-kubernetes/ - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-8-set-filesystem-and-volumes-to-read-only category: security technology: - docker-compose cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service shortlink: https://sg.run/e4JE semgrep.dev: rule: r_id: 10132 rv_id: 1263925 rule_id: v8U5vN version_id: l4TJR0w url: https://semgrep.dev/playground/r/l4TJR0w/yaml.docker-compose.security.writable-filesystem-service.writable-filesystem-service origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath patterns: - pattern-inside: | volumes: ... - pattern: | hostPath: ... path: /var/run/docker.sock message: Exposing host's Docker socket to containers via a volume. The owner of this socket is root. Giving someone access to it is equivalent to giving unrestricted root access to your host. Remove 'docker.sock' from hostpath to prevent this. metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' references: - https://kubernetes.io/docs/concepts/storage/volumes/#hostpath - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#volumes-and-file-systems - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-1-do-not-expose-the-docker-daemon-socket-even-to-the-containers category: security technology: - kubernetes subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath shortlink: https://sg.run/v0pR semgrep.dev: rule: r_id: 10133 rv_id: 947054 rule_id: d8Uz6v version_id: nWTpYZe url: https://semgrep.dev/playground/r/nWTpYZe/yaml.kubernetes.security.exposing-docker-socket-hostpath.exposing-docker-socket-hostpath origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.run-as-non-root.run-as-non-root patterns: - pattern-inside: | $SPEC: ... containers: ... ... - metavariable-regex: metavariable: $SPEC regex: ^(spec)$ - pattern-not-inside: | spec: ... securityContext: ... ... - pattern-inside: | $SPEC: ... containers: ... - pattern-not-inside: | $SPEC: ... containers: ... - name: $NAME image: ... ... securityContext: ... runAsNonRoot: $VALUE - focus-metavariable: $SPEC fix: | $SPEC: securityContext: runAsNonRoot: true # message: When running containers in Kubernetes, it's important to ensure that they are properly secured to prevent privilege escalation attacks. One potential vulnerability is when a container is allowed to run applications as the root user, which could allow an attacker to gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container, with the parameter `runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root user, limiting the damage that could be caused by any potential attacks. By adding a `securityContext` to the container in your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: references: - https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/ - https://kubernetes.io/docs/concepts/policy/pod-security-policy/ - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user category: security cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration technology: - kubernetes subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root.run-as-non-root shortlink: https://sg.run/dgP5 semgrep.dev: rule: r_id: 10134 rv_id: 1263940 rule_id: ZqUqeK version_id: kbTzGbo url: https://semgrep.dev/playground/r/kbTzGbo/yaml.kubernetes.security.run-as-non-root.run-as-non-root origin: community languages: - yaml severity: INFO - id: yaml.kubernetes.security.hostipc-pod.hostipc-pod patterns: - pattern-inside: | spec: ... - pattern: | hostIPC: true message: Pod is sharing the host IPC namespace. This allows container processes to communicate with processes on the host which reduces isolation and bypasses container protection models. Remove the 'hostIPC' key to disable this functionality. metadata: cwe: - 'CWE-693: Protection Mechanism Failure' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces category: security technology: - kubernetes subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.hostipc-pod.hostipc-pod shortlink: https://sg.run/nqGO semgrep.dev: rule: r_id: 10236 rv_id: 947055 rule_id: nJUYPE version_id: ExTg4KB url: https://semgrep.dev/playground/r/ExTg4KB/yaml.kubernetes.security.hostipc-pod.hostipc-pod origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod patterns: - pattern-inside: | spec: ... - pattern: | hostNetwork: true message: Pod may use the node network namespace. This gives the pod access to the loopback device, services listening on localhost, and could be used to snoop on network activity of other pods on the same node. Remove the 'hostNetwork' key to disable this functionality. metadata: cwe: - 'CWE-406: Insufficient Control of Network Message Volume (Network Amplification)' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces category: security technology: - kubernetes subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod shortlink: https://sg.run/E51A semgrep.dev: rule: r_id: 10237 rv_id: 947056 rule_id: EwU4NO version_id: 7ZTreWz url: https://semgrep.dev/playground/r/7ZTreWz/yaml.kubernetes.security.hostnetwork-pod.hostnetwork-pod origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.hostpid-pod.hostpid-pod patterns: - pattern-inside: | spec: ... - pattern: | hostPID: true message: Pod is sharing the host process ID namespace. When paired with ptrace this can be used to escalate privileges outside of the container. Remove the 'hostPID' key to disable this functionality. metadata: cwe: - 'CWE-269: Improper Privilege Management' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#host-namespaces category: security technology: - kubernetes owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.hostpid-pod.hostpid-pod shortlink: https://sg.run/708R semgrep.dev: rule: r_id: 10238 rv_id: 1263934 rule_id: 7KUeo0 version_id: 1QTypvL url: https://semgrep.dev/playground/r/1QTypvL/yaml.kubernetes.security.hostpid-pod.hostpid-pod origin: community languages: - yaml severity: WARNING - id: go.lang.security.audit.sqli.gosql-sqli.gosql-sqli patterns: - pattern-either: - patterns: - pattern: $DB.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = fmt.Sprintf("...", $PARAM1, ...) ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern: $DB.$METHOD(..., $X + $Y, ...) - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) - pattern-either: - pattern-inside: | $DB, ... = sql.Open(...) ... - pattern-inside: | func $FUNCNAME(..., $DB *sql.DB, ...) { ... } - pattern-not: $DB.$METHOD(..., "..." + "...", ...) - metavariable-regex: metavariable: $METHOD regex: ^(Exec|ExecContent|Query|QueryContext|QueryRow|QueryRowContext)$ languages: - go message: Detected string concatenation with a non-literal variable in a "database/sql" Go SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' calls. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' references: - https://golang.org/pkg/database/sql/ category: security technology: - go confidence: LOW owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli shortlink: https://sg.run/YgOX semgrep.dev: rule: r_id: 10258 rv_id: 1262951 rule_id: YGUrnQ version_id: RGT0Lpr url: https://semgrep.dev/playground/r/RGT0Lpr/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli origin: community severity: ERROR - id: go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli patterns: - pattern-inside: | import ( ... "$IMPORT" ) ... - metavariable-regex: metavariable: $IMPORT regex: .*go-pg - pattern-either: - patterns: - pattern: $DB.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = fmt.Sprintf("...", $PARAM1, ...) ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern: | $DB.$INTFUNC1(...).$METHOD(..., $X + $Y, ...).$INTFUNC2(...) - pattern: | $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) - pattern-inside: | $DB = pg.Connect(...) ... - pattern-inside: | func $FUNCNAME(..., $DB *pg.DB, ...) { ... } - pattern-not-inside: | $QUERY = fmt.Sprintf("...", ...,"...", ...) ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not: $DB.$METHOD(...,"...",...) - pattern-not: | $DB.$INTFUNC1(...).$METHOD(..., "...", ...).$INTFUNC2(...) - pattern-not-inside: | $QUERY = "..." + "..." - pattern-not: | "..." - pattern-not: path.Join(...) - pattern-not: filepath.Join(...) - metavariable-regex: metavariable: $METHOD regex: ^(Where|WhereOr|Join|GroupExpr|OrderExpr|ColumnExpr)$ languages: - go message: Detected string concatenation with a non-literal variable in a go-pg ORM SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, do not use strings concatenated with user-controlled input. Instead, use parameterized statements. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' references: - https://pg.uptrace.dev/queries/ category: security technology: - go-pg confidence: LOW owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli shortlink: https://sg.run/6rA6 semgrep.dev: rule: r_id: 10259 rv_id: 1262952 rule_id: 6JUqQ1 version_id: A8Tgdqn url: https://semgrep.dev/playground/r/A8Tgdqn/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli origin: community severity: ERROR - id: go.lang.security.audit.sqli.pgx-sqli.pgx-sqli languages: - go message: 'Detected string concatenation with a non-literal variable in a pgx Go SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries instead. You can use parameterized queries like so: (`SELECT $1 FROM table`, `data1)' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' references: - https://github.com/jackc/pgx - https://pkg.go.dev/github.com/jackc/pgx/v4#hdr-Connection_Pool category: security technology: - pgx confidence: LOW owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli shortlink: https://sg.run/okKN semgrep.dev: rule: r_id: 10260 rv_id: 1262954 rule_id: oqUz92 version_id: DkTRbkL url: https://semgrep.dev/playground/r/DkTRbkL/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli origin: community patterns: - pattern-either: - patterns: - pattern: $DB.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = fmt.Sprintf("...", $PARAM1, ...) ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern: $DB.$METHOD(..., $X + $Y, ...) - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) - pattern-either: - pattern-inside: | $DB, ... = pgx.Connect(...) ... - pattern-inside: | $DB, ... = pgx.NewConnPool(...) ... - pattern-inside: | $DB, ... = pgx.ConnectConfig(...) ... - pattern-inside: | func $FUNCNAME(..., $DB *pgx.Conn, ...) { ... } - pattern-not: $DB.$METHOD(..., "..." + "...", ...) - metavariable-regex: metavariable: $METHOD regex: ^(Exec|ExecEx|Query|QueryEx|QueryRow|QueryRowEx)$ severity: ERROR - id: go.lang.security.audit.sqli.pg-sqli.pg-sqli languages: - go message: 'Detected string concatenation with a non-literal variable in a go-pg SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries instead of string concatenation. You can use parameterized queries like so: ''(SELECT ? FROM table, data1)''' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' references: - https://pg.uptrace.dev/ - https://pkg.go.dev/github.com/go-pg/pg/v10 category: security technology: - go-pg confidence: LOW owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-sqli.pg-sqli shortlink: https://sg.run/Al94 semgrep.dev: rule: r_id: 10294 rv_id: 1262953 rule_id: AbUWXY version_id: BjTkZbQ url: https://semgrep.dev/playground/r/BjTkZbQ/go.lang.security.audit.sqli.pg-sqli.pg-sqli origin: community severity: ERROR patterns: - pattern-either: - patterns: - pattern: | $DB.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = fmt.Sprintf("...", $PARAM1, ...) ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern: $DB.$METHOD(..., $X + $Y, ...) - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) - pattern-either: - pattern-inside: | $DB = pg.Connect(...) ... - pattern-inside: | func $FUNCNAME(..., $DB *pg.DB, ...) { ... } - pattern-not: $DB.$METHOD(..., "..." + "...", ...) - metavariable-regex: metavariable: $METHOD regex: ^(Exec|ExecContext|ExecOne|ExecOneContext|Query|QueryOne|QueryContext|QueryOneContext)$ - id: python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli languages: - python message: 'Detected string concatenation with a non-literal variable in an aiopg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries instead. You can create parameterized queries like so: ''cur.execute("SELECT %s FROM table", (user_value,))''.' metadata: references: - https://github.com/aio-libs/aiopg category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aiopg owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli shortlink: https://sg.run/WgGL semgrep.dev: rule: r_id: 10309 rv_id: 1263512 rule_id: DbUWRY version_id: GxTke3z url: https://semgrep.dev/playground/r/GxTke3z/python.lang.security.audit.sqli.aiopg-sqli.aiopg-sqli origin: community patterns: - pattern-either: - patterns: - pattern: $CUR.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = '...'.format(...) ... - pattern-inside: | $QUERY = '...' % (...) ... - pattern-inside: | $QUERY = f'...{$USERINPUT}...' ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern-not-inside: | $QUERY = '...'.format() ... - pattern-not-inside: | $QUERY = '...' % () ... - pattern: $CUR.$METHOD(..., $X + $Y, ...) - pattern: $CUR.$METHOD(..., '...'.format(...), ...) - pattern: $CUR.$METHOD(..., '...' % (...), ...) - pattern: $CUR.$METHOD(..., f'...{$USERINPUT}...', ...) - pattern-either: - pattern-inside: | $CONN = await aiopg.connect(...) ... $CUR = await $CONN.cursor(...) ... - pattern-inside: | $POOL = await aiopg.create_pool(...) ... async with $POOL.acquire(...) as $CONN: ... async with $CONN.cursor(...) as $CUR: ... - pattern-inside: | $POOL = await aiopg.create_pool(...) ... with (await $POOL.cursor(...)) as $CUR: ... - pattern-inside: | $POOL = await aiopg.create_pool(...) ... async with $POOL as $CONN: ... $CUR = await $CONN.cursor(...) ... - pattern-inside: | $POOL = await aiopg.create_pool(...) ... async with $POOL.cursor(...) as $CUR: ... - pattern-not: $CUR.$METHOD(..., "..." + "...", ...) - pattern-not: $CUR.$METHOD(..., '...'.format(), ...) - pattern-not: $CUR.$METHOD(..., '...'%(), ...) - metavariable-regex: metavariable: $METHOD regex: ^(execute)$ severity: WARNING - id: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli languages: - python message: 'Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: ''conn.fetch("SELECT $1 FROM table", value)''. You can also create prepared statements with ''Connection.prepare'': ''stmt = conn.prepare("SELECT $1 FROM table"); await stmt.fetch(user_value)''' metadata: references: - https://github.com/MagicStack/asyncpg - https://magicstack.github.io/asyncpg/current/ category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - asyncpg owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli shortlink: https://sg.run/0nBB semgrep.dev: rule: r_id: 10310 rv_id: 1263513 rule_id: WAUZqq version_id: RGT0L8K url: https://semgrep.dev/playground/r/RGT0L8K/python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli origin: community patterns: - pattern-either: - patterns: - pattern: $CONN.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = '...'.format(...) ... - pattern-inside: | $QUERY = '...' % (...) ... - pattern-inside: | $QUERY = f'...{$USERINPUT}...' ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern-not-inside: | $QUERY = '...'.format() ... - pattern-not-inside: | $QUERY = '...' % () ... - pattern: $CONN.$METHOD(..., $X + $Y, ...) - pattern: $CONN.$METHOD(..., $Y.format(...), ...) - pattern: $CONN.$METHOD(..., '...'.format(...), ...) - pattern: $CONN.$METHOD(..., '...' % (...), ...) - pattern: $CONN.$METHOD(..., f'...{$USERINPUT}...', ...) - pattern-either: - pattern-inside: | $CONN = await asyncpg.connect(...) ... - pattern-inside: | async with asyncpg.create_pool(...) as $CONN: ... - pattern-inside: | async with $POOL.acquire(...) as $CONN: ... - pattern-inside: | $CONN = await $POOL.acquire(...) ... - pattern-inside: | def $FUNCNAME(..., $CONN: Connection, ...): ... - pattern-inside: | def $FUNCNAME(..., $CONN: asyncpg.Connection, ...): ... - pattern-not: $CONN.$METHOD(..., "..." + "...", ...) - pattern-not: $CONN.$METHOD(..., '...'.format(), ...) - pattern-not: $CONN.$METHOD(..., '...'%(), ...) - metavariable-regex: metavariable: $METHOD regex: ^(fetch|fetchrow|fetchval|execute|executemany|prepare|cursor|copyfromquery)$ severity: WARNING - id: python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli languages: - python message: 'Detected string concatenation with a non-literal variable in a pg8000 Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: ''conn.run("SELECT :value FROM table", value=myvalue)''. You can also create prepared statements with ''conn.prepare'': ''conn.prepare("SELECT (:v) FROM table")''' metadata: references: - https://github.com/tlocke/pg8000 cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - pg8000 owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli shortlink: https://sg.run/KWAL semgrep.dev: rule: r_id: 10311 rv_id: 1263514 rule_id: 0oUEKo version_id: A8TgdKN url: https://semgrep.dev/playground/r/A8TgdKN/python.lang.security.audit.sqli.pg8000-sqli.pg8000-sqli origin: community patterns: - pattern-either: - patterns: - pattern: $CONN.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = '...'.format(...) ... - pattern-inside: | $QUERY = '...' % (...) ... - pattern-inside: | $QUERY = f'...{$USERINPUT}...' ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern-not-inside: | $QUERY = '...'.format() ... - pattern-not-inside: | $QUERY = '...' % () ... - pattern: $CONN.$METHOD(..., $X + $Y, ...) - pattern: $CONN.$METHOD(..., '...'.format(...), ...) - pattern: $CONN.$METHOD(..., '...' % (...), ...) - pattern: $CONN.$METHOD(..., f'...{$USERINPUT}...', ...) - pattern-either: - pattern-inside: | $CONN = pg8000.native.Connection(...) ... - pattern-inside: | $CONN = pg8000.dhapi.connect(...) ... - pattern-inside: | $CONN1 = pg8000.connect(...) ... $CONN = $CONN1.cursor(...) ... - pattern-inside: | $CONN = pg8000.connect(...) ... - pattern-not: $CONN.$METHOD(..., "..." + "...", ...) - pattern-not: $CONN.$METHOD(..., '...'.format(), ...) - pattern-not: $CONN.$METHOD(..., '...'%(), ...) - metavariable-regex: metavariable: $METHOD regex: ^(run|execute|executemany|prepare)$ severity: WARNING - id: python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli languages: - python message: 'Detected string concatenation with a non-literal variable in a psycopg2 Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use prepared statements by creating a ''sql.SQL'' string. You can also use the pyformat binding style to create parameterized queries. For example: ''cur.execute(SELECT * FROM table WHERE name=%s, user_input)''' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' references: - https://www.psycopg.org/docs/sql.html category: security technology: - psycopg owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli shortlink: https://sg.run/qrLe semgrep.dev: rule: r_id: 10312 rv_id: 1263515 rule_id: KxU4Kg version_id: BjTkZl1 url: https://semgrep.dev/playground/r/BjTkZl1/python.lang.security.audit.sqli.psycopg-sqli.psycopg-sqli origin: community patterns: - pattern-either: - patterns: - pattern: $CUR.$METHOD(...,$QUERY,...) - pattern-either: - pattern-inside: | $QUERY = $X + $Y ... - pattern-inside: | $QUERY += $X ... - pattern-inside: | $QUERY = '...'.format(...) ... - pattern-inside: | $QUERY = '...' % (...) ... - pattern-inside: | $QUERY = f'...{$USERINPUT}...' ... - pattern-not-inside: | $QUERY += "..." ... - pattern-not-inside: | $QUERY = "..." + "..." ... - pattern-not-inside: | $QUERY = '...'.format() ... - pattern-not-inside: | $QUERY = '...' % () ... - pattern: $CUR.$METHOD(..., $X + $Y, ...) - pattern: $CUR.$METHOD(..., '...'.format(...), ...) - pattern: $CUR.$METHOD(..., '...' % (...), ...) - pattern: $CUR.$METHOD(..., f'...{$USERINPUT}...', ...) - pattern-either: - pattern-inside: | $CONN = psycopg2.connect(...) ... $CUR = $CONN.cursor(...) ... - pattern-inside: | $CONN = psycopg2.connect(...) ... with $CONN.cursor(...) as $CUR: ... - pattern-not: $CUR.$METHOD(..., "..." + "...", ...) - pattern-not: $CUR.$METHOD(..., '...'.format(), ...) - pattern-not: $CUR.$METHOD(..., '...'%(), ...) - metavariable-regex: metavariable: $METHOD regex: ^(execute|executemany|mogrify)$ severity: WARNING - id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli mode: taint pattern-propagators: - pattern: $X << $Y from: $Y to: $X pattern-sources: - pattern-either: - pattern: | params - pattern: | cookies pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $CON = PG.connect(...) ... - pattern-inside: | $CON = PG::Connection.open(...) ... - pattern-inside: | $CON = PG::Connection.new(...) ... - pattern-either: - pattern: | $CON.$METHOD($X,...) - pattern: | $CON.$METHOD $X, ... - focus-metavariable: $X - metavariable-regex: metavariable: $METHOD regex: ^(exec|exec_params)$ languages: - ruby message: 'Detected string concatenation with a non-literal variable in a pg Ruby SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized queries like so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And you can use prepared statements with `exec_prepared`.' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://www.rubydoc.info/gems/pg/PG/Connection category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli shortlink: https://sg.run/kL0o semgrep.dev: rule: r_id: 10328 rv_id: 1263628 rule_id: NbUAz7 version_id: 2KTv2y2 url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli origin: community severity: WARNING - id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled pattern: management.endpoints.web.exposure.include=* message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless you have Spring Security enabled or another means to protect these endpoints, this functionality is available without authentication, causing a significant security risk. severity: ERROR languages: - generic paths: include: - '*properties' metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators category: security technology: - spring cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled shortlink: https://sg.run/L0vY semgrep.dev: rule: r_id: 10439 rv_id: 1263077 rule_id: EwU4vg version_id: xyTjzwp url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled origin: community - id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling patterns: - pattern-either: - pattern: | proxy_http_version 1.1 ...; ... proxy_set_header Upgrade ...; ... proxy_set_header Connection ...; - pattern: | proxy_set_header Upgrade ...; ... proxy_set_header Connection ...; ... proxy_http_version 1.1 ...; - pattern: | proxy_set_header Upgrade ...; ... proxy_http_version 1.1 ...; ... proxy_set_header Connection ...; - pattern-inside: | location ... { ... } languages: - generic severity: WARNING message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted HTTP traffic directly to back-end servers. To mitigate: WebSocket support required: Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket). WebSocket support not required: Do not forward Upgrade headers.' paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' metadata: cwe: - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' references: - https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c category: security technology: - nginx confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling shortlink: https://sg.run/ploZ semgrep.dev: rule: r_id: 10562 rv_id: 1262679 rule_id: 6JUq0Z version_id: nWT2Lyp url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling origin: community - id: python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query message: 'Avoiding SQL string concatenation: untrusted input concatenated with raw SQL query can result in SQL Injection. In order to execute raw query safely, prepared statement should be used. SQLAlchemy provides TextualSQL to easily used prepared statement with named parameters. For complex SQL composition, use SQL Expression Language or Schema Definition Language. In most cases, SQLAlchemy ORM will be a better option.' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column category: security technology: - sqlalchemy cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query shortlink: https://sg.run/2b1L semgrep.dev: rule: r_id: 10563 rv_id: 1263578 rule_id: oqUz5y version_id: bZT53rp url: https://semgrep.dev/playground/r/bZT53rp/python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query origin: community severity: ERROR languages: - python pattern-either: - pattern: | $CONNECTION.execute( $SQL + ..., ... ) - pattern: | $CONNECTION.execute( $SQL % (...), ...) - pattern: | $CONNECTION.execute( $SQL.format(...), ... ) - pattern: | $CONNECTION.execute(f"...{...}...", ...) - patterns: - pattern-inside: | $QUERY = $SQL + ... ... - pattern: | $CONNECTION.execute($QUERY, ...) - patterns: - pattern-inside: | $QUERY = $SQL % (...) ... - pattern: | $CONNECTION.execute($QUERY, ...) - patterns: - pattern-inside: | $QUERY = $SQL.format(...) ... - pattern: | $CONNECTION.execute($QUERY, ...) - patterns: - pattern-inside: | $QUERY = f"...{...}..." ... - pattern: | $CONNECTION.execute($QUERY, ...) - id: javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli message: 'Detected string concatenation with a non-literal variable in a node-postgres JS SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `client.query(''SELECT $1 from table'', [userinput])`' metadata: owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' references: - https://node-postgres.com/features/queries category: security technology: - node-postgres subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli shortlink: https://sg.run/0n3v semgrep.dev: rule: r_id: 10710 rv_id: 1263208 rule_id: ReUPN9 version_id: 5PTo1BA url: https://semgrep.dev/playground/r/5PTo1BA/javascript.lang.security.audit.sqli.node-postgres-sqli.node-postgres-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | function ... (...,$FUNC,...) { ... } - focus-metavariable: $FUNC - pattern-not-inside: | $F. ... .$SOURCE(...) pattern-sinks: - patterns: - pattern-either: - pattern-inside: | const { $CLIENT } = require('pg') ... - pattern-inside: | var { $CLIENT } = require('pg') ... - pattern-inside: | let { $CLIENT } = require('pg') ... - pattern-either: - pattern-inside: | $DB = new $CLIENT(...) ... - pattern-inside: | $NEWPOOL = new $CLIENT(...) ... $NEWPOOL.connect((..., $DB, ...) => { ... }) - pattern: $DB.query($QUERY,...) - focus-metavariable: $QUERY - id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide category: security technology: - .net confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization shortlink: https://sg.run/ZeXW semgrep.dev: rule: r_id: 11135 rv_id: 1262635 rule_id: bwUOjK version_id: nWT2LGp url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization origin: community message: The BinaryFormatter type is dangerous and is not recommended for data processing. Applications should stop using BinaryFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. BinaryFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization.Formatters.Binary; ... - pattern: | new BinaryFormatter(); - id: csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://github.com/mgholam/fastJSON#security-warning-update category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization shortlink: https://sg.run/nqnd semgrep.dev: rule: r_id: 11136 rv_id: 1262637 rule_id: NbUAwk version_id: 7ZTE3Wn url: https://semgrep.dev/playground/r/7ZTE3Wn/csharp.lang.security.insecure-deserialization.fast-json.insecure-fastjson-deserialization origin: community message: $type extension has the potential to be unsafe, so use it with common sense and known json sources and not public facing ones to be safe patterns: - pattern-inside: | using fastJSON; ... - pattern: | new JSONParameters { BadListTypeChecking = false } - id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization shortlink: https://sg.run/E5e5 semgrep.dev: rule: r_id: 11137 rv_id: 1262638 rule_id: kxURnR version_id: LjTkgPk url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization origin: community message: The FsPickler is dangerous and is not recommended for data processing. Default configuration tend to insecure deserialization vulnerability. patterns: - pattern-inside: | using MBrace.FsPickler.Json; ... - pattern: | FsPickler.CreateJsonSerializer(); - id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization shortlink: https://sg.run/70pG semgrep.dev: rule: r_id: 11138 rv_id: 1262641 rule_id: wdU87G version_id: QkTGqnA url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization origin: community message: The LosFormatter type is dangerous and is not recommended for data processing. Applications should stop using LosFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. LosFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Web.UI; ... - pattern: | new LosFormatter(); - id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization shortlink: https://sg.run/L0AX semgrep.dev: rule: r_id: 11139 rv_id: 1262642 rule_id: x8UW7x version_id: 3ZT4X6b url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization origin: community message: The NetDataContractSerializer type is dangerous and is not recommended for data processing. Applications should stop using NetDataContractSerializer as soon as possible, even if they believe the data they're processing to be trustworthy. NetDataContractSerializer is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization; ... - pattern: | new NetDataContractSerializer(); - id: csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization patterns: - pattern-either: - pattern: TypeNameHandling = TypeNameHandling.$TYPEHANDLER - pattern: | $SETTINGS.TypeNameHandling = TypeNameHandling.$TYPEHANDLER; ... JsonConvert.DeserializeObject<$TYPE>(...,$SETTINGS); - pattern: | $SETTINGS.TypeNameHandling = TypeNameHandling.$TYPEHANDLER; ... JsonConvert.DeserializeObject(...,$SETTINGS); - pattern-inside: | using Newtonsoft.Json; ... - metavariable-regex: metavariable: $TYPEHANDLER regex: (All|Auto|Objects|Arrays) message: TypeNameHandling $TYPEHANDLER is unsafe and can lead to arbitrary code execution in the context of the process. Use a custom SerializationBinder whenever using a setting other than TypeNameHandling.None. languages: - csharp severity: WARNING metadata: category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://www.newtonsoft.com/json/help/html/T_Newtonsoft_Json_TypeNameHandling.htm#remarks technology: - .net - newtonsoft - json confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization shortlink: https://sg.run/8n2g semgrep.dev: rule: r_id: 11140 rv_id: 1262643 rule_id: OrUGgl version_id: 44TEjgG url: https://semgrep.dev/playground/r/44TEjgG/csharp.lang.security.insecure-deserialization.newtonsoft.insecure-newtonsoft-deserialization origin: community - id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization shortlink: https://sg.run/gJnR semgrep.dev: rule: r_id: 11141 rv_id: 1262644 rule_id: eqUvND version_id: PkTR30n url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization origin: community message: The SoapFormatter type is dangerous and is not recommended for data processing. Applications should stop using SoapFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. SoapFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization.Formatters.Soap; ... - pattern: | new SoapFormatter(); - id: csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization severity: ERROR languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.web.script.serialization.simpletyperesolver?view=netframework-4.8#remarks category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization shortlink: https://sg.run/0nJq semgrep.dev: rule: r_id: 11198 rv_id: 1262640 rule_id: PeUkrK version_id: gETB7Jr url: https://semgrep.dev/playground/r/gETB7Jr/csharp.lang.security.insecure-deserialization.javascript-serializer.insecure-javascriptserializer-deserialization origin: community message: The SimpleTypeResolver class is insecure and should not be used. Using SimpleTypeResolver to deserialize JSON could allow the remote client to execute malicious code within the app and take control of the web server. patterns: - pattern-inside: | using System.Web.Script.Serialization; ... - pattern: | new JavaScriptSerializer((SimpleTypeResolver $RESOLVER)) - id: csharp.lang.security.injections.os-command.os-command-injection severity: ERROR languages: - csharp metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/Command_Injection category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/csharp.lang.security.injections.os-command.os-command-injection shortlink: https://sg.run/Ze6p semgrep.dev: rule: r_id: 11479 rv_id: 1262634 rule_id: 9AUOjg version_id: ZRTKAGe url: https://semgrep.dev/playground/r/ZRTKAGe/csharp.lang.security.injections.os-command.os-command-injection origin: community message: The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. patterns: - pattern-inside: | using System.Diagnostics; ... - pattern-inside: | public $T $F(..., $ARG, ...) { ... } - pattern-either: - patterns: - pattern: | Process.Start($ARG, ...); - focus-metavariable: $ARG - patterns: - pattern-inside: | Process $PROC = new Process(); ... - pattern-either: - pattern-inside: | $PROC.StartInfo.FileName = $ARG; ... - pattern-inside: | $PROC.StartInfo.Arguments = <... $ARG ...>; ... - pattern: | $PROC.Start(); - patterns: - patterns: - pattern-inside: | ProcessStartInfo $PSINFO = new ProcessStartInfo() { ... }; ... - pattern-either: - pattern-inside: | FileName = $ARG; ... - pattern-inside: | Arguments = <... $ARG ...>; ... - pattern: | Process.Start($PSINFO); - focus-metavariable: $PSINFO - patterns: - pattern-inside: | Process $PROC = new Process() { StartInfo = new ProcessStartInfo() { ... } }; ... - pattern-either: - pattern-inside: | FileName = $ARG; ... - pattern-inside: | Arguments = $ARG; ... - pattern: | $PROC.Start(); - id: generic.secrets.security.detected-github-token.detected-github-token patterns: - pattern-either: - pattern: | $VAR = $SECRET - pattern: | $VAR: $SECRET - pattern: | $VAR = '$SECRET' - pattern: | $VAR: '$SECRET' - pattern: | '$VAR' = '$SECRET' - pattern: | '$VAR': '$SECRET' - pattern: | "[hH][tT][tT][pP][sS]?://.*$SECRET.*" - metavariable-regex: metavariable: $SECRET regex: gh[pousr]_[A-Za-z0-9_]{36,251} - metavariable-analysis: analyzer: entropy metavariable: $SECRET languages: - generic message: GitHub Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.blog/changelog/2021-03-04-authentication-token-format-updates/ category: security technology: - secrets - github confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-github-token.detected-github-token shortlink: https://sg.run/PpOv semgrep.dev: rule: r_id: 11589 rv_id: 1262871 rule_id: eqUv7b version_id: bZT5397 url: https://semgrep.dev/playground/r/bZT5397/generic.secrets.security.detected-github-token.detected-github-token origin: community - id: trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil message: The `func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error` function does not handle `nil` argument, as the `ServerCodec` interface requires. An incorrect implementation could lead to denial of service languages: - go severity: WARNING metadata: category: security cwe: 'CWE-476: NULL Pointer Dereference' subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: LOW technology: - --no-technology-- description: Possible incorrect `ServerCodec` interface implementation references: - https://github.com/golang/go/blob/go1.15.2/src/net/rpc/server.go#L643-L658 license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil shortlink: https://sg.run/lx09 semgrep.dev: rule: r_id: 11757 rv_id: 833272 rule_id: QrUp7k version_id: yeTN1ek url: https://semgrep.dev/playground/r/yeTN1ek/trailofbits.go.servercodec-readrequestbody-unhandled-nil.servercodec-readrequestbody-unhandled-nil origin: community patterns: - pattern: | func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { ... } - pattern-not: | func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { ... if $ARG == nil { ... } ... } - pattern-not: | func ($O *$CODEC) ReadRequestBody($ARG $TYPE) error { ... if $ARG != nil { ... } ... } - id: trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast message: Downcasting or changing sign of an integer with `$CAST_METHOD` method languages: - go severity: WARNING metadata: category: security cwe: 'CWE-681: Incorrect Conversion between Numeric Types' subcategory: - audit confidence: HIGH likelihood: LOW impact: MEDIUM technology: - --no-technology-- description: Integer underflows references: - https://github.com/golang/go/issues/30209 license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast shortlink: https://sg.run/65WB semgrep.dev: rule: r_id: 11759 rv_id: 833273 rule_id: 4bU2AZ version_id: rxTDzNy url: https://semgrep.dev/playground/r/rxTDzNy/trailofbits.go.string-to-int-signedness-cast.string-to-int-signedness-cast origin: community pattern-either: - patterns: - metavariable-pattern: metavariable: $CAST_METHOD pattern-either: - pattern: uint8 - pattern: uint16 - pattern: uint32 - pattern: int8 - pattern: int16 - pattern: int32 - pattern-either: - pattern: | $X, ... = strconv.Atoi(...) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseInt(..., ..., 64) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 64) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.Atoi(...) ... uint64($X) - pattern: | $X, ... = strconv.ParseInt(..., ..., 64) ... uint64($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 64) ... int64($X) - patterns: - metavariable-pattern: metavariable: $CAST_METHOD pattern-either: - pattern: uint8 - pattern: uint16 - pattern: int8 - pattern: int16 - pattern-either: - pattern: | $X, ... = strconv.ParseInt(..., ..., 32) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 32) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseInt(..., ..., 32) ... uint32($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 32) ... int32($X) - patterns: - metavariable-pattern: metavariable: $CAST_METHOD pattern-either: - pattern: uint8 - pattern: int8 - pattern-either: - pattern: | $X, ... = strconv.ParseInt(..., ..., 16) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 16) ... $CAST_METHOD($X) - pattern: | $X, ... = strconv.ParseInt(..., ..., 16) ... uint16($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 16) ... int16($X) - pattern: | $X, ... = strconv.ParseInt(..., ..., 8) ... uint8($X) - pattern: | $X, ... = strconv.ParseUint(..., ..., 8) ... int8($X) - id: trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied message: A `sync.Mutex` is copied in function `$FUNC` given that `$T` is value receiver. As a result, the struct `$T` may not be locked as intended languages: - go severity: ERROR metadata: category: security cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' subcategory: - vuln confidence: HIGH likelihood: HIGH impact: LOW technology: - --no-technology-- description: Copying of `sync.Mutex` via value receivers references: - https://go101.org/article/concurrent-common-mistakes.html license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied shortlink: https://sg.run/owlR semgrep.dev: rule: r_id: 11760 rv_id: 833274 rule_id: PeUBW1 version_id: bZTBelR url: https://semgrep.dev/playground/r/bZTBelR/trailofbits.go.sync-mutex-value-copied.sync-mutex-value-copied origin: community patterns: - pattern-either: - pattern: | func ($T $TYPE) $FUNC(...){ ... $T.Lock() ... } - pattern: | func ($T $TYPE) $FUNC(...){ ... $T.RLock() ... } - pattern-not: | func ($T2 *$TYPE2) $FUNC(...){ ... } - id: trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine message: | Calling `$WG.Add` inside of an anonymous goroutine may result in `$WG.Wait` waiting for more or less calls to `$WG.Done()` than expected languages: - go severity: ERROR metadata: category: security cwe: 'CWE-667: Improper Locking' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM technology: - --no-technology-- description: Calls to `sync.WaitGroup.Add` inside of anonymous goroutines references: - https://go101.org/article/concurrent-common-mistakes.html license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine shortlink: https://sg.run/z98W semgrep.dev: rule: r_id: 11761 rv_id: 833276 rule_id: JDUQ3v version_id: kbT2l5k url: https://semgrep.dev/playground/r/kbT2l5k/trailofbits.go.waitgroup-add-called-inside-goroutine.waitgroup-add-called-inside-goroutine origin: community patterns: - pattern-either: - pattern: | $WG := &sync.WaitGroup{} ... go func(...) { ... $WG.Add(...) ... }(...) ... $WG.Wait() - pattern: | var $WG sync.WaitGroup ... go func(...) { ... $WG.Add(...) ... }(...) ... $WG.Wait() - pattern-not-inside: | for ... { ... $WG.Add(...) ... } - id: trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop message: Calling `$WG.Wait()` inside a loop blocks the call to `$WG.Done()` languages: - go severity: WARNING metadata: category: security cwe: 'CWE-667: Improper Locking' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM technology: - --no-technology-- description: Calls to `sync.WaitGroup.Wait` inside a loop references: - https://go101.org/article/concurrent-common-mistakes.html license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop shortlink: https://sg.run/pkGL semgrep.dev: rule: r_id: 11762 rv_id: 833277 rule_id: 5rU8Po version_id: w8TAx58 url: https://semgrep.dev/playground/r/w8TAx58/trailofbits.go.waitgroup-wait-inside-loop.waitgroup-wait-inside-loop origin: community patterns: - pattern-either: - pattern: | var $WG sync.WaitGroup ... for ... { ... go func(...){ ... defer $WG.Done() ... }() ... $WG.Wait() ... } - pattern: | $WG := &sync.WaitGroup{} ... for ... { ... go func(...){ ... defer $WG.Done() ... }() ... $WG.Wait() ... } - pattern: | var $WG sync.WaitGroup ... for ... { ... go func(...){ ... $WG.Done() ... }() ... $WG.Wait() ... } - pattern: | $WG := &sync.WaitGroup{} ... for ... { ... go func(...){ ... $WG.Done() ... }() ... $WG.Wait() ... } - id: trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal message: Possible path traversal through `tarfile.open($PATH).extractall()` if the source tar is controlled by an attacker languages: - python severity: ERROR metadata: category: security cwe: 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM technology: - --no-technology-- description: Potential path traversal in call to `extractall` for a `tarfile` references: - https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall license: AGPL-3.0 license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal shortlink: https://sg.run/2RLD semgrep.dev: rule: r_id: 11763 rv_id: 833310 rule_id: GdUZxq version_id: pZTXjAW url: https://semgrep.dev/playground/r/pZTXjAW/trailofbits.python.tarfile-extractall-traversal.tarfile-extractall-traversal origin: community patterns: - pattern-either: - pattern: | with tarfile.open(...) as $TAR: ... $TAR.extractall(...) - pattern: | tarfile.open(...).extractall(...) - pattern: | $TAR = tarfile.open(...) ... $TAR.extractall(...) - pattern-not: | with tarfile.open(...) as $TAR: ... $TAR.extractall(..., members=$MEMBERS, ...) - pattern-not: | tarfile.open(...).extractall(..., members=$MEMBERS, ...) - pattern-not: | $TAR = tarfile.open(...) ... $TAR.extractall(..., members=$MEMBERS, ...) - id: trailofbits.go.racy-append-to-slice.racy-append-to-slice message: Appending `$SLICE` from multiple goroutines is not concurrency safe languages: - go severity: ERROR metadata: category: security cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (''Race Condition'')' subcategory: - vuln confidence: MEDIUM likelihood: HIGH impact: MEDIUM technology: - --no-technology-- description: Concurrent calls to `append` from multiple goroutines references: - https://go.dev/blog/maps#concurrency license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.racy-append-to-slice.racy-append-to-slice shortlink: https://sg.run/jkNY semgrep.dev: rule: r_id: 11865 rv_id: 833270 rule_id: ReUoP7 version_id: 1QTPL3x url: https://semgrep.dev/playground/r/1QTPL3x/trailofbits.go.racy-append-to-slice.racy-append-to-slice origin: community patterns: - pattern: | $SLICE = append($SLICE, $ITEM) - pattern-either: - pattern-inside: | var $SLICE []$TYPE ... for ... { ... go func(...) { ... $SLICE = append($SLICE, ...) ... }(...) ... } - pattern-inside: | $SLICE := make([]$TYPE, ...) ... for ... { ... go func(...) { ... $SLICE = append($SLICE, ...) ... }(...) ... } - pattern-not-inside: | $MUTEX.Lock() ... $MUTEX.Unlock() - pattern-not-inside: | $MUTEX.Lock() ... defer $MUTEX.Unlock() ... - id: trailofbits.go.racy-write-to-map.racy-write-to-map message: Writing `$MAP` from multiple goroutines is not concurrency safe languages: - go severity: ERROR metadata: category: security cwe: 'CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (''Race Condition'')' subcategory: - vuln confidence: MEDIUM likelihood: HIGH impact: MEDIUM technology: - --no-technology-- description: Concurrent writes to the same map in multiple goroutines references: - https://go.dev/blog/maps#concurrency license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.racy-write-to-map.racy-write-to-map shortlink: https://sg.run/1Gnw semgrep.dev: rule: r_id: 11866 rv_id: 833271 rule_id: AbUGWD version_id: 9lTJ0qD url: https://semgrep.dev/playground/r/9lTJ0qD/trailofbits.go.racy-write-to-map.racy-write-to-map origin: community patterns: - pattern: | $MAP[$KEY] = $VALUE - pattern-inside: | $MAP = make(map[$KTYPE]$VTYPE) ... for ... { ... go func(...) { ... $MAP[$KEY] = $VALUE ... }(...) ... } - pattern-not-inside: | $MUTEX.Lock() ... $MUTEX.Unlock() - pattern-not-inside: | $MUTEX.Lock() ... defer $MUTEX.Unlock() ... - id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse metadata: functional-categories: - crypto::search::randomness::javax.crypto cwe: - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' category: security source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM technology: - java owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse shortlink: https://sg.run/Dww2 semgrep.dev: rule: r_id: 11908 rv_id: 1263000 rule_id: GdUZZ3 version_id: 0bTKzGk url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse origin: community languages: - java message: 'GCM IV/nonce is reused: encryption can be totally useless' patterns: - pattern-either: - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., $NONCE, ...); severity: ERROR - id: java.lang.security.audit.java-reverse-shell.java-reverse-shell patterns: - pattern-either: - pattern: | Socket $S=new Socket(...); ... InputStream $SI = $S.getInputStream(); ... while(!$S.isClosed()) { ... while($SI.available()>0)$PO.write($SI.read()); ... $SO.flush(); ... } - pattern-inside: | Process $P=new ProcessBuilder(...).redirectErrorStream(true).start(); ... $P.destroy(); message: Semgrep found potential reverse shell behavior severity: WARNING metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' category: security technology: - java owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.lang.security.audit.java-reverse-shell.java-reverse-shell shortlink: https://sg.run/kkrX semgrep.dev: rule: r_id: 11928 rv_id: 1263025 rule_id: KxUY7b version_id: 1QTyp3Z url: https://semgrep.dev/playground/r/1QTyp3Z/java.lang.security.audit.java-reverse-shell.java-reverse-shell origin: community languages: - java - id: typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard message: 'Unescaped ''.'' character in CORS domain regex $CORS: $PATTERN' metadata: cwe: - 'CWE-183: Permissive List of Allowed Inputs' category: security technology: - cors owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard shortlink: https://sg.run/w13x semgrep.dev: rule: r_id: 11929 rv_id: 1263908 rule_id: qNUbXo version_id: WrTqKwN url: https://semgrep.dev/playground/r/WrTqKwN/typescript.lang.security.audit.cors-regex-wildcard.cors-regex-wildcard origin: community languages: - ts severity: WARNING patterns: - pattern-either: - pattern: $CORS = [...,/$PATTERN/,...] - pattern: $CORS = /$PATTERN/ - focus-metavariable: $PATTERN - metavariable-regex: metavariable: $PATTERN regex: .+?(?, ...) - pattern: format_html("..." % ..., ...) - pattern: format_html("...".format(...), ...) - id: python.pymongo.security.mongodb.mongo-client-bad-auth pattern: | pymongo.MongoClient(..., authMechanism='MONGODB-CR') message: Warning MONGODB-CR was deprecated with the release of MongoDB 3.6 and is no longer supported by MongoDB 4.0 (see https://api.mongodb.com/python/current/examples/authentication.html for details). fix-regex: regex: MONGODB-CR replacement: SCRAM-SHA-256 severity: WARNING languages: - python metadata: cwe: - 'CWE-477: Use of Obsolete Function' category: security technology: - pymongo references: - https://cwe.mitre.org/data/definitions/477.html subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/python.pymongo.security.mongodb.mongo-client-bad-auth shortlink: https://sg.run/YXRd semgrep.dev: rule: r_id: 12658 rv_id: 946422 rule_id: d8UlOX version_id: 0bT15XY url: https://semgrep.dev/playground/r/0bT15XY/python.pymongo.security.mongodb.mongo-client-bad-auth origin: community - id: java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor languages: - java metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://securitylab.github.com/research/swagger-yaml-parser-vulnerability/#snakeyaml-deserialization-vulnerability category: security technology: - snakeyaml cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor shortlink: https://sg.run/L8qY semgrep.dev: rule: r_id: 12683 rv_id: 1263067 rule_id: 6JU67x version_id: X0Tzynw url: https://semgrep.dev/playground/r/X0Tzynw/java.lang.security.use-snakeyaml-constructor.use-snakeyaml-constructor origin: community message: Used SnakeYAML org.yaml.snakeyaml.Yaml() constructor with no arguments, which is vulnerable to deserialization attacks. Use the one-argument Yaml(...) constructor instead, with SafeConstructor or a custom Constructor as the argument. patterns: - pattern: | $Y = new org.yaml.snakeyaml.Yaml(); ... $Y.load(...); severity: WARNING - id: javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp message: RegExp() called with a `$ARG` function argument, this might allow an attacker to cause a Regular Expression Denial-of-Service (ReDoS) within your application as RegExP blocks the main thread. For this reason, it is recommended to use hardcoded regexes instead. If your regex is run on user-controlled input, consider performing input validation or use a regex checking/sanitization library such as https://www.npmjs.com/package/recheck to verify that the regex does not appear vulnerable to ReDoS. metadata: owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-non-literal-regexp.js category: security technology: - javascript subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp shortlink: https://sg.run/gr65 semgrep.dev: rule: r_id: 12685 rv_id: 1263195 rule_id: zdU1gD version_id: 5PTo1Yn url: https://semgrep.dev/playground/r/5PTo1Yn/javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | function ... (...,$ARG,...) {...} - focus-metavariable: $ARG pattern-sinks: - patterns: - pattern-either: - pattern: new RegExp($ARG, ...) - pattern: RegExp($ARG, ...) - pattern-not: RegExp("...", ...) - pattern-not: new RegExp("...", ...) - pattern-not: RegExp(/.../, ...) - pattern-not: new RegExp(/.../, ...) - id: ocaml.lang.portability.crlf-support.broken-input-line pattern: | input_line message: '''input_line'' leaves a ''\r'' (CR) character when reading lines from a Windows text file, whose lines end in "\r\n" (CRLF). This is a problem for any Windows file that is being read either on a Unix-like platform or on Windows in binary mode. If the code already takes care of removing any trailing ''\r'' after reading the line, add a ''(* nosemgrep *)'' comment to disable this warning.' languages: - ocaml severity: WARNING metadata: category: portability technology: - ocaml license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.broken-input-line shortlink: https://sg.run/v2gY semgrep.dev: rule: r_id: 12777 rv_id: 945971 rule_id: DbUKZX version_id: BjT1Ngb url: https://semgrep.dev/playground/r/BjT1Ngb/ocaml.lang.portability.crlf-support.broken-input-line origin: community - id: ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode pattern: open_in fix: open_in_bin message: '''open_in'' behaves differently on Windows and on Unix-like systems with respect to line endings. To get the same behavior everywhere, use ''open_in_bin'' or ''open_in_gen [Open_binary]''. If you really want CRLF-to-LF translations to take place when running on Windows, use ''open_in_gen [Open_text]''.' languages: - ocaml severity: WARNING metadata: category: portability technology: - ocaml license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode shortlink: https://sg.run/d0YE semgrep.dev: rule: r_id: 12778 rv_id: 945972 rule_id: WAUPAJ version_id: DkTNpPw url: https://semgrep.dev/playground/r/DkTNpPw/ocaml.lang.portability.crlf-support.prefer-read-in-binary-mode origin: community - id: ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode pattern: open_out fix: open_out_bin message: '''open_out'' behaves differently on Windows and on Unix-like systems with respect to line endings. To get the same behavior everywhere, use ''open_out_bin'' or ''open_out_gen [Open_binary]''. If you really want LF-to-CRLF translations to take place when running on Windows, use ''open_out_gen [Open_text]''.' languages: - ocaml severity: WARNING metadata: category: portability technology: - ocaml license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode shortlink: https://sg.run/ZkGw semgrep.dev: rule: r_id: 12779 rv_id: 945973 rule_id: 0oUJY9 version_id: WrTEoXG url: https://semgrep.dev/playground/r/WrTEoXG/ocaml.lang.portability.crlf-support.prefer-write-in-binary-mode origin: community - id: ocaml.lang.portability.slash-tmp.not-portable-tmp-string pattern: | "=~/\/tmp/" message: You should probably use Filename.get_temp_dirname(). languages: - ocaml severity: WARNING metadata: category: portability technology: - ocaml license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ocaml.lang.portability.slash-tmp.not-portable-tmp-string shortlink: https://sg.run/Q4ZZ semgrep.dev: rule: r_id: 12786 rv_id: 945974 rule_id: zdU100 version_id: 0bT158q url: https://semgrep.dev/playground/r/0bT158q/ocaml.lang.portability.slash-tmp.not-portable-tmp-string origin: community - id: javascript.express.security.express-data-exfiltration.express-data-exfiltration message: Depending on the context, user control data in `Object.assign` can cause web response to include data that it should not have or can lead to a mass assignment vulnerability. metadata: owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' references: - https://en.wikipedia.org/wiki/Mass_assignment_vulnerability - https://cheatsheetseries.owasp.org/cheatsheets/Mass_Assignment_Cheat_Sheet.html category: security technology: - express subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/javascript.express.security.express-data-exfiltration.express-data-exfiltration shortlink: https://sg.run/pkpL semgrep.dev: rule: r_id: 12818 rv_id: 1263163 rule_id: ReUo60 version_id: 6xT290x url: https://semgrep.dev/playground/r/6xT290x/javascript.express.security.express-data-exfiltration.express-data-exfiltration origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - pattern: Object.assign(...) - id: javascript.lang.security.insecure-object-assign.insecure-object-assign message: Depending on the context, user control data in `Object.assign` can cause web response to include data that it should not have or can lead to a mass assignment vulnerability. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Mass_Assignment_Cheat_Sheet.html - https://en.wikipedia.org/wiki/Mass_assignment_vulnerability category: security technology: - javascript subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/javascript.lang.security.insecure-object-assign.insecure-object-assign shortlink: https://sg.run/2R0D semgrep.dev: rule: r_id: 12819 rv_id: 1263219 rule_id: AbUGOq version_id: YDTZezg url: https://semgrep.dev/playground/r/YDTZezg/javascript.lang.security.insecure-object-assign.insecure-object-assign origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern: JSON.parse(...) - pattern-not: JSON.parse("...",...) pattern-sinks: - pattern: Object.assign(...) - id: javascript.express.security.express-vm-injection.express-vm-injection message: Make sure that unverified user data can not reach `$VM`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection shortlink: https://sg.run/jkqJ semgrep.dev: rule: r_id: 12821 rv_id: 1263170 rule_id: DbUKPX version_id: 1QTypXQ url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | $VM = require('vm'); ... - pattern-either: - pattern: | $VM.runInContext(...) - pattern: | $VM.runInNewContext(...) - pattern: | $VM.compileFunction(...) - pattern: | $VM.runInThisContext(...) - pattern: new $VM.Script(...) - id: javascript.express.security.express-vm2-injection.express-vm2-injection message: Make sure that unverified user data can not reach `vm2`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection shortlink: https://sg.run/1GWv semgrep.dev: rule: r_id: 12822 rv_id: 1263171 rule_id: WAUPXJ version_id: 9lT4bnX url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | require('vm2') ... - pattern-either: - patterns: - pattern-either: - pattern-inside: | $VM = new VM(...) ... - pattern-inside: | $VM = new NodeVM(...) ... - pattern: | $VM.run(...) - pattern: | new VM(...).run(...) - pattern: | new NodeVM(...).run(...) - pattern: | new VMScript(...) - pattern: | new VM(...) - pattern: new NodeVM(...) - id: generic.secrets.security.detected-jwt-token.detected-jwt-token pattern-regex: eyJ[A-Za-z0-9-_=]{14,}\.[A-Za-z0-9-_=]{13,}\.?[A-Za-z0-9-_.+/=]*? languages: - regex message: JWT token detected severity: ERROR metadata: source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/jwt.py category: security technology: - secrets - jwt confidence: LOW references: - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ cwe: - 'CWE-321: Use of Hard-coded Cryptographic Key' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/generic.secrets.security.detected-jwt-token.detected-jwt-token shortlink: https://sg.run/05N5 semgrep.dev: rule: r_id: 12854 rv_id: 1262879 rule_id: kxU8E8 version_id: d6Tyxvg url: https://semgrep.dev/playground/r/d6Tyxvg/generic.secrets.security.detected-jwt-token.detected-jwt-token origin: community - id: generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key pattern-regex: SG\.[a-zA-Z0-9]{22}\.[a-zA-Z0-9-]{43}\b languages: - regex message: SendGrid API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/narendrakadali/gitrob/blob/master/rules/contentsignatures.json category: security technology: - secrets - sendgrid confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key shortlink: https://sg.run/qqOy semgrep.dev: rule: r_id: 12856 rv_id: 1262890 rule_id: x8U2EG version_id: PkTR3RD url: https://semgrep.dev/playground/r/PkTR3RD/generic.secrets.security.detected-sendgrid-api-key.detected-sendgrid-api-key origin: community - id: generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key pattern-regex: (?i)snyk.{0,50}['|"|`]?[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}['"\s]? languages: - regex message: Snyk API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets - snyk confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key shortlink: https://sg.run/lxO9 semgrep.dev: rule: r_id: 12857 rv_id: 1262893 rule_id: OrUD9J version_id: GxTkek0 url: https://semgrep.dev/playground/r/GxTkek0/generic.secrets.security.detected-snyk-api-key.detected-snyk-api-key origin: community - id: generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key pattern-regex: (?i)softlayer.{0,50}["|'|`]?[a-z0-9]{64}["|'|`]? languages: - regex message: SoftLayer API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/Yelp/detect-secrets/blob/master/detect_secrets/plugins/softlayer.py category: security technology: - secrets - softlayer confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key shortlink: https://sg.run/YXq4 semgrep.dev: rule: r_id: 12858 rv_id: 1262894 rule_id: eqUplZ version_id: RGT0L0o url: https://semgrep.dev/playground/r/RGT0L0o/generic.secrets.security.detected-softlayer-api-key.detected-softlayer-api-key origin: community - id: javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf message: User-controllable argument $DATAVAL to $METHOD passed to Axios via internal handler $INNERFUNC. This could be a server-side request forgery. A user could call a restricted API or leak internal headers to an unauthorized party. Validate your user arguments against an allowlist of known URLs, or consider refactoring so that user-controlled data is not necessary. metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - apollo - axios references: - https://www.cvedetails.com/cve/CVE-2020-28168/ - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf shortlink: https://sg.run/jkEZ semgrep.dev: rule: r_id: 13021 rv_id: 1263102 rule_id: AbUGBR version_id: K3TKk30 url: https://semgrep.dev/playground/r/K3TKk30/javascript.apollo.security.apollo-axios-ssrf.apollo-axios-ssrf origin: community languages: - javascript severity: WARNING patterns: - pattern: const $RESPONSE = await axios.request($INNERARG,...) - pattern-inside: | Query: { $METHOD(parent, args, context, info) { ... $DATA = args.$DATAVAL ... async function $INNERFUNC(...,$INNERARG,...){ ... } ... return $INNERFUNC(...,$DATA,...) } } - id: javascript.lang.security.audit.code-string-concat.code-string-concat message: Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible. options: interfile: true metadata: interfile: true confidence: HIGH owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' references: - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html category: security technology: - node.js - Express - Next.js subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat shortlink: https://sg.run/96Yk semgrep.dev: rule: r_id: 13023 rv_id: 1263192 rule_id: DbUKEz version_id: 44TEjYX url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - pattern-either: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | import { ...,$IMPORT,... } from 'next/router' ... - pattern-inside: | import $IMPORT from 'next/router'; ... - pattern-either: - patterns: - pattern-inside: | $ROUTER = $IMPORT() ... - pattern-either: - pattern-inside: | const { ...,$PROPS,... } = $ROUTER.query ... - pattern-inside: | var { ...,$PROPS,... } = $ROUTER.query ... - pattern-inside: | let { ...,$PROPS,... } = $ROUTER.query ... - focus-metavariable: $PROPS - patterns: - pattern-inside: | $ROUTER = $IMPORT() ... - pattern: "$ROUTER.query.$VALUE \n" - patterns: - pattern: $IMPORT().query.$VALUE pattern-sinks: - patterns: - pattern: | eval(...) - id: yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled languages: - yaml severity: WARNING message: Do not set FLASK_ENV to "development" since that sets `debug=True` in Flask. Use "dev" or a similar term instead. metadata: owasp: A06:2017 - Security Misconfiguration cwe: - 'CWE-489: Active Debug Code' references: - https://flask.palletsprojects.com/en/2.0.x/debugging/ - https://flask.palletsprojects.com/en/2.0.x/config/#ENV category: security technology: - kubernetes - flask subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled shortlink: https://sg.run/y6x8 semgrep.dev: rule: r_id: 13024 rv_id: 947053 rule_id: WAUP0z version_id: ZRT3qOw url: https://semgrep.dev/playground/r/ZRT3qOw/yaml.kubernetes.security.env.flask-debugging-enabled.flask-debugging-enabled origin: community patterns: - pattern-inside: | env: [...] - pattern: | {name: FLASK_ENV, value: "development"} fix-regex: regex: development replacement: dev - id: javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli message: 'Detected string concatenation with a non-literal variable in a `mssql` JS SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `$REQ.input(''USER_ID'', mssql.Int, id);`' metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - mssql references: - https://www.npmjs.com/package/mssql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli shortlink: https://sg.run/lxlB semgrep.dev: rule: r_id: 13157 rv_id: 1263206 rule_id: kxU8Pd version_id: YDTZezY url: https://semgrep.dev/playground/r/YDTZezY/javascript.lang.security.audit.sqli.node-mssql-sqli.node-mssql-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | function ... (...,$FUNC,...) { ... } - focus-metavariable: $FUNC pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('mssql'); ... - pattern-inside: | import 'mssql'; ... - pattern-inside: | $REQ = $POOL.request(...) ... - pattern: | $REQ.query($QUERY,...) - focus-metavariable: $QUERY - id: yaml.github-actions.security.run-shell-injection.run-shell-injection languages: - yaml message: 'Using variable interpolation `${{...}}` with `github` context data in a `run:` step could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment variable, like this: "$ENVVAR".' metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections - https://securitylab.github.com/research/github-actions-untrusted-input/ technology: - github-actions cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection shortlink: https://sg.run/pkzk semgrep.dev: rule: r_id: 13162 rv_id: 1423395 rule_id: v8UjQj version_id: GxTl1DQ url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ ... github.event.issue.title ... }} - pattern: ${{ ... github.event.issue.body ... }} - pattern: ${{ ... github.event.pull_request.title ... }} - pattern: ${{ ... github.event.pull_request.body ... }} - pattern: ${{ ... github.event.comment.body ... }} - pattern: ${{ ... github.event.review.body ... }} - pattern: ${{ ... github.event.review_comment.body ... }} - pattern: ${{ ... github.event.pages ... .page_name ... }} - pattern: ${{ ... github.event.head_commit.message ... }} - pattern: ${{ ... github.event.head_commit.author.email ... }} - pattern: ${{ ... github.event.head_commit.author.name ... }} - pattern: ${{ ... github.event.commits ... .author.email ... }} - pattern: ${{ ... github.event.commits ... .author.name ... }} - pattern: ${{ ... github.event.commits ... .message ... }} - pattern: ${{ ... github.event.pull_request.head.ref ... }} - pattern: ${{ ... github.event.pull_request.head.label ... }} - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} - pattern: ${{ ... github.ref ... }} - pattern: ${{ ... github.base_ref ... }} - pattern: ${{ ... github.head_ref ... }} - pattern: ${{ ... github.ref_name ... }} - pattern: ${{ ... github.workflow ... }} - pattern: ${{ ... github.event.inputs ... }} - pattern: ${{ ... github.event.discussion.title ... }} - pattern: ${{ ... github.event.discussion.body ... }} - pattern: ${{ ... github.event.workflow_run.head_branch ... }} - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} - pattern: ${{ ... github.event.milestone.title ... }} - pattern: ${{ ... github.event.milestone.description ... }} - pattern: ${{ ... github.event.project_card.note ... }} - pattern: ${{ ... github.event.project.name ... }} - pattern: ${{ ... github.event.project_column.name ... }} - pattern: ${{ ... github.event.release.name ... }} - pattern: ${{ ... github.event.release.body ... }} - pattern: ${{ ... github.event.deployment.ref ... }} - pattern: ${{ ... inputs ... }} - pattern-not: ${{ ... github.event.issue.title && ... }} - pattern-not: ${{ ... github.event.issue.body && ... }} - pattern-not: ${{ ... github.event.pull_request.title && ... }} - pattern-not: ${{ ... github.event.pull_request.body && ... }} - pattern-not: ${{ ... github.event.comment.body && ... }} - pattern-not: ${{ ... github.event.review.body && ... }} - pattern-not: ${{ ... github.event.review_comment.body && ... }} - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} - pattern-not: ${{ ... github.event.head_commit.message && ... }} - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .message && ... }} - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} - pattern-not: ${{ ... github.ref && ... }} - pattern-not: ${{ ... github.base_ref && ... }} - pattern-not: ${{ ... github.head_ref && ... }} - pattern-not: ${{ ... github.ref_name && ... }} - pattern-not: ${{ ... github.workflow && ... }} - pattern-not: ${{ ... github.event.inputs && ... }} - pattern-not: ${{ ... github.event.discussion.title && ... }} - pattern-not: ${{ ... github.event.discussion.body && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} - pattern-not: ${{ ... github.event.milestone.title && ... }} - pattern-not: ${{ ... github.event.milestone.description && ... }} - pattern-not: ${{ ... github.event.project_card.note && ... }} - pattern-not: ${{ ... github.event.project.name && ... }} - pattern-not: ${{ ... github.event.project_column.name && ... }} - pattern-not: ${{ ... github.event.release.name && ... }} - pattern-not: ${{ ... github.event.release.body && ... }} - pattern-not: ${{ ... github.event.deployment.ref && ... }} severity: ERROR - id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout languages: - yaml message: This GitHub Actions workflow file uses `pull_request_target` and checks out code from the incoming pull request. When using `pull_request_target`, the Action runs in the context of the target repository, which includes access to all repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. metadata: category: security owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software and Data Integrity Failures cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' references: - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout shortlink: https://sg.run/jkdn semgrep.dev: rule: r_id: 13365 rv_id: 1413423 rule_id: d8Ulkd version_id: O9TQ2nX url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout origin: community patterns: - pattern-either: - pattern-inside: | on: ... pull_request_target: ... ... ... - pattern-inside: | on: [..., pull_request_target, ...] ... - pattern-inside: | on: pull_request_target ... - pattern-inside: | jobs: ... $JOBNAME: ... steps: ... - pattern: | ... uses: "$ACTION" with: ... ref: $EXPR - metavariable-regex: metavariable: $ACTION regex: actions/checkout@.* - metavariable-pattern: language: generic metavariable: $EXPR patterns: - pattern-inside: ${{ ... }} - pattern-either: - pattern: github.event.pull_request ... - pattern: github.head_ref ... severity: ERROR - id: javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop message: 'Possibility of prototype polluting function detected. By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the software depends on existence or non-existence of certain attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, toString or valueOf). Possible mitigations might be: freezing the object prototype, using an object without prototypes (via Object.create(null) ), blocking modifications of attributes that resolve to object prototype, using Map instead of object.' metadata: cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' category: security references: - https://github.com/HoLyVieR/prototype-pollution-nsec18/blob/master/paper/JavaScript_prototype_pollution_attack_in_NodeJS.pdf technology: - typescript owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop shortlink: https://sg.run/w1DB semgrep.dev: rule: r_id: 13373 rv_id: 1263203 rule_id: QrUpbJ version_id: K3TKkP7 url: https://semgrep.dev/playground/r/K3TKkP7/javascript.lang.security.audit.prototype-pollution.prototype-pollution-loop.prototype-pollution-loop origin: community languages: - typescript - javascript severity: WARNING patterns: - pattern-either: - pattern: | $SMTH = $SMTH[$A] - pattern: | $SMTH = $SMTH[$A] = ... - pattern: | $SMTH = $SMTH[$A] && $Z - pattern: | $SMTH = $SMTH[$A] || $Z - pattern-either: - pattern-inside: | for(...) { ... } - pattern-inside: | while(...) { ... } - pattern-inside: | $X.forEach(function $NAME(...) { ... }) - pattern-not-inside: | for(var $A = $S; ...; ...) {...} - pattern-not-inside: | for($A = $S; ...; ...) {...} - pattern-not-inside: | $X.forEach(function $NAME($OBJ, $A,...) {...}) - metavariable-pattern: patterns: - pattern-not: '"..."' - pattern-not: | `...${...}...` - pattern-not: | ($A: float) metavariable: $A - id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands languages: - yaml severity: WARNING message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this workflow permissions to use the `set-env` and `add-path` commands. There is a vulnerability in these commands that could result in environment variables being modified by an attacker. Depending on the use of the environment variable, this could enable an attacker to, at worst, modify the system path to run a different command than intended, resulting in arbitrary code execution. This could result in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files for more information. metadata: cwe: - 'CWE-749: Exposed Dangerous Method or Function' owasp: A06:2017 - Security Misconfiguration references: - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files category: security technology: - github-actions subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands shortlink: https://sg.run/qq78 semgrep.dev: rule: r_id: 13412 rv_id: 947039 rule_id: EwUQ9x version_id: jQTzq34 url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands origin: community patterns: - pattern-either: - patterns: - pattern-inside: '{env: ...}' - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' - id: json.aws.security.public-s3-bucket.public-s3-bucket languages: - json message: Detected public S3 bucket. This policy allows anyone to have some kind of access to the bucket. The exact level of access and types of actions allowed will depend on the configuration of bucket policy and ACLs. Please review the bucket configuration to make sure they are set with intended values. metadata: category: security cwe: - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html technology: - aws subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket shortlink: https://sg.run/lxv5 semgrep.dev: rule: r_id: 13413 rv_id: 1263254 rule_id: 7KUpLy version_id: RGT0Ld0 url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket origin: community patterns: - pattern-inside: | $BUCKETNAME: { "Type": "AWS::S3::Bucket", "Properties": { ..., }, ..., } - pattern-either: - pattern: | "PublicAccessBlockConfiguration": { ..., "RestrictPublicBuckets": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "IgnorePublicAcls": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "BlockPublicAcls": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "BlockPublicPolicy": false, ..., }, severity: WARNING - id: javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization message: '`$STR.replace` method will only replace the first occurrence when used with a string argument ($CHAR). If this method is used for escaping of dangerous data then there is a possibility for a bypass. Try to use sanitization library instead or use a Regex with a global flag.' metadata: cwe: - 'CWE-116: Improper Encoding or Escaping of Output' category: security technology: - javascript owasp: - A03:2021 - Injection - A05:2025 - Injection subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Encoding source: https://semgrep.dev/r/javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization shortlink: https://sg.run/1GbQ semgrep.dev: rule: r_id: 13466 rv_id: 1263199 rule_id: d8UlRq version_id: BjTkZQD url: https://semgrep.dev/playground/r/BjTkZQD/javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern: | $STR.replace(($CHAR: string), ...) - metavariable-regex: metavariable: $CHAR regex: ^[\"\']([\'\"\<\>\*\|\{\}\[\]\%\$]{1}|\\n|\\r|\\t|\\&)[\"\']$ - id: terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - patterns: - pattern: | {..., Action = "*", ...} - pattern: | {..., Resource = "*", ...} - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - patterns: - pattern: | {..., resources = ["*"], ...} - pattern: | {..., actions = ["*"], ...} message: IAM policies that allow full "*-*" admin privileges violates the principle of least privilege. This allows an attacker to take full control over all AWS account resources. Instead, give each user more fine-grained control with only the privileges they need. $TYPE metadata: references: - https://github.com/bridgecrewio/checkov/blob/master/checkov/terraform/checks/data/aws/AdminPolicyDocument.py category: security cwe: - 'CWE-269: Improper Privilege Management' technology: - terraform - aws owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges shortlink: https://sg.run/oY0N semgrep.dev: rule: r_id: 13560 rv_id: 1263889 rule_id: NbUNDX version_id: d6Tyxxd url: https://semgrep.dev/playground/r/d6Tyxxd/terraform.lang.security.iam.no-iam-admin-privileges.no-iam-admin-privileges origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: | Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = [..., $ACTION, ...] - metavariable-pattern: metavariable: $ACTION pattern-either: - pattern: | "chime:CreateApiKey" - pattern: | "codepipeline:PollForJobs" - pattern: | "cognito-identity:GetOpenIdToken" - pattern: | "cognito-identity:GetOpenIdTokenForDeveloperEdentity" - pattern: | "cognito-identity:GetCredentialsForIdentity" - pattern: | "connect:GetFederationToken" - pattern: | "connect:GetFederationTokens" - pattern: | "ec2:GetPasswordData" - pattern: | "ecr:GetAuthorizationToken" - pattern: | "gamelift:RequestUploadCredentials" - pattern: | "iam:CreateAccessKey" - pattern: | "iam:CreateLoginProfile" - pattern: | "iam:CreateServiceSpecificCredential" - pattern: | "iam:ResetServiceSpecificCredential" - pattern: | "iam:UpdateAccessKey" - pattern: | "lightsail:GetInstanceAccessDetails" - pattern: | "lightsail:GetRelationalDatabaseMasterUserPassword" - pattern: | "rds-db:Connect" - pattern: | "redshift:GetClusterCredentials" - pattern: | "sso:GetRoleCredentials" - pattern: | "mediapackage:RotateChannelCredentials" - pattern: | "mediapackage:RotateIngestEndpointCredentials" - pattern: | "sts:AssumeRole" - pattern: | "sts:AssumeRoleWithSaml" - pattern: | "sts:AssumeRoleWithWebIdentity" - pattern: | "sts:GetFederationToken" - pattern: | "sts:GetSessionToken" - pattern: | "ec2:*" - pattern: | "codepipeline:*" - pattern: | "rds-db:*" - pattern: | "connect:*" - pattern: | "iam:*" - pattern: | "ecr:*" - pattern: | "sts:*" - pattern: | "chime:*" - pattern: | "mediapackage:*" - pattern: | "redshift:*" - pattern: | "gamelift:*" - pattern: | "cognito-identity:*" - pattern: | "lightsail:*" - pattern: | "sso:*" message: Ensure IAM policies don't allow credentials exposure. Credentials exposure actions return credentials as part of the API response, and can possibly lead to leaking important credentials. Instead, use another action that doesn't return sensitive data as part of the API response. metadata: references: - https://cloudsplaining.readthedocs.io/en/latest/glossary/credentials-exposure/ - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMCredentialsExposure.py category: security cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure shortlink: https://sg.run/zxY1 semgrep.dev: rule: r_id: 13561 rv_id: 1263890 rule_id: kxUwK2 version_id: ZRTKAAP url: https://semgrep.dev/playground/r/ZRTKAAP/terraform.lang.security.iam.no-iam-creds-exposure.no-iam-creds-exposure origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Resource = "*" ...}, ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: | Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... resources = ["*"] ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = [..., $ACTION, ...] - metavariable-pattern: metavariable: $ACTION pattern-either: - pattern: | "s3:GetObject" - pattern: | "ssm:GetParameter*" - pattern: | "secretsmanager:GetSecretValue" - pattern: | "rds:CopyDBSnapshot" - pattern: | "rds:CreateDBSnapshot" - pattern: | "ssm:*" - pattern: | "s3:*" - pattern: | "rds:*" - pattern: | "rn: secretsmanager:*" message: Ensure that IAM policies don't allow data exfiltration actions that are not resource-constrained. This can allow the user to read sensitive data they don't need to read. Instead, make sure that the user granted these privileges are given these permissions on specific resources. metadata: references: - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMDataExfiltration.py - https://cloudsplaining.readthedocs.io/en/latest/glossary/data-exfiltration/ category: security cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration shortlink: https://sg.run/pYrN semgrep.dev: rule: r_id: 13562 rv_id: 1263891 rule_id: wdUj1k version_id: nWT2LLN url: https://semgrep.dev/playground/r/nWT2LLN/terraform.lang.security.iam.no-iam-data-exfiltration.no-iam-data-exfiltration origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = [..., $ACTION, ...] - metavariable-pattern: metavariable: $ACTION pattern-either: - pattern: | "iam:AddUserToGroup" - pattern: | "iam:CreatePolicyVersion" - pattern: | "iam:SetDefaultPolicyVersion" - pattern: | "iam:AttachUserPolicy" - pattern: | "iam:AttachGroupPolicy" - pattern: | "iam:AttachRolePolicy" - pattern: | "iam:PutUserPolicy" - pattern: | "iam:PutGroupPolicy" - pattern: | "iam:PutRolePolicy" - pattern: | "glue:UpdateDevEndpoint" - pattern: | "iam:*" - pattern: | "glue:*" message: Ensure that actions that can result in privilege escalation are not used. These actions could potentially result in an attacker gaining full administrator access of an AWS account. Try not to use these actions. metadata: references: - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ category: security cwe: - 'CWE-250: Execution with Unnecessary Privileges' technology: - terraform - aws subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs shortlink: https://sg.run/28y5 semgrep.dev: rule: r_id: 13563 rv_id: 946990 rule_id: x8UxLq version_id: o5TZzrP url: https://semgrep.dev/playground/r/o5TZzrP/terraform.lang.security.iam.no-iam-priv-esc-funcs.no-iam-priv-esc-funcs origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Resource = $RESOURCE ...}, ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: | Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... resources = $RESOURCE ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = [..., $ACTION, ...] - metavariable-pattern: metavariable: $RESOURCE pattern-either: - pattern-regex: .*\*.* - metavariable-pattern: metavariable: $ACTION pattern-either: - pattern: | "iam:CreateAccessKey" - pattern: | "iam:CreateLoginProfile" - pattern: | "iam:UpdateLoginProfile" - pattern: | "iam:*" message: Ensure that IAM policies with permissions on other users don't allow for privilege escalation. This can lead to an attacker gaining full administrator access of AWS accounts. Instead, specify which user the permission should be used on or do not use the listed actions. $RESOURCE metadata: references: - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMPrivilegeEscalation.py category: security cwe: - 'CWE-269: Improper Privilege Management' technology: - terraform - aws owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users shortlink: https://sg.run/XOeA semgrep.dev: rule: r_id: 13564 rv_id: 1263892 rule_id: OrU6jO version_id: ExTExxx url: https://semgrep.dev/playground/r/ExTExxx/terraform.lang.security.iam.no-iam-priv-esc-other-users.no-iam-priv-esc-other-users origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: | Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = $ACTION - metavariable-pattern: metavariable: $ACTION pattern-either: - patterns: - pattern: | [..., "sts:AssumeRole", ...] - pattern: | [..., "iam:UpdateAssumeRolePolicy", ...] - patterns: - pattern: | [..., "iam:PassRole", ...] - pattern: | [..., "lambda:CreateFunction", ...] - pattern: | [..., "lambda:InvokeFunction", ...] - patterns: - pattern: | [..., "iam:PassRole", ...] - pattern: | [..., "lambda:CreateFunction", ...] - pattern: | [..., "lambda:CreateEventSourceMapping", ...] - pattern: | "lambda:UpdateFunctionCode" - patterns: - pattern: | [..., "iam:PassRole", ...] - pattern: | [..., "glue:CreateDevEndpoint", ...] - patterns: - pattern: | [..., "iam:PassRole", ...] - pattern: | [..., "cloudformation:CreateStack", ...] - patterns: - pattern: | [..., "iam:PassRole", ...] - pattern: | [..., "datapipeline:CreatePipeline", ...] - pattern: | [..., "datapipeline:PutPipelineDefinition", ...] message: Ensure that groups of actions that include iam:PassRole and could result in privilege escalation are not all allowed for the same user. These actions could result in an attacker gaining full admin access of an AWS account. Try not to use these actions in conjuction. metadata: references: - https://cloudsplaining.readthedocs.io/en/latest/glossary/privilege-escalation/ - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ category: security cwe: - 'CWE-269: Improper Privilege Management' technology: - terraform - aws owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles shortlink: https://sg.run/jwrA semgrep.dev: rule: r_id: 13565 rv_id: 1263893 rule_id: eqUzR3 version_id: 7ZTE33y url: https://semgrep.dev/playground/r/7ZTE33y/terraform.lang.security.iam.no-iam-priv-esc-roles.no-iam-priv-esc-roles origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern: | Action = $ACTION - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = [..., $ACTION, ...] - metavariable-pattern: metavariable: $ACTION pattern-either: - pattern: | "acm-pca:CreatePermission" - pattern: | "acm-pca:DeletePermission" - pattern: | "acm-pca:DeletePolicy" - pattern: | "acm-pca:PutPolicy" - pattern: | "apigateway:UpdateRestApiPolicy" - pattern: | "backup:DeleteBackupVaultAccessPolicy" - pattern: | "backup:PutBackupVaultAccessPolicy" - pattern: | "chime:DeleteVoiceConnectorTerminationCredentials" - pattern: | "chime:PutVoiceConnectorTerminationCredentials" - pattern: | "cloudformation:SetStackPolicy" - pattern: | "cloudsearch:UpdateServiceAccessPolicies" - pattern: | "codeartifact:DeleteDomainPermissionsPolicy" - pattern: | "codeartifact:DeleteRepositoryPermissionsPolicy" - pattern: | "codebuild:DeleteResourcePolicy" - pattern: | "codebuild:DeleteSourceCredentials" - pattern: | "codebuild:ImportSourceCredentials" - pattern: | "codebuild:PutResourcePolicy" - pattern: | "codeguru-profiler:PutPermission" - pattern: | "codeguru-profiler:RemovePermission" - pattern: | "codestar:AssociateTeamMember" - pattern: | "codestar:CreateProject" - pattern: | "codestar:DeleteProject" - pattern: | "codestar:DisassociateTeamMember" - pattern: | "codestar:UpdateTeamMember" - pattern: | "cognito-identity:CreateIdentityPool" - pattern: | "cognito-identity:DeleteIdentities" - pattern: | "cognito-identity:DeleteIdentityPool" - pattern: | "cognito-identity:GetId" - pattern: | "cognito-identity:MergeDeveloperIdentities" - pattern: | "cognito-identity:SetIdentityPoolRoles" - pattern: | "cognito-identity:UnlinkDeveloperIdentity" - pattern: | "cognito-identity:UnlinkIdentity" - pattern: | "cognito-identity:UpdateIdentityPool" - pattern: | "deeplens:AssociateServiceRoleToAccount" - pattern: | "ds:CreateConditionalForwarder" - pattern: | "ds:CreateDirectory" - pattern: | "ds:CreateMicrosoftAD" - pattern: | "ds:CreateTrust" - pattern: | "ds:ShareDirectory" - pattern: | "ec2:CreateNetworkInterfacePermission" - pattern: | "ec2:DeleteNetworkInterfacePermission" - pattern: | "ec2:ModifySnapshotAttribute" - pattern: | "ec2:ModifyVpcEndpointServicePermissions" - pattern: | "ec2:ResetSnapshotAttribute" - pattern: | "ecr:DeleteRepositoryPolicy" - pattern: | "ecr:SetRepositoryPolicy" - pattern: | "elasticfilesystem:DeleteFileSystemPolicy" - pattern: | "elasticfilesystem:PutFileSystemPolicy" - pattern: | "elasticmapreduce:PutBlockPublicAccessConfiguration" - pattern: | "es:CreateElasticsearchDomain" - pattern: | "es:UpdateElasticsearchDomainConfig" - pattern: | "glacier:AbortVaultLock" - pattern: | "glacier:CompleteVaultLock" - pattern: | "glacier:DeleteVaultAccessPolicy" - pattern: | "glacier:InitiateVaultLock" - pattern: | "glacier:SetDataRetrievalPolicy" - pattern: | "glacier:SetVaultAccessPolicy" - pattern: | "glue:DeleteResourcePolicy" - pattern: | "glue:PutResourcePolicy" - pattern: | "greengrass:AssociateServiceRoleToAccount" - pattern: | "health:DisableHealthServiceAccessForOrganization" - pattern: | "health:EnableHealthServiceAccessForOrganization" - pattern: | "iam:AddClientIDToOpenIDConnectProvider" - pattern: | "iam:AddRoleToInstanceProfile" - pattern: | "iam:AddUserToGroup" - pattern: | "iam:AttachGroupPolicy" - pattern: | "iam:AttachRolePolicy" - pattern: | "iam:AttachUserPolicy" - pattern: | "iam:ChangePassword" - pattern: | "iam:CreateAccessKey" - pattern: | "iam:CreateAccountAlias" - pattern: | "iam:CreateGroup" - pattern: | "iam:CreateInstanceProfile" - pattern: | "iam:CreateLoginProfile" - pattern: | "iam:CreateOpenIDConnectProvider" - pattern: | "iam:CreatePolicy" - pattern: | "iam:CreatePolicyVersion" - pattern: | "iam:CreateRole" - pattern: | "iam:CreateSAMLProvider" - pattern: | "iam:CreateServiceLinkedRole" - pattern: | "iam:CreateServiceSpecificCredential" - pattern: | "iam:CreateUser" - pattern: | "iam:CreateVirtualMFADevice" - pattern: | "iam:DeactivateMFADevice" - pattern: | "iam:DeleteAccessKey" - pattern: | "iam:DeleteAccountAlias" - pattern: | "iam:DeleteAccountPasswordPolicy" - pattern: | "iam:DeleteGroup" - pattern: | "iam:DeleteGroupPolicy" - pattern: | "iam:DeleteInstanceProfile" - pattern: | "iam:DeleteLoginProfile" - pattern: | "iam:DeleteOpenIDConnectProvider" - pattern: | "iam:DeletePolicy" - pattern: | "iam:DeletePolicyVersion" - pattern: | "iam:DeleteRole" - pattern: | "iam:DeleteRolePermissionsBoundary" - pattern: | "iam:DeleteRolePolicy" - pattern: | "iam:DeleteSAMLProvider" - pattern: | "iam:DeleteSSHPublicKey" - pattern: | "iam:DeleteServerCertificate" - pattern: | "iam:DeleteServiceLinkedRole" - pattern: | "iam:DeleteServiceSpecificCredential" - pattern: | "iam:DeleteSigningCertificate" - pattern: | "iam:DeleteUser" - pattern: | "iam:DeleteUserPermissionsBoundary" - pattern: | "iam:DeleteUserPolicy" - pattern: | "iam:DeleteVirtualMFADevice" - pattern: | "iam:DetachGroupPolicy" - pattern: | "iam:DetachRolePolicy" - pattern: | "iam:DetachUserPolicy" - pattern: | "iam:EnableMFADevice" - pattern: | "iam:PassRole" - pattern: | "iam:PutGroupPolicy" - pattern: | "iam:PutRolePermissionsBoundary" - pattern: | "iam:PutRolePolicy" - pattern: | "iam:PutUserPermissionsBoundary" - pattern: | "iam:PutUserPolicy" - pattern: | "iam:RemoveClientIDFromOpenIDConnectProvider" - pattern: | "iam:RemoveRoleFromInstanceProfile" - pattern: | "iam:RemoveUserFromGroup" - pattern: | "iam:ResetServiceSpecificCredential" - pattern: | "iam:ResyncMFADevice" - pattern: | "iam:SetDefaultPolicyVersion" - pattern: | "iam:SetSecurityTokenServicePreferences" - pattern: | "iam:UpdateAccessKey" - pattern: | "iam:UpdateAccountPasswordPolicy" - pattern: | "iam:UpdateAssumeRolePolicy" - pattern: | "iam:UpdateGroup" - pattern: | "iam:UpdateLoginProfile" - pattern: | "iam:UpdateOpenIDConnectProviderThumbprint" - pattern: | "iam:UpdateRole" - pattern: | "iam:UpdateRoleDescription" - pattern: | "iam:UpdateSAMLProvider" - pattern: | "iam:UpdateSSHPublicKey" - pattern: | "iam:UpdateServerCertificate" - pattern: | "iam:UpdateServiceSpecificCredential" - pattern: | "iam:UpdateSigningCertificate" - pattern: | "iam:UpdateUser" - pattern: | "iam:UploadSSHPublicKey" - pattern: | "iam:UploadServerCertificate" - pattern: | "iam:UploadSigningCertificate" - pattern: | "imagebuilder:PutComponentPolicy" - pattern: | "imagebuilder:PutImagePolicy" - pattern: | "imagebuilder:PutImageRecipePolicy" - pattern: | "iot:AttachPolicy" - pattern: | "iot:AttachPrincipalPolicy" - pattern: | "iot:DetachPolicy" - pattern: | "iot:DetachPrincipalPolicy" - pattern: | "iot:SetDefaultAuthorizer" - pattern: | "iot:SetDefaultPolicyVersion" - pattern: | "iotsitewise:CreateAccessPolicy" - pattern: | "iotsitewise:DeleteAccessPolicy" - pattern: | "iotsitewise:UpdateAccessPolicy" - pattern: | "kms:CreateGrant" - pattern: | "kms:PutKeyPolicy" - pattern: | "kms:RetireGrant" - pattern: | "kms:RevokeGrant" - pattern: | "lakeformation:BatchGrantPermissions" - pattern: | "lakeformation:BatchRevokePermissions" - pattern: | "lakeformation:GrantPermissions" - pattern: | "lakeformation:PutDataLakeSettings" - pattern: | "lakeformation:RevokePermissions" - pattern: | "lambda:AddLayerVersionPermission" - pattern: | "lambda:AddPermission" - pattern: | "lambda:DisableReplication" - pattern: | "lambda:EnableReplication" - pattern: | "lambda:RemoveLayerVersionPermission" - pattern: | "lambda:RemovePermission" - pattern: | "license-manager:UpdateServiceSettings" - pattern: | "lightsail:GetRelationalDatabaseMasterUserPassword" - pattern: | "logs:DeleteResourcePolicy" - pattern: | "logs:PutResourcePolicy" - pattern: | "mediapackage:RotateIngestEndpointCredentials" - pattern: | "mediastore:DeleteContainerPolicy" - pattern: | "mediastore:PutContainerPolicy" - pattern: | "opsworks:SetPermission" - pattern: | "opsworks:UpdateUserProfile" - pattern: | "quicksight:CreateAdmin" - pattern: | "quicksight:CreateGroup" - pattern: | "quicksight:CreateGroupMembership" - pattern: | "quicksight:CreateIAMPolicyAssignment" - pattern: | "quicksight:CreateUser" - pattern: | "quicksight:DeleteGroup" - pattern: | "quicksight:DeleteGroupMembership" - pattern: | "quicksight:DeleteIAMPolicyAssignment" - pattern: | "quicksight:DeleteUser" - pattern: | "quicksight:DeleteUserByPrincipalId" - pattern: | "quicksight:RegisterUser" - pattern: | "quicksight:UpdateDashboardPermissions" - pattern: | "quicksight:UpdateGroup" - pattern: | "quicksight:UpdateIAMPolicyAssignment" - pattern: | "quicksight:UpdateTemplatePermissions" - pattern: | "quicksight:UpdateUser" - pattern: | "ram:AcceptResourceShareInvitation" - pattern: | "ram:AssociateResourceShare" - pattern: | "ram:CreateResourceShare" - pattern: | "ram:DeleteResourceShare" - pattern: | "ram:DisassociateResourceShare" - pattern: | "ram:EnableSharingWithAwsOrganization" - pattern: | "ram:RejectResourceShareInvitation" - pattern: | "ram:UpdateResourceShare" - pattern: | "rds:AuthorizeDBSecurityGroupIngress" - pattern: | "rds-db:connect" - pattern: | "redshift:AuthorizeSnapshotAccess" - pattern: | "redshift:CreateClusterUser" - pattern: | "redshift:CreateSnapshotCopyGrant" - pattern: | "redshift:JoinGroup" - pattern: | "redshift:ModifyClusterIamRoles" - pattern: | "redshift:RevokeSnapshotAccess" - pattern: | "route53resolver:PutResolverRulePolicy" - pattern: | "s3:BypassGovernanceRetention" - pattern: | "s3:DeleteAccessPointPolicy" - pattern: | "s3:DeleteBucketPolicy" - pattern: | "s3:ObjectOwnerOverrideToBucketOwner" - pattern: | "s3:PutAccessPointPolicy" - pattern: | "s3:PutAccountPublicAccessBlock" - pattern: | "s3:PutBucketAcl" - pattern: | "s3:PutBucketPolicy" - pattern: | "s3:PutBucketPublicAccessBlock" - pattern: | "s3:PutObjectAcl" - pattern: | "s3:PutObjectVersionAcl" - pattern: | "secretsmanager:DeleteResourcePolicy" - pattern: | "secretsmanager:PutResourcePolicy" - pattern: | "secretsmanager:ValidateResourcePolicy" - pattern: | "servicecatalog:CreatePortfolioShare" - pattern: | "servicecatalog:DeletePortfolioShare" - pattern: | "sns:AddPermission" - pattern: | "sns:CreateTopic" - pattern: | "sns:RemovePermission" - pattern: | "sns:SetTopicAttributes" - pattern: | "sqs:AddPermission" - pattern: | "sqs:CreateQueue" - pattern: | "sqs:RemovePermission" - pattern: | "sqs:SetQueueAttributes" - pattern: | "ssm:ModifyDocumentPermission" - pattern: | "sso:AssociateDirectory" - pattern: | "sso:AssociateProfile" - pattern: | "sso:CreateApplicationInstance" - pattern: | "sso:CreateApplicationInstanceCertificate" - pattern: | "sso:CreatePermissionSet" - pattern: | "sso:CreateProfile" - pattern: | "sso:CreateTrust" - pattern: | "sso:DeleteApplicationInstance" - pattern: | "sso:DeleteApplicationInstanceCertificate" - pattern: | "sso:DeletePermissionSet" - pattern: | "sso:DeletePermissionsPolicy" - pattern: | "sso:DeleteProfile" - pattern: | "sso:DisassociateDirectory" - pattern: | "sso:DisassociateProfile" - pattern: | "sso:ImportApplicationInstanceServiceProviderMetadata" - pattern: | "sso:PutPermissionsPolicy" - pattern: | "sso:StartSSO" - pattern: | "sso:UpdateApplicationInstanceActiveCertificate" - pattern: | "sso:UpdateApplicationInstanceDisplayData" - pattern: | "sso:UpdateApplicationInstanceResponseConfiguration" - pattern: | "sso:UpdateApplicationInstanceResponseSchemaConfiguration" - pattern: | "sso:UpdateApplicationInstanceSecurityConfiguration" - pattern: | "sso:UpdateApplicationInstanceServiceProviderConfiguration" - pattern: | "sso:UpdateApplicationInstanceStatus" - pattern: | "sso:UpdateDirectoryAssociation" - pattern: | "sso:UpdatePermissionSet" - pattern: | "sso:UpdateProfile" - pattern: | "sso:UpdateSSOConfiguration" - pattern: | "sso:UpdateTrust" - pattern: | "sso-directory:AddMemberToGroup" - pattern: | "sso-directory:CreateAlias" - pattern: | "sso-directory:CreateGroup" - pattern: | "sso-directory:CreateUser" - pattern: | "sso-directory:DeleteGroup" - pattern: | "sso-directory:DeleteUser" - pattern: | "sso-directory:DisableUser" - pattern: | "sso-directory:EnableUser" - pattern: | "sso-directory:RemoveMemberFromGroup" - pattern: | "sso-directory:UpdateGroup" - pattern: | "sso-directory:UpdatePassword" - pattern: | "sso-directory:UpdateUser" - pattern: | "sso-directory:VerifyEmail" - pattern: | "storagegateway:DeleteChapCredentials" - pattern: | "storagegateway:SetLocalConsolePassword" - pattern: | "storagegateway:SetSMBGuestPassword" - pattern: | "storagegateway:UpdateChapCredentials" - pattern: | "waf:DeletePermissionPolicy" - pattern: | "waf:PutPermissionPolicy" - pattern: | "waf-regional:DeletePermissionPolicy" - pattern: | "waf-regional:PutPermissionPolicy" - pattern: | "wafv2:CreateWebACL" - pattern: | "wafv2:DeletePermissionPolicy" - pattern: | "wafv2:DeleteWebACL" - pattern: | "wafv2:PutPermissionPolicy" - pattern: | "wafv2:UpdateWebACL" - pattern: | "worklink:UpdateDevicePolicyConfiguration" - pattern: | "workmail:ResetPassword" - pattern: | "workmail:ResetUserPassword" - pattern: | "xray:PutEncryptionConfig" - pattern: | "worklink:*" - pattern: | "route53resolver:*" - pattern: | "es:*" - pattern: | "greengrass:*" - pattern: | "redshift:*" - pattern: | "license-manager:*" - pattern: | "rds:*" - pattern: | "lambda:*" - pattern: | "elasticfilesystem:*" - pattern: | "logs:*" - pattern: | "sso:*" - pattern: | "waf:*" - pattern: | "mediastore:*" - pattern: | "acm-pca:*" - pattern: | "sso-directory:*" - pattern: | "imagebuilder:*" - pattern: | "sqs:*" - pattern: | "codeguru-profiler:*" - pattern: | "wafv2:*" - pattern: | "cloudformation:*" - pattern: | "xray:*" - pattern: | "codeartifact:*" - pattern: | "iotsitewise:*" - pattern: | "workmail:*" - pattern: | "glue:*" - pattern: | "deeplens:*" - pattern: | "chime:*" - pattern: | "mediapackage:*" - pattern: | "opsworks:*" - pattern: | "ds:*" - pattern: | "ram:*" - pattern: | "iam:*" - pattern: | "waf-regional:*" - pattern: | "glacier:*" - pattern: | "cloudsearch:*" - pattern: | "lakeformation:*" - pattern: | "elasticmapreduce:*" - pattern: | "quicksight:*" - pattern: | "sns:*" - pattern: | "ec2:*" - pattern: | "health:*" - pattern: | "lightsail:*" - pattern: | "codestar:*" - pattern: | "kms:*" - pattern: | "codebuild:*" - pattern: | "s3:*" - pattern: | "cognito-identity:*" - pattern: | "apigateway:*" - pattern: | "rds-db:*" - pattern: | "iot:*" - pattern: | "backup:*" - pattern: | "secretsmanager:*" - pattern: | "servicecatalog:*" - pattern: | "ssm:*" - pattern: | "storagegateway:*" - pattern: | "ecr:*" message: Ensure IAM policies don't allow resource exposure. These actions can expose AWS resources to the public. For example `ecr:SetRepositoryPolicy` could let an attacker retrieve container images. Instead, use another action that doesn't expose AWS resources. metadata: references: - https://cloudsplaining.readthedocs.io/en/latest/glossary/resource-exposure/ - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/IAMPermissionsManagement.py category: security cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure shortlink: https://sg.run/18rD semgrep.dev: rule: r_id: 13566 rv_id: 1263894 rule_id: v8U9r0 version_id: LjTkggK url: https://semgrep.dev/playground/r/LjTkggK/terraform.lang.security.iam.no-iam-resource-exposure.no-iam-resource-exposure origin: community languages: - hcl severity: WARNING - id: terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions patterns: - pattern-either: - patterns: - pattern-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ... ] ... }) ... } - pattern-not-inside: | resource $TYPE "..." { ... policy = jsonencode({ ... Statement = [ ..., {... Effect = "Deny" ...}, ... ] ... }) ... } - pattern-either: - pattern: Action = "*" - pattern: Action = ["*"] - metavariable-pattern: metavariable: $TYPE pattern-either: - pattern: | "aws_iam_role_policy" - pattern: | "aws_iam_policy" - pattern: | "aws_iam_user_policy" - pattern: | "aws_iam_group_policy" - patterns: - pattern-inside: | data aws_iam_policy_document "..." { ... statement { ... } ... } - pattern-not-inside: | data aws_iam_policy_document "..." { ... statement { ... effect = "Deny" ... } ... } - pattern: | actions = ["*"] message: Ensure that no IAM policies allow "*" as a statement's actions. This allows all actions to be performed on the specified resources, and is a violation of the principle of least privilege. Instead, specify the actions that a certain user or policy is allowed to take. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy - https://github.com/bridgecrewio/checkov/blob/ca830e14745c2c8e1b941985f305abe985d7f1f9/checkov/terraform/checks/data/aws/StarActionPolicyDocument.py category: security cwe: - 'CWE-269: Improper Privilege Management' technology: - terraform - aws owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions shortlink: https://sg.run/9rZ4 semgrep.dev: rule: r_id: 13567 rv_id: 1263895 rule_id: d8Uew3 version_id: 8KT5rrp url: https://semgrep.dev/playground/r/8KT5rrp/terraform.lang.security.iam.no-iam-star-actions.no-iam-star-actions origin: community languages: - hcl severity: WARNING - id: javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true message: 'By setting `allErrors: true` in `Ajv` library, all error objects will be allocated without limit. This allows the attacker to produce a huge number of errors which can lead to denial of service. Do not use `allErrors: true` in production.' metadata: cwe: - 'CWE-400: Uncontrolled Resource Consumption' category: security technology: - ajv references: - https://ajv.js.org/options.html#allerrors cwe2022-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true shortlink: https://sg.run/d2jY semgrep.dev: rule: r_id: 13578 rv_id: 945749 rule_id: PeUo5X version_id: 44TZkJ6 url: https://semgrep.dev/playground/r/44TZkJ6/javascript.ajv.security.audit.ajv-allerrors-true.ajv-allerrors-true origin: community languages: - javascript - typescript severity: WARNING pattern-either: - pattern: | new Ajv({...,allErrors: true,...},...) - patterns: - pattern: | new Ajv($SETTINGS,...) - pattern-inside: | $SETTINGS = {...,allErrors: true,...} ... - id: javascript.express.security.audit.remote-property-injection.remote-property-injection message: Bracket object notation with user input is present, this might allow an attacker to access all properties of the object and even it's prototype. Use literal values for object properties. metadata: confidence: LOW owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-522: Insufficiently Protected Credentials' category: security technology: - express references: - https://github.com/nodesecurity/eslint-plugin-security/blob/3c7522ca1be800353513282867a1034c795d9eb4/docs/the-dangers-of-square-bracket-notation.md cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.remote-property-injection.remote-property-injection shortlink: https://sg.run/Z4gn semgrep.dev: rule: r_id: 13579 rv_id: 1263148 rule_id: JDUL1B version_id: 44TEjGX url: https://semgrep.dev/playground/r/44TEjGX/javascript.express.security.audit.remote-property-injection.remote-property-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: $OBJ[...] = ... - pattern-not-inside: $OBJ["..."] = ... - pattern-not-inside: $OBJ[...] = "..." - pattern: $INDEX - pattern-not: | "..." + $INDEX - pattern-not: | $INDEX + "..." pattern-sanitizers: - patterns: - pattern: var $X = ... - pattern-not: var $X = $REQ.$ANY - id: javascript.express.security.cors-misconfiguration.cors-misconfiguration message: By letting user input control CORS parameters, there is a risk that software does not properly verify that the source of data or communication is valid. Use literal values for CORS settings. metadata: owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-346: Origin Validation Error' category: security references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS technology: - express subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration shortlink: https://sg.run/nKXO semgrep.dev: rule: r_id: 13580 rv_id: 1263162 rule_id: 5rULJQ version_id: YDTZe8Y url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.set($HEADER, $X) - pattern: $RES.header($HEADER, $X) - pattern: $RES.setHeader($HEADER, $X) - pattern: | $RES.set({$HEADER: $X}, ...) - pattern: | $RES.writeHead($STATUS, {$HEADER: $X}, ...) - focus-metavariable: $X - metavariable-regex: metavariable: $HEADER regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* - id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration message: By letting user input control `X-Frame-Options` header, there is a risk that software does not properly verify whether or not a browser should be allowed to render a page in an `iframe`. metadata: references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' category: security technology: - express subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration shortlink: https://sg.run/EvjA semgrep.dev: rule: r_id: 13581 rv_id: 1263178 rule_id: GdUrLy version_id: xyTjz3D url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.set($HEADER, ...) - pattern: $RES.header($HEADER, ...) - pattern: $RES.setHeader($HEADER, ...) - pattern: | $RES.set({$HEADER: ...}, ...) - pattern: | $RES.writeHead($STATUS, {$HEADER: ...}, ...) - metavariable-regex: metavariable: $HEADER regex: .*(X-Frame-Options|x-frame-options).* - id: javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring message: Detected string concatenation with a non-literal variable in a util.format / console.log function. If an attacker injects a format specifier in the string, it will forge the log message. Try to use constant values for the format string. metadata: cwe: - 'CWE-134: Use of Externally-Controlled Format String' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - javascript subcategory: - audit likelihood: MEDIUM impact: LOW confidence: LOW references: - https://cwe.mitre.org/data/definitions/134.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring shortlink: https://sg.run/7Y5R semgrep.dev: rule: r_id: 13582 rv_id: 1263211 rule_id: ReU3OJ version_id: A8Tgdyq url: https://semgrep.dev/playground/r/A8Tgdyq/javascript.lang.security.audit.unsafe-formatstring.unsafe-formatstring origin: community languages: - javascript - typescript severity: INFO mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $X + $Y - pattern: $X.concat($Y) - pattern: | `...${...}...` - pattern-not: | "..." + "..." - pattern-not: | $X.concat("...") pattern-sinks: - patterns: - focus-metavariable: $STR - pattern-either: - pattern: | console.$LOG($STR,$PARAM,...) - patterns: - pattern-inside: | $UTIL = require('util') ... - pattern: | $UTIL.format($STR,$PARAM,...) - id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation metadata: shortDescription: Allowing an attacker to manipulate the session may lead to unintended behavior. tags: - security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-276: Incorrect Default Permissions' references: - https://brakemanscanner.org/docs/warning_types/session_manipulation/ category: security technology: - rails help: | ## Remediation Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior. ## References [Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/) cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation shortlink: https://sg.run/86q7 semgrep.dev: rule: r_id: 13584 rv_id: 1263621 rule_id: BYUdW6 version_id: qkTR76G url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation origin: community message: This gets data from session using user inputs. A malicious user may be able to retrieve information from your session that you didn't intend them to. Do not use user input as a session key. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern: session[...] - id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access shortlink: https://sg.run/gYln semgrep.dev: rule: r_id: 13585 rv_id: 1263622 rule_id: DbU1dr version_id: l4TJRkk url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-either: - pattern: Dir.$X(...) - pattern: File.$X(...) - pattern: IO.$X(...) - pattern: Kernel.$X(...) - pattern: PStore.$X(...) - pattern: Pathname.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: chdir - pattern: chroot - pattern: delete - pattern: entries - pattern: foreach - pattern: glob - pattern: install - pattern: lchmod - pattern: lchown - pattern: link - pattern: load - pattern: load_file - pattern: makedirs - pattern: move - pattern: new - pattern: open - pattern: read - pattern: readlines - pattern: rename - pattern: rmdir - pattern: safe_unlink - pattern: symlink - pattern: syscopy - pattern: sysopen - pattern: truncate - pattern: unlink - id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call shortlink: https://sg.run/Q9gP semgrep.dev: rule: r_id: 13586 rv_id: 1263623 rule_id: WAUyzp version_id: YDTZeWL url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern-either: - pattern: Net::FTP.$X(...) - patterns: - pattern-inside: | $FTP = Net::FTP.$OPEN(...) ... $FTP.$METHOD(...) - pattern: $FTP.$METHOD(...) - id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request shortlink: https://sg.run/3rLb semgrep.dev: rule: r_id: 13587 rv_id: 1263624 rule_id: 0oU2x3 version_id: 6xT29nN url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern-either: - patterns: - pattern: Net::HTTP::$METHOD.new(...) - metavariable-pattern: metavariable: $METHOD patterns: - pattern-either: - pattern: Copy - pattern: Delete - pattern: Get - pattern: Head - pattern: Lock - pattern: Mkcol - pattern: Move - pattern: Options - pattern: Patch - pattern: Post - pattern: Propfind - pattern: Proppatch - pattern: Put - pattern: Trace - pattern: Unlock - patterns: - pattern: Net::HTTP.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: get - pattern: get2 - pattern: head - pattern: head2 - pattern: options - pattern: patch - pattern: post - pattern: post2 - pattern: post_form - pattern: put - pattern: request - pattern: request_get - pattern: request_head - pattern: request_post - pattern: send_request - pattern: trace - pattern: get_print - pattern: get_response - pattern: start - id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call shortlink: https://sg.run/4e8E semgrep.dev: rule: r_id: 13588 rv_id: 1263625 rule_id: KxU72k version_id: o5TbDq8 url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: ERROR mode: taint pattern-sources: - pattern-either: - pattern: params[...] - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: Kernel.$X(...) - patterns: - pattern-either: - pattern: Shell.$X(...) - patterns: - pattern-inside: | $SHELL = Shell.$ANY(...) ... $SHELL.$X(...) - pattern: $SHELL.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: cat - pattern: chdir - pattern: chroot - pattern: delete - pattern: entries - pattern: exec - pattern: foreach - pattern: glob - pattern: install - pattern: lchmod - pattern: lchown - pattern: link - pattern: load - pattern: load_file - pattern: makedirs - pattern: move - pattern: new - pattern: open - pattern: read - pattern: readlines - pattern: rename - pattern: rmdir - pattern: safe_unlink - pattern: symlink - pattern: syscopy - pattern: sysopen - pattern: system - pattern: truncate - pattern: unlink - id: ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-276: Incorrect Default Permissions' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/default_routes/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes shortlink: https://sg.run/Pbrq semgrep.dev: rule: r_id: 13589 rv_id: 1263630 rule_id: qNUXYy version_id: jQTn5dx url: https://semgrep.dev/playground/r/jQTn5dx/ruby.rails.security.audit.xss.avoid-default-routes.avoid-default-routes origin: community message: Default routes are enabled in this routes file. This means any public method on a controller can be called as an action. It is very easy to accidentally expose a method you didn't mean to. Instead, remove this line and explicitly include all routes you intend external users to follow. languages: - ruby severity: WARNING patterns: - pattern-either: - pattern: map.connect ":controller/:action/:id" - pattern: match ':controller(/:action(/:id(.:format)))' paths: include: - '*routes.rb' - id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://brakemanscanner.org/docs/warning_types/link_to/ - https://brakemanscanner.org/docs/warning_types/link_to_href/ category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to shortlink: https://sg.run/JxXQ semgrep.dev: rule: r_id: 13590 rv_id: 1263632 rule_id: lBU8Qj version_id: 9lT4brj url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to origin: community message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` is not escaped. This means that user input which reaches the body will be executed when the HTML is rendered. Even in other versions, values starting with `javascript:` or `data:` are not escaped. It is better to create and use a safer function which checks the body argument. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env - pattern-either: - pattern: $MODEL.url(...) - pattern: $MODEL.uri(...) - pattern: $MODEL.link(...) - pattern: $MODEL.page(...) - pattern: $MODEL.site(...) pattern-sinks: - pattern: link_to(...) pattern-sanitizers: - patterns: - pattern: | "...#{...}..." - pattern-not: | "#{...}..." - id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' references: - https://brakemanscanner.org/docs/warning_types/redirect/ category: security technology: - rails subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect shortlink: https://sg.run/5DY3 semgrep.dev: rule: r_id: 13591 rv_id: 1263634 rule_id: YGUDqJ version_id: rxTAKdY url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect origin: community message: When a redirect uses user input, a malicious user can spoof a website under a trusted URL or access restricted parts of a site. When using user-supplied values, sanitize the value before using it for the redirect. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env - patterns: - pattern: $MODEL.$X(...) - pattern-not: $MODEL.$X("...") - metavariable-pattern: metavariable: $X pattern-either: - pattern: all - pattern: create - pattern: create! - pattern: find - pattern: find_by_sql - pattern: first - pattern: last - pattern: new - pattern: from - pattern: group - pattern: having - pattern: joins - pattern: lock - pattern: order - pattern: reorder - pattern: select - pattern: where - pattern: find_by - pattern: find_by! - pattern: take pattern-sinks: - pattern: redirect_to(...) pattern-sanitizers: - pattern: params.merge(:only_path => true) - pattern: params.merge(:host => ...) - id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path shortlink: https://sg.run/GO2n semgrep.dev: rule: r_id: 13592 rv_id: 1263635 rule_id: 6JU1bL version_id: bZT53p0 url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path origin: community message: Avoid rendering user input. It may be possible for a malicious user to input a path that lets them access a template they shouldn't. To prevent this, check dynamic template paths against a predefined allowlist to make sure it's an allowed template. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-inside: render($X => $INPUT, ...) - pattern: $INPUT - metavariable-pattern: metavariable: $X pattern-either: - pattern: action - pattern: template - pattern: partial - pattern: file - id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions languages: - python severity: WARNING metadata: category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-276: Incorrect Default Permissions' technology: - python references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions shortlink: https://sg.run/AXY4 semgrep.dev: rule: r_id: 13594 rv_id: 1263482 rule_id: zdUYqR version_id: O9Tpxqr url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions origin: community message: These permissions `$BITS` are widely permissive and grant access to more people than may be necessary. A good default is `0o644` which gives read and write access to yourself and read access to everyone else. patterns: - pattern-inside: os.$METHOD(...) - metavariable-pattern: metavariable: $METHOD patterns: - pattern-either: - pattern: chmod - pattern: lchmod - pattern: fchmod - pattern-either: - patterns: - pattern: os.$METHOD($FILE, $BITS, ...) - metavariable-comparison: metavariable: $BITS comparison: $BITS >= 0o650 and $BITS < 0o100000 - patterns: - pattern: os.$METHOD($FILE, $BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS >= 0o100650 - patterns: - pattern: os.$METHOD($FILE, $BITS, ...) - metavariable-pattern: metavariable: $BITS patterns: - pattern-either: - pattern: <... stat.S_IWGRP ...> - pattern: <... stat.S_IXGRP ...> - pattern: <... stat.S_IWOTH ...> - pattern: <... stat.S_IXOTH ...> - pattern: <... stat.S_IRWXO ...> - pattern: <... stat.S_IRWXG ...> - patterns: - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) - metavariable-comparison: metavariable: $MOD comparison: $MOD == 0o111 - id: csharp.lang.security.ssrf.http-client.ssrf severity: ERROR languages: - csharp metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/csharp.lang.security.ssrf.http-client.ssrf shortlink: https://sg.run/4eB9 semgrep.dev: rule: r_id: 13700 rv_id: 1262649 rule_id: 10UdbE version_id: A8Tgde1 url: https://semgrep.dev/playground/r/A8Tgde1/csharp.lang.security.ssrf.http-client.ssrf origin: community message: SSRF is an attack vector that abuses an application to interact with the internal/external network or the machine itself. patterns: - pattern-inside: | using System.Net.Http; ... - pattern-either: - pattern: | $T $F(..., $X, ...) { ... HttpClient $Y = new HttpClient(); ... ... $Y.GetAsync(<... $X ...>, ...); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... HttpClient $Y = new HttpClient(); ... ... $Y.GetAsync($B, ...); } - pattern: | $T $F(..., $X, ...) { ... HttpClient $Y = new HttpClient(); ... ... $Y.GetStringAsync(<... $X ...>); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... HttpClient $Y = new HttpClient(); ... ... $Y.GetStringAsync($B); } - id: csharp.lang.security.ssrf.rest-client.ssrf severity: ERROR languages: - csharp metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/csharp.lang.security.ssrf.rest-client.ssrf shortlink: https://sg.run/Pb9v semgrep.dev: rule: r_id: 13701 rv_id: 1262650 rule_id: 9AURoq version_id: BjTkZzn url: https://semgrep.dev/playground/r/BjTkZzn/csharp.lang.security.ssrf.rest-client.ssrf origin: community message: SSRF is an attack vector that abuses an application to interact with the internal/external network or the machine itself. patterns: - pattern-inside: | using RestSharp; ... - pattern-either: - pattern: | $T $F(..., $X, ...) { ... ... new RestClient(<... $X ...>); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... ... new RestClient($B); } - id: csharp.lang.security.ssrf.web-client.ssrf severity: ERROR languages: - csharp metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/csharp.lang.security.ssrf.web-client.ssrf shortlink: https://sg.run/JxqP semgrep.dev: rule: r_id: 13702 rv_id: 1262651 rule_id: yyUPBe version_id: DkTRbxP url: https://semgrep.dev/playground/r/DkTRbxP/csharp.lang.security.ssrf.web-client.ssrf origin: community message: SSRF is an attack vector that abuses an application to interact with the internal/external network or the machine itself. patterns: - pattern-inside: | using System.Net; ... - pattern-either: - pattern: | $T $F(..., $X, ...) { ... WebClient $Y = new WebClient(); ... ... $Y.OpenRead(<... $X ...>); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... WebClient $Y = new WebClient(); ... ... $Y.OpenRead($B); } - pattern: | $T $F(..., $X, ...) { ... WebClient $Y = new WebClient(); ... ... $Y.OpenReadAsync(<... $X ...>, ...); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... WebClient $Y = new WebClient(); ... ... $Y.OpenReadAsync($B, ...); } - pattern: | $T $F(..., $X, ...) { ... WebClient $Y = new WebClient(); ... ... $Y.DownloadString(<... $X ...>); } - pattern: | $T $F(..., $X, ...) { ... $A $B = <... $X ...>; ... WebClient $Y = new WebClient(); ... ... $Y.DownloadString($B); } - id: csharp.lang.security.ssrf.web-request.ssrf severity: ERROR languages: - csharp metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cwe.mitre.org/data/definitions/918.html - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/csharp.lang.security.ssrf.web-request.ssrf shortlink: https://sg.run/5DWj semgrep.dev: rule: r_id: 13703 rv_id: 1262652 rule_id: r6UwoG version_id: WrTqKND url: https://semgrep.dev/playground/r/WrTqKND/csharp.lang.security.ssrf.web-request.ssrf origin: community message: The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Many different options exist to fix this issue depending the use case (Application can send request only to identified and trusted applications, Application can send requests to ANY external IP address or domain name). patterns: - pattern-inside: | using System.Net; ... - pattern-either: - pattern: | $T $F(..., $X, ...) { ... ... WebRequest.Create(<... $X ...>); } - pattern: | $T $F($X) { ... $A $B = <... $X ...>; ... ... WebRequest.Create($B); } - pattern: | $T $F($X) { ... $A $B = <... $X ...>; ... $C $D = <... $B ...>; ... ... WebRequest.Create($D); } - id: html.security.audit.missing-integrity.missing-integrity metadata: category: security technology: - html cwe: - 'CWE-353: Missing Support for Integrity Check' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures confidence: LOW references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity shortlink: https://sg.run/krXA semgrep.dev: rule: r_id: 13728 rv_id: 1262975 rule_id: AbUQzj version_id: w8TRopQ url: https://semgrep.dev/playground/r/w8TRopQ/html.security.audit.missing-integrity.missing-integrity origin: community patterns: - pattern-either: - pattern: - pattern: - metavariable-pattern: metavariable: $...A patterns: - pattern-either: - pattern: src='... :// ...' - pattern: src="... :// ..." - pattern: href='... :// ...' - pattern: href="... :// ..." - pattern: src='//...' - pattern: src="//..." - pattern: href='//...' - pattern: href="//..." - pattern-not-regex: (?is).*integrity=.* - pattern-not-regex: (google-analytics\.com|fonts\.googleapis\.com|fonts\.gstatic\.com|googletagmanager\.com) - pattern-not-regex: .*rel\s*=\s*['"]?preconnect.* paths: include: - '*.html' message: "This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you\u2019re telling the browser to fetch in the 'integrity' attribute for all externally hosted files." severity: WARNING languages: - generic - id: php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query languages: - php message: Detected string concatenation with a non-literal variable in a Doctrine DBAL query method. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/security.html - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html technology: - doctrine cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query shortlink: https://sg.run/KXWn semgrep.dev: rule: r_id: 13799 rv_id: 1263270 rule_id: X5UdZj version_id: jQTn5pd url: https://semgrep.dev/playground/r/jQTn5pd/php.doctrine.security.audit.doctrine-dbal-dangerous-query.doctrine-dbal-dangerous-query origin: community patterns: - pattern-either: - pattern: $CONNECTION->prepare($QUERY,...) - pattern: $CONNECTION->createQuery($QUERY,...) - pattern: $CONNECTION->executeQuery($QUERY,...) - pattern-either: - pattern-inside: | use Doctrine\DBAL\Connection; ... - pattern-inside: | $CONNECTION = $SMTH->getConnection(...); ... - pattern-not: $CONNECTION->prepare("...",...) - pattern-not: $CONNECTION->createQuery("...",...) - pattern-not: $CONNECTION->executeQuery("...",...) severity: WARNING - id: php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect patterns: - pattern: $this->redirect(...) - pattern-not: $this->redirect("...") - pattern-not: $this->redirect() message: The `redirect()` method does not check its destination in any way. If you redirect to a URL provided by end-users, your application may be open to the unvalidated redirects security vulnerability. Consider using literal values or an allowlist to validate URLs. languages: - php metadata: references: - https://symfony.com/doc/current/controller.html#redirecting - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' category: security technology: - symfony subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect shortlink: https://sg.run/4ey5 semgrep.dev: rule: r_id: 13800 rv_id: 1263316 rule_id: j2U3q8 version_id: 0bTKz0j url: https://semgrep.dev/playground/r/0bTKz0j/php.symfony.security.audit.symfony-non-literal-redirect.symfony-non-literal-redirect origin: community severity: WARNING - id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query languages: - php message: '`$QUERY` Detected string concatenation with a non-literal variable in a Doctrine QueryBuilder method. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead.' metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html technology: - doctrine cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query shortlink: https://sg.run/jwDJ semgrep.dev: rule: r_id: 13965 rv_id: 1263271 rule_id: kxUw23 version_id: 1QTypnG url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query origin: community mode: taint pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: $QUERY->add(...,$SINK,...) - pattern: $QUERY->select(...,$SINK,...) - pattern: $QUERY->addSelect(...,$SINK,...) - pattern: $QUERY->delete(...,$SINK,...) - pattern: $QUERY->update(...,$SINK,...) - pattern: $QUERY->insert(...,$SINK,...) - pattern: $QUERY->from(...,$SINK,...) - pattern: $QUERY->join(...,$SINK,...) - pattern: $QUERY->innerJoin(...,$SINK,...) - pattern: $QUERY->leftJoin(...,$SINK,...) - pattern: $QUERY->rightJoin(...,$SINK,...) - pattern: $QUERY->where(...,$SINK,...) - pattern: $QUERY->andWhere(...,$SINK,...) - pattern: $QUERY->orWhere(...,$SINK,...) - pattern: $QUERY->groupBy(...,$SINK,...) - pattern: $QUERY->addGroupBy(...,$SINK,...) - pattern: $QUERY->having(...,$SINK,...) - pattern: $QUERY->andHaving(...,$SINK,...) - pattern: $QUERY->orHaving(...,$SINK,...) - pattern: $QUERY->orderBy(...,$SINK,...) - pattern: $QUERY->addOrderBy(...,$SINK,...) - pattern: $QUERY->set($SINK,...) - pattern: $QUERY->setValue($SINK,...) - pattern-either: - pattern-inside: | $Q = $X->createQueryBuilder(); ... - pattern-inside: | $Q = new QueryBuilder(...); ... pattern-sources: - patterns: - pattern-either: - pattern: sprintf(...) - pattern: | "...".$SMTH severity: WARNING - id: php.lang.security.ldap-bind-without-password.ldap-bind-without-password patterns: - pattern-either: - pattern: ldap_bind($LDAP, $DN, NULL) - pattern: ldap_bind($LDAP, $DN, '') - patterns: - pattern: ldap_bind(...) - pattern-not: ldap_bind($LDAP, $DN, $PASSWORD) message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP statements. Consider enforcing authentication for LDAP. metadata: references: - https://www.php.net/manual/en/function.ldap-bind.php cwe: - 'CWE-287: Improper Authentication' owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - php cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/php.lang.security.ldap-bind-without-password.ldap-bind-without-password shortlink: https://sg.run/18Rv semgrep.dev: rule: r_id: 13966 rv_id: 1263292 rule_id: wdUjA5 version_id: 3ZT4X56 url: https://semgrep.dev/playground/r/3ZT4X56/php.lang.security.ldap-bind-without-password.ldap-bind-without-password origin: community languages: - php severity: WARNING - id: php.lang.security.php-permissive-cors.php-permissive-cors patterns: - pattern: header($VALUE,...) - pattern-either: - pattern: header("...",...) - pattern-inside: | $VALUE = "..."; ... - metavariable-regex: metavariable: $VALUE regex: (\'|\")\s*(Access-Control-Allow-Origin|access-control-allow-origin)\s*:\s*(\*)\s*(\'|\") message: Access-Control-Allow-Origin response header is set to "*". This will disable CORS Same Origin Policy restrictions. metadata: references: - https://developer.mozilla.org/ru/docs/Web/HTTP/Headers/Access-Control-Allow-Origin owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-346: Origin Validation Error' category: security technology: - php subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/php.lang.security.php-permissive-cors.php-permissive-cors shortlink: https://sg.run/y1XR semgrep.dev: rule: r_id: 13968 rv_id: 1263296 rule_id: OrU6JZ version_id: 5PTo1KA url: https://semgrep.dev/playground/r/5PTo1KA/php.lang.security.php-permissive-cors.php-permissive-cors origin: community languages: - php severity: WARNING - id: php.lang.security.unlink-use.unlink-use patterns: - pattern: unlink(...) - pattern-not: unlink("...",...) message: Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. metadata: references: - https://www.php.net/manual/en/function.unlink - https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html category: security technology: - php owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use shortlink: https://sg.run/rYeR semgrep.dev: rule: r_id: 13969 rv_id: 1263301 rule_id: eqUzDE version_id: DkTRbBX url: https://semgrep.dev/playground/r/DkTRbBX/php.lang.security.unlink-use.unlink-use origin: community languages: - php severity: WARNING - id: php.lang.security.unserialize-use.unserialize-use patterns: - pattern: unserialize(...) - pattern-not: unserialize("...",...) message: Calling `unserialize()` with user input in the pattern can lead to arbitrary code execution. Consider using JSON or structured data approaches (e.g. Google Protocol Buffers). metadata: references: - https://www.php.net/manual/en/function.unserialize.php - https://owasp.org/www-project-top-ten/2017/A8_2017-Insecure_Deserialization.html category: security technology: - php owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/php.lang.security.unserialize-use.unserialize-use shortlink: https://sg.run/b24E semgrep.dev: rule: r_id: 13970 rv_id: 1263302 rule_id: v8U9OJ version_id: WrTqKeJ url: https://semgrep.dev/playground/r/WrTqKeJ/php.lang.security.unserialize-use.unserialize-use origin: community languages: - php severity: WARNING - id: php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled patterns: - pattern-either: - pattern: $X->createForm($TYPE, $TASK, [..., 'csrf_protection' => false, ...], ...) - pattern: $X->prependExtensionConfig('framework', [..., 'csrf_protection' => false, ...], ...) - pattern: $X->loadFromExtension('framework', [..., 'csrf_protection' => false, ...], ...) - pattern: $X->setDefaults([..., 'csrf_protection' => false, ...], ...) - patterns: - pattern-either: - pattern: $X->createForm($TYPE, $TASK, [..., 'csrf_protection' => $VAL, ...], ...) - pattern: $X->prependExtensionConfig('framework', [..., 'csrf_protection' => $VAL, ...], ...) - pattern: $X->loadFromExtension('framework', [..., 'csrf_protection' => $VAL, ...], ...) - pattern: $X->setDefaults([..., 'csrf_protection' => $VAL, ...], ...) - pattern-inside: | $VAL = false; ... message: CSRF protection is disabled for this configuration. This is a security risk. Make sure that it is safe or consider setting `csrf_protection` property to `true`. metadata: references: - https://symfony.com/doc/current/security/csrf.html cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - symfony cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled shortlink: https://sg.run/N1gz semgrep.dev: rule: r_id: 13971 rv_id: 1263315 rule_id: d8UeKO version_id: WrTqKeL url: https://semgrep.dev/playground/r/WrTqKeL/php.symfony.security.audit.symfony-csrf-protection-disabled.symfony-csrf-protection-disabled origin: community languages: - php severity: WARNING - id: php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors patterns: - pattern-inside: | use Symfony\Component\HttpFoundation\Response; ... - pattern-either: - patterns: - pattern-either: - pattern: | new Symfony\Component\HttpFoundation\Response($X, $Y, $HEADERS, ...) - pattern: new Response($X, $Y, $HEADERS, ...) - pattern-either: - pattern: new $R($X, $Y, [$KEY => $VALUE], ...) - pattern-inside: | $HEADERS = [$KEY => $VALUE]; ... - patterns: - pattern: $RES->headers->set($KEY, $VALUE) - metavariable-regex: metavariable: $KEY regex: (\'|\")\s*(Access-Control-Allow-Origin|access-control-allow-origin)\s*(\'|\") - metavariable-regex: metavariable: $VALUE regex: (\'|\")\s*(\*)\s*(\'|\") message: Access-Control-Allow-Origin response header is set to "*". This will disable CORS Same Origin Policy restrictions. metadata: references: - https://developer.mozilla.org/ru/docs/Web/HTTP/Headers/Access-Control-Allow-Origin owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-346: Origin Validation Error' category: security technology: - symfony subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors shortlink: https://sg.run/kr92 semgrep.dev: rule: r_id: 13972 rv_id: 1263317 rule_id: ZqUOlR version_id: K3TKkAW url: https://semgrep.dev/playground/r/K3TKkAW/php.symfony.security.audit.symfony-permissive-cors.symfony-permissive-cors origin: community languages: - php severity: WARNING - id: trailofbits.go.missing-unlock-before-return.missing-unlock-before-return message: Missing mutex unlock (`$T` variable) before returning from a function. This could result in panics resulting from double lock operations languages: - go severity: ERROR metadata: category: security cwe: 'CWE-667: Improper Locking' subcategory: - vuln confidence: MEDIUM likelihood: HIGH impact: MEDIUM technology: - --no-technology-- description: Missing `mutex` unlock before returning from a function references: - https://pkg.go.dev/sync#Mutex - https://blog.trailofbits.com/2020/06/09/how-to-check-if-a-mutex-is-locked-in-go/ license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.missing-unlock-before-return.missing-unlock-before-return shortlink: https://sg.run/18Bk semgrep.dev: rule: r_id: 14222 rv_id: 937959 rule_id: L1U5Gz version_id: O9TXj4X url: https://semgrep.dev/playground/r/O9TXj4X/trailofbits.go.missing-unlock-before-return.missing-unlock-before-return origin: community patterns: - pattern-either: - pattern: panic(...) - pattern: return ... - metavariable-pattern: metavariable: $T patterns: - pattern: | ($T : sync.Mutex) - pattern-inside: | $T.Lock() ... - pattern-not-inside: | $T.Unlock() ... - pattern-not-inside: | defer $T.Unlock() ... - pattern-not-inside: | defer func(...) { ... $T.Unlock() ... }(...) ... - pattern-not-inside: "$FOO(..., ..., func(...) { \n ... \n})\n" - pattern-not-inside: | return func(...) { ... $T.Unlock() ... } - id: trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex message: Missing `RUnlock` on an `RWMutex` (`$T` variable) lock before returning from a function languages: - go severity: ERROR metadata: category: security cwe: 'CWE-667: Improper Locking' subcategory: - vuln confidence: MEDIUM likelihood: HIGH impact: MEDIUM technology: - --no-technology-- description: Missing `RUnlock` on an `RWMutex` lock before returning from a function references: - https://pkg.go.dev/sync#RWMutex - https://blog.trailofbits.com/2020/06/09/how-to-check-if-a-mutex-is-locked-in-go/ license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex shortlink: https://sg.run/9r40 semgrep.dev: rule: r_id: 14223 rv_id: 937958 rule_id: 8GUzNK version_id: xyTqL9d url: https://semgrep.dev/playground/r/xyTqL9d/trailofbits.go.missing-runlock-on-rwmutex.missing-runlock-on-rwmutex origin: community patterns: - pattern-either: - pattern: panic(...) - pattern: return ... - metavariable-pattern: metavariable: $T patterns: - pattern: | ($T : sync.RWMutex) - pattern-inside: | $T.RLock() ... - pattern-not-inside: | $T.RUnlock() ... - pattern-not-inside: | defer $T.RUnlock() ... - pattern-not-inside: | defer func(...) { ... $T.RUnlock() ... }(...) ... - pattern-not-inside: "$FOO(..., ..., func(...) { \n ... \n})\n" - pattern-not-inside: | return func(...) { ... $T.RUnlock() ... } - id: python.django.security.injection.raw-html-format.raw-html-format languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - django references: - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/oYj1 semgrep.dev: rule: r_id: 14360 rv_id: 1263397 rule_id: 2ZUPER version_id: 5PTo100 url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern: django.utils.html.escape(...) pattern-sources: - patterns: - pattern: request.$ANYTHING - pattern-not: request.build_absolute_uri pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: python.flask.security.injection.raw-html-concat.raw-html-format languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates (`flask.render_template`) which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - flask references: - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format shortlink: https://sg.run/Pb7e semgrep.dev: rule: r_id: 14389 rv_id: 1409401 rule_id: GdUrJv version_id: RGTEN1l url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern: jinja2.escape(...) - pattern: flask.escape(...) - patterns: - pattern: flask.render_template($TPL, ...) - metavariable-regex: metavariable: $TPL regex: .*\.html pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: go.lang.security.injection.tainted-url-host.tainted-url-host languages: - go message: A request was found to be crafted from user-input `$REQUEST`. This can lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing sensitive data. It is recommend where possible to not allow user-input to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommended to follow OWASP best practices to prevent abuse, including using an allowlist. options: interfile: true metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://goteleport.com/blog/ssrf-attacks/ category: security technology: - go confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/5DjW semgrep.dev: rule: r_id: 14391 rv_id: 1262970 rule_id: AbUQLr version_id: yeTxpOj url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - label: INPUT patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ - label: CLEAN requires: INPUT patterns: - pattern-either: - pattern: | "$URLSTR" + $INPUT - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) - pattern: fmt.Printf("$URLSTR", $INPUT, ...) - metavariable-regex: metavariable: $URLSTR regex: .*//[a-zA-Z0-10]+\..* pattern-sinks: - requires: INPUT and not CLEAN patterns: - pattern-either: - patterns: - pattern-either: - patterns: - pattern-inside: | $CLIENT := &http.Client{...} ... - pattern: $CLIENT.$METHOD($URL, ...) - pattern: http.$METHOD($URL, ...) - metavariable-regex: metavariable: $METHOD regex: ^(Get|Head|Post|PostForm)$ - patterns: - pattern: | http.NewRequest("$METHOD", $URL, ...) - metavariable-regex: metavariable: $METHOD regex: ^(GET|HEAD|POST|POSTFORM)$ - focus-metavariable: $URL severity: WARNING - id: javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport message: If user input reaches `HoverProvider` while `supportHml` is set to `true` it may introduce an XSS vulnerability. Do not produce HTML for hovers with dynamically generated input. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/microsoft/monaco-editor/issues/801 category: security technology: - monaco - monaco-editor cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport shortlink: https://sg.run/Jx7R semgrep.dev: rule: r_id: 14402 rv_id: 1263221 rule_id: zdUYQb version_id: o5TbDWj url: https://semgrep.dev/playground/r/o5TbDWj/javascript.monaco-editor.security.audit.monaco-hover-htmlsupport.monaco-hover-htmlsupport origin: community languages: - typescript - javascript severity: WARNING patterns: - pattern-either: - pattern-inside: | import "monaco-editor" ... - pattern-inside: | require("monaco-editor") ... - pattern-either: - pattern: | {value: $VAL, supportHtml: true} - pattern: | {value: $VAL, isTrusted: true} - pattern-inside: | {range: $R, contents: [...]} - pattern-not: | {..., value: "...", ...} - id: go.lang.security.injection.raw-html-format.raw-html-format languages: - go severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. Use the `html/template` package which will safely render HTML instead, or inspect that the HTML is rendered safely. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/3r1G semgrep.dev: rule: r_id: 14443 rv_id: 1262968 rule_id: PeUonQ version_id: 1QTyp2p url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sanitizers: - pattern: html.EscapeString(...) pattern-sinks: - patterns: - pattern-either: - pattern: fmt.Printf("$HTMLSTR", ...) - pattern: fmt.Sprintf("$HTMLSTR", ...) - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) - pattern: '"$HTMLSTR" + ...' - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: ruby.rails.security.injection.raw-html-format.raw-html-format languages: - ruby severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. Use the `render template` and make template files which will safely render HTML instead, or inspect that the HTML is absolutely rendered safely with a function like `sanitize`. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/ - https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/b2JQ semgrep.dev: rule: r_id: 14470 rv_id: 1409408 rule_id: kxUwZX version_id: qkTvgYY url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern-either: - pattern: sanitize(...) - pattern: strip_tags(...) pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | $HTMLSTR - pattern-regex: <\w+.* - patterns: - pattern-either: - pattern: Kernel::sprintf("$HTMLSTR", ...) - pattern: | "$HTMLSTR" + $EXPR - pattern: | "$HTMLSTR" % $EXPR - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: bash.curl.security.curl-eval.curl-eval severity: WARNING languages: - bash message: Data is being eval'd from a `curl` command. An attacker with control of the server in the `curl` command could inject malicious code into the `eval`, resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its integrity. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' category: security technology: - bash - curl confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval shortlink: https://sg.run/0yqJ semgrep.dev: rule: r_id: 14554 rv_id: 1262601 rule_id: KxU7Rq version_id: JdTzxL2 url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval origin: community mode: taint pattern-sources: - pattern: | $(curl ...) - pattern: | `curl ...` pattern-sinks: - pattern: eval ... - id: bash.curl.security.curl-pipe-bash.curl-pipe-bash languages: - bash severity: WARNING message: Data is being piped into `bash` from a `curl` command. An attacker with control of the server in the `curl` command could inject malicious code into the pipe, resulting in a system compromise. Avoid piping untrusted data into `bash` or any other shell if you can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its integrity. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' category: security technology: - bash - curl confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/bash.curl.security.curl-pipe-bash.curl-pipe-bash shortlink: https://sg.run/KXz6 semgrep.dev: rule: r_id: 14555 rv_id: 1262602 rule_id: qNUXrw version_id: 5PTo1Lx url: https://semgrep.dev/playground/r/5PTo1Lx/bash.curl.security.curl-pipe-bash.curl-pipe-bash origin: community patterns: - pattern-either: - pattern: curl ... | ... bash ... - pattern: curl ... | ... /bin/bash ... - pattern: '... bash <(curl ...)' - pattern: '... /bin/bash <(curl ...)' - pattern: '... bash -c "$(curl ...)"' - pattern: '... /bin/bash -c "$(curl ...)"' - id: python.flask.security.injection.tainted-url-host.tainted-url-host languages: - python message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/RXpK semgrep.dev: rule: r_id: 14649 rv_id: 1409403 rule_id: ReU3Wb version_id: BjTy42w url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: '"$URLSTR" % ...' - metavariable-pattern: metavariable: $URLSTR language: generic patterns: - pattern-either: - pattern: $SCHEME://%s - pattern: $SCHEME://%r - patterns: - pattern: '"$URLSTR".format(...)' - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME:// { ... } - patterns: - pattern: '"$URLSTR" + ...' - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern: f"$URLSTR{...}..." - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern-inside: | $URL = "$URLSTR" ... - pattern: $URL += ... - metavariable-regex: metavariable: $URLSTR regex: .*://$ pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR severity: WARNING - id: go.lang.security.audit.md5-used-as-password.md5-used-as-password languages: - go severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt` package. options: interfile: true metadata: category: security technology: - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://pkg.go.dev/golang.org/x/crypto/bcrypt owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/4eOE semgrep.dev: rule: r_id: 14688 rv_id: 1262938 rule_id: 4bU1Wj version_id: nWT2L9r url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: md5.New - pattern: md5.Sum pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: go.lang.security.injection.tainted-sql-string.tainted-sql-string languages: - go message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) or a safe library. options: interfile: true metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/doc/database/sql-injection - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ category: security technology: - go confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/PbEq semgrep.dev: rule: r_id: 14689 rv_id: 1409388 rule_id: PeUoqy version_id: nWTQ5qD url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint severity: ERROR pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - patterns: - pattern-inside: | var $SB strings.Builder ... - pattern-inside: | $SB.WriteString("$SQLSTR") ... $SB.String(...) - pattern: | $SB.WriteString(...) - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop).* - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$SQLSTR", ...) - pattern: fmt.Sprintf("$SQLSTR", ...) - pattern: fmt.Printf("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* pattern-sanitizers: - pattern-either: - pattern: strconv.Atoi(...) - pattern: | ($X: bool) - id: java.lang.security.audit.md5-used-as-password.md5-used-as-password languages: - java severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use `javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")` or, if using Spring, `org.springframework.security.crypto.bcrypt`. metadata: category: security technology: - java - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory - https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/JxEQ semgrep.dev: rule: r_id: 14690 rv_id: 1263029 rule_id: JDULAW version_id: bZT53QB url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-inside: | $TYPE $MD = MessageDigest.getInstance("MD5"); ... - pattern: $MD.digest(...); pattern-sinks: - patterns: - pattern: $MODEL.$METHOD(...); - metavariable-regex: metavariable: $METHOD regex: (?i)(.*password.*) - id: javascript.express.security.injection.raw-html-format.raw-html-format message: User data flows into the host portion of this manually-constructed HTML. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. Consider using a sanitization library such as DOMPurify to sanitize the HTML within. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/5DO3 semgrep.dev: rule: r_id: 14691 rv_id: 1263175 rule_id: 5rUL0X version_id: NdTzyQv url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - label: EXPRESS patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - label: EXPRESSTS patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - label: CLEAN by-side-effect: true patterns: - pattern-either: - pattern: $A($SOURCE) - pattern: $SANITIZE. ... .$A($SOURCE) - pattern: $A. ... .$SANITIZE($SOURCE) - focus-metavariable: $SOURCE - metavariable-regex: metavariable: $A regex: (?i)(.*valid|.*sanitiz) pattern-sinks: - requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" + $EXPR' - pattern: '"$HTMLSTR".concat(...)' - pattern: util.format($HTMLSTR, ...) - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - patterns: - pattern: | `...` - pattern-regex: | .*<\w+.* - id: javascript.lang.security.audit.md5-used-as-password.md5-used-as-password message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can use the `bcrypt` node.js package. metadata: category: security technology: - crypto - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://www.npmjs.com/package/bcrypt owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/GOEn semgrep.dev: rule: r_id: 14692 rv_id: 1263200 rule_id: GdUr5G version_id: DkTRb3p url: https://semgrep.dev/playground/r/DkTRb3p/javascript.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community languages: - javascript severity: WARNING mode: taint pattern-sources: - pattern: $CRYPTO.createHash("md5") pattern-sinks: - patterns: - pattern: $FUNCTION(...); - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DEFAULT_HTTP_CLIENT asvs: section: V9 Communications Verification Requirements control_id: 9.1.3 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated shortlink: https://sg.run/RXEK semgrep.dev: rule: r_id: 14693 rv_id: 1263262 rule_id: ReU3Yb version_id: l4TJRYY url: https://semgrep.dev/playground/r/l4TJRYY/kotlin.lang.security.defaulthttpclient-is-deprecated.defaulthttpclient-is-deprecated origin: community message: DefaultHttpClient is deprecated. Further, it does not support connections using TLS1.2, which makes using DefaultHttpClient a security hazard. Use SystemDefaultHttpClient instead, which supports TLS1.2. severity: WARNING languages: - kt pattern: DefaultHttpClient(...) fix-regex: regex: DefaultHttpClient replacement: SystemDefaultHttpClient - id: kotlin.lang.security.ecb-cipher.ecb-cipher metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher shortlink: https://sg.run/DzLj semgrep.dev: rule: r_id: 14696 rv_id: 1263263 rule_id: DbU1Zd version_id: YDTZexg url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher origin: community message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. severity: WARNING languages: - kt patterns: - pattern-either: - pattern: | val $VAR : Cipher = $CIPHER.getInstance($MODE) - pattern: | var $VAR : Cipher = $CIPHER.getInstance($MODE) - pattern: | val $VAR = $CIPHER.getInstance($MODE) - pattern: | var $VAR = $CIPHER.getInstance($MODE) - metavariable-regex: metavariable: $MODE regex: .*ECB.* - id: kotlin.lang.security.gcm-detection.gcm-detection metadata: category: security cwe: - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' references: - https://cwe.mitre.org/data/definitions/323.html technology: - kotlin owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.gcm-detection.gcm-detection shortlink: https://sg.run/WpPA semgrep.dev: rule: r_id: 14697 rv_id: 1263264 rule_id: WAUyAW version_id: 6xT29k7 url: https://semgrep.dev/playground/r/6xT29k7/kotlin.lang.security.gcm-detection.gcm-detection origin: community languages: - kt message: GCM detected, please check that IV/nonce is not reused, an Initialization Vector (IV) is a nonce used to randomize the encryption, so that even if multiple messages with identical plaintext are encrypted, the generated corresponding ciphertexts are different.Unlike the Key, the IV usually does not need to be secret, rather it is important that it is random and unique. Certain encryption schemes the IV is exchanged in public as part of the ciphertext. Reusing same Initialization Vector with the same Key to encrypt multiple plaintext blocks allows an attacker to compare the ciphertexts and then, with some assumptions on the content of the messages, to gain important information about the data being encrypted. patterns: - pattern-either: - pattern: $METHOD.getInstance("AES/GCM/NoPadding",...) - pattern: GCMParameterSpec(...) severity: INFO - id: kotlin.lang.security.no-null-cipher.no-null-cipher pattern: NullCipher(...) metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher shortlink: https://sg.run/0ywb semgrep.dev: rule: r_id: 14698 rv_id: 1263265 rule_id: 0oU2Yy version_id: o5TbDPj url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher origin: community message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - kt - scala - id: kotlin.lang.security.unencrypted-socket.unencrypted-socket metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/kotlin.lang.security.unencrypted-socket.unencrypted-socket shortlink: https://sg.run/KXZd semgrep.dev: rule: r_id: 14699 rv_id: 1413421 rule_id: KxU76z version_id: w8TWBzA url: https://semgrep.dev/playground/r/w8TWBzA/kotlin.lang.security.unencrypted-socket.unencrypted-socket origin: community message: This socket is not encrypted. The traffic could be read by an attacker intercepting the network traffic. Use an SSLSocket created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead severity: WARNING languages: - kt patterns: - pattern-either: - pattern: ServerSocket(...) - pattern: Socket(...) - pattern-not-inside: | fun $FN(...): Int { ... val $SS = ServerSocket(0) ... $SS.close() ... } - pattern-not-inside: | fun $FN(...): Int { ... val $SS = ServerSocket(0) ... $SS.localPort ... $SS.close() ... } - id: kotlin.lang.security.use-of-md5.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - kt severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5 shortlink: https://sg.run/4eQx semgrep.dev: rule: r_id: 14700 rv_id: 1263267 rule_id: qNUXPj version_id: pZT03Jd url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5 origin: community pattern-either: - pattern: | java.security.MessageDigest.getInstance("MD5") - pattern: | org.apache.commons.codec.digest.DigestUtils.getMd5Digest() - id: python.django.security.injection.tainted-sql-string.tainted-sql-string message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using the Django object-relational mappers (ORM) instead of raw SQL queries. metadata: cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection category: security technology: - django subcategory: - audit impact: LOW likelihood: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/python.django.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/PbZp semgrep.dev: rule: r_id: 14701 rv_id: 1263408 rule_id: lBU8Ad version_id: YDTZeje url: https://semgrep.dev/playground/r/YDTZeje/python.django.security.injection.tainted-sql-string.tainted-sql-string origin: community severity: ERROR languages: - python mode: taint pattern-sources: - patterns: - pattern: request.$ANYTHING - pattern-not: request.build_absolute_uri pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR" % ... - pattern: | "$SQLSTR".format(...) - pattern: | f"$SQLSTR{...}..." - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* - id: python.flask.security.injection.tainted-sql-string.tainted-sql-string message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as SQLAlchemy which will protect your queries. metadata: cwe: - 'CWE-704: Incorrect Type Conversion or Cast' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column category: security technology: - sqlalchemy - flask subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/JxZj semgrep.dev: rule: r_id: 14702 rv_id: 1409402 rule_id: YGUDKQ version_id: A8TEvb4 url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string origin: community severity: ERROR languages: - python mode: taint pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR" % ... - pattern: | "$SQLSTR".format(...) - pattern: | f"$SQLSTR{...}..." - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* - id: python.lang.security.audit.md5-used-as-password.md5-used-as-password severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`. languages: - python metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://tools.ietf.org/html/rfc6151 - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt category: security technology: - pycryptodome - hashlib - md5 subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/5DwD semgrep.dev: rule: r_id: 14703 rv_id: 1263504 rule_id: 6JU1w1 version_id: WrTqKDz url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: hashlib.md5 - pattern: hashlib.new(..., name="MD5", ...) - pattern: Cryptodome.Hash.MD5 - pattern: Crypto.Hash.MD5 - pattern: cryptography.hazmat.primitives.hashes.MD5 pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: ruby.lang.security.md5-used-as-password.md5-used-as-password languages: - ruby severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Instead, use a suitable password hashing function such as bcrypt. You can use the `bcrypt` gem. metadata: category: security technology: - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/GOZy semgrep.dev: rule: r_id: 14704 rv_id: 1263611 rule_id: oqU4p2 version_id: JdTzx0e url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - pattern: Digest::MD5 pattern-sinks: - patterns: - pattern: $FUNCTION(...); - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: ruby.rails.security.injection.tainted-url-host.tainted-url-host languages: - ruby severity: WARNING message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction with `SsrfFilter(...)`, or create an allowlist for approved hosts. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://github.com/arkadiyt/ssrf_filter cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/RX3g semgrep.dev: rule: r_id: 14705 rv_id: 1263668 rule_id: zdUY0W version_id: 6xT29BN url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sanitizers: - pattern: SsrfFilter pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | $URLSTR - pattern-regex: \w+:\/\/#{.*} - patterns: - pattern-either: - pattern: Kernel::sprintf("$URLSTR", ...) - pattern: | "$URLSTR" + $EXPR - pattern: | "$URLSTR" % $EXPR - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME:// ... - id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string languages: - ruby severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as ActiveRecord which will protect your queries. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/Y85o semgrep.dev: rule: r_id: 14714 rv_id: 1263667 rule_id: bwU8gl version_id: YDTZeLL url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sanitizers: - pattern: | $PARAMS.slice(...) pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - patterns: - pattern: | $RECORD.where($X,...) - pattern: | $RECORD.find(..., :conditions => $X,...) - focus-metavariable: $X - patterns: - pattern: | "$SQLVERB#{$EXPR}..." - pattern-not-inside: | $FUNC("...", "...#{$EXPR}...",...) - focus-metavariable: $SQLVERB - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b - patterns: - pattern-either: - pattern: Kernel::sprintf("$SQLSTR", $EXPR) - pattern: | "$SQLSTR" + $EXPR - pattern: | "$SQLSTR" % $EXPR - pattern-not-inside: | $FUNC("...", "...#{$EXPR}...",...) - focus-metavariable: $EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - id: generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key pattern-regex: k2sk_v[0-9]_[0-9a-zA-Z]{24} languages: - regex message: Kolide API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets - kolide confidence: LOW owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key shortlink: https://sg.run/d2YQ semgrep.dev: rule: r_id: 14734 rv_id: 1262880 rule_id: JDULYW version_id: ZRTKApA url: https://semgrep.dev/playground/r/ZRTKApA/generic.secrets.security.detected-kolide-api-key.detected-kolide-api-key origin: community - id: php.lang.security.injection.tainted-sql-string.tainted-sql-string languages: - php severity: ERROR message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) VALUES (?, ?)");`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/SQL_Injection category: security technology: - php cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/lZYG semgrep.dev: rule: r_id: 14757 rv_id: 1263290 rule_id: qNUXdL version_id: gETB7vY url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sanitizers: - pattern-either: - pattern: mysqli_real_escape_string(...) - pattern: real_escape_string(...) - pattern: $MYSQLI->real_escape_string(...) pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sinks: - pattern-either: - patterns: - pattern: | sprintf($SQLSTR, ...) - metavariable-regex: metavariable: $SQLSTR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - patterns: - pattern: | "...$EXPR..." - metavariable-regex: metavariable: $EXPR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - patterns: - pattern: | "$SQLSTR".$EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - id: php.lang.security.injection.tainted-url-host.tainted-url-host languages: - php severity: WARNING message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - php cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/Y8no semgrep.dev: rule: r_id: 14758 rv_id: 1263291 rule_id: lBU8K1 version_id: QkTGqRd url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sinks: - pattern-either: - patterns: - pattern: | sprintf($URLSTR, ...) - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME://%s - patterns: - pattern: | "...{$EXPR}..." - pattern-regex: | .*://\{.* - patterns: - pattern: | "...$EXPR..." - pattern-regex: | .*://\$.* - patterns: - pattern: | "...".$EXPR - pattern-regex: | .*://["'].* - id: php.lang.security.md5-used-as-password.md5-used-as-password severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD, PASSWORD_BCRYPT, $OPTIONS);`. languages: - php metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://tools.ietf.org/html/rfc6151 - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://www.php.net/password_hash category: security technology: - md5 subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/66YL semgrep.dev: rule: r_id: 14759 rv_id: 1263294 rule_id: YGUD1O version_id: PkTR37j url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: md5(...) - pattern: hash('md5', ...) pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: python.django.security.injection.tainted-url-host.tainted-url-host languages: - python message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - audit impact: MEDIUM likelihood: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.django.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/oYz6 semgrep.dev: rule: r_id: 14760 rv_id: 1263409 rule_id: 6JU1l0 version_id: JdTzxAj url: https://semgrep.dev/playground/r/JdTzxAj/python.django.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: '"$URLSTR" % ...' - metavariable-pattern: metavariable: $URLSTR language: generic patterns: - pattern-either: - pattern: $SCHEME://%s - pattern: $SCHEME://%r - patterns: - pattern: '"$URLSTR".format(...)' - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME:// { ... } - patterns: - pattern: '"$URLSTR" + ...' - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern: f"$URLSTR{...}..." - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern-inside: | $URL = "$URLSTR" ... - pattern: $URL += ... - metavariable-regex: metavariable: $URLSTR regex: .*://$ pattern-sources: - patterns: - pattern: request.$ANYTHING - pattern-not: request.build_absolute_uri severity: WARNING - id: java.spring.security.injection.tainted-sql-string.tainted-sql-string languages: - java severity: ERROR message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html category: security technology: - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/9rzz semgrep.dev: rule: r_id: 14767 rv_id: 1409396 rule_id: 10UdRR version_id: 44TbKvr url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string origin: community options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true interfile: true mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - focus-metavariable: $SOURCE pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$SQLSTR", ...) - patterns: - pattern-inside: | String $VAR = "$SQLSTR"; ... - pattern: String.format($VAR, ...) - pattern-not-inside: System.out.println(...) - pattern-not-inside: $LOG.info(...) - pattern-not-inside: $LOG.warn(...) - pattern-not-inside: $LOG.warning(...) - pattern-not-inside: $LOG.debug(...) - pattern-not-inside: $LOG.debugging(...) - pattern-not-inside: $LOG.error(...) - pattern-not-inside: new Exception(...) - pattern-not-inside: throw ...; - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - id: bash.lang.security.ifs-tampering.ifs-tampering languages: - bash severity: WARNING message: The special variable IFS affects how splitting takes place when expanding unquoted variables. Don't set it globally. Prefer a dedicated utility such as 'cut' or 'awk' if you need to split input data. If you must use 'read', set IFS locally using e.g. 'IFS="," read -a my_array'. pattern: IFS=... metadata: cwe: - 'CWE-20: Improper Input Validation' category: security technology: - bash confidence: LOW owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/bash.lang.security.ifs-tampering.ifs-tampering shortlink: https://sg.run/Q9pq semgrep.dev: rule: r_id: 14842 rv_id: 1262603 rule_id: WAUy9q version_id: GxTkerb url: https://semgrep.dev/playground/r/GxTkerb/bash.lang.security.ifs-tampering.ifs-tampering origin: community - id: generic.unicode.security.bidi.contains-bidirectional-characters patterns: - pattern-either: - pattern-regex: "\u202A" - pattern-regex: "\u202B" - pattern-regex: "\u202D" - pattern-regex: "\u202E" - pattern-regex: "\u2066" - pattern-regex: "\u2067" - pattern-regex: "\u2068" - pattern-regex: "\u202C" - pattern-regex: "\u2069" message: This code contains bidirectional (bidi) characters. While this is useful for support of right-to-left languages such as Arabic or Hebrew, it can also be used to trick language parsers into executing code in a manner that is different from how it is displayed in code editing and review tools. If this is not what you were expecting, please review this code in an editor that can reveal hidden Unicode characters. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - unicode references: - https://trojansource.codes/ confidence: LOW owasp: - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/generic.unicode.security.bidi.contains-bidirectional-characters shortlink: https://sg.run/nK4r semgrep.dev: rule: r_id: 14880 rv_id: 1262904 rule_id: d8UeX4 version_id: JdTzxzn url: https://semgrep.dev/playground/r/JdTzxzn/generic.unicode.security.bidi.contains-bidirectional-characters origin: community languages: - bash - c - csharp - go - java - javascript - json - kotlin - lua - ocaml - php - python - ruby - rust - scala - sh - typescript - yaml severity: WARNING - id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version patterns: - pattern-either: - patterns: - pattern: ssl_policy = $ANYTHING - pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+ - pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+ - patterns: - pattern: protocol = "HTTP" - pattern-not-inside: | resource $ANYTHING $NAME { ... default_action { ... redirect { ... protocol = "HTTPS" ... } ... } ... } - pattern-inside: | resource $RESOURCE $X { ... } - metavariable-pattern: metavariable: $RESOURCE patterns: - pattern-either: - pattern: | "aws_lb_listener" - pattern: | "aws_alb_listener" message: Detected an AWS load balancer with an insecure TLS version. TLS versions less than 1.2 are considered insecure because they can be broken. To fix this, set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include a default action to redirect to HTTPS. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.ietf.org/rfc/rfc5246.txt subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version shortlink: https://sg.run/187G semgrep.dev: rule: r_id: 14966 rv_id: 1263747 rule_id: 2ZUP9K version_id: ExTEx0y url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version origin: community languages: - hcl severity: WARNING - id: yaml.github-actions.security.curl-eval.curl-eval languages: - yaml message: Data is being eval'd from a `curl` command. An attacker with control of the server in the `curl` command could inject malicious code into the `eval`, resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its integrity. metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections technology: - github-actions - bash - curl cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/yaml.github-actions.security.curl-eval.curl-eval shortlink: https://sg.run/9r7r semgrep.dev: rule: r_id: 14967 rv_id: 1263926 rule_id: X5Udrd version_id: YDTZe7K url: https://semgrep.dev/playground/r/YDTZe7K/yaml.github-actions.security.curl-eval.curl-eval origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: bash metavariable: $SHELL patterns: - pattern: | $DATA=<... curl ...> ... eval <... $DATA ...> severity: ERROR - id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli mode: taint pattern-sources: - patterns: - pattern: | (string $X) - pattern-not: | "..." pattern-propagators: - pattern: (StringBuilder $B).$ANY(...,(string $X),...) from: $X to: $B pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | new $PATTERN($CMD,...) - focus-metavariable: $CMD - patterns: - pattern: | $CMD.$PATTERN = $VALUE; - focus-metavariable: $VALUE - metavariable-regex: metavariable: $PATTERN regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ pattern-sanitizers: - pattern-either: - pattern: | $CMD.Parameters.Add(...) - pattern: | $CMD.Parameters.AddRange(...) - pattern: | $CMD.Parameters.AddWithValue(...) - pattern: | $CMD.Parameters[$IDX].Value = ... by-side-effect: true message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand' and 'SqlParameter'. metadata: category: security technology: - csharp owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli shortlink: https://sg.run/d2Xd semgrep.dev: rule: r_id: 15078 rv_id: 1262648 rule_id: x8UxeP version_id: RGT0LqW url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli origin: community languages: - csharp severity: ERROR - id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret languages: - scala message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' metadata: category: security cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A04_2021-Insecure_Design cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret shortlink: https://sg.run/Z40o semgrep.dev: rule: r_id: 15079 rv_id: 1263691 rule_id: OrU6W1 version_id: 7ZTE3kr url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret origin: community pattern-either: - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC256("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); ... } ... } - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC384("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); ... } ... } - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC512("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); ... } ... } severity: ERROR - id: terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered message: Registering the identity used by an App with AD allows it to interact with other services without using username and password. Set the `identity` block in your appservice. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... identity { type = "..." identity_ids = "..." } ... } - pattern-not-inside: | resource "azurerm_app_service" "..." { ... identity { type = "SystemAssigned" } ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... } metadata: category: security owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-287: Improper Authentication' technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#identity cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered shortlink: https://sg.run/PbXY semgrep.dev: rule: r_id: 15101 rv_id: 1263754 rule_id: WAUynd version_id: 44TEj04 url: https://semgrep.dev/playground/r/44TEj04/terraform.azure.security.appservice.appservice-account-identity-registered.appservice-account-identity-registered origin: community languages: - hcl severity: INFO - id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled message: Enabling authentication ensures that all communications in the application are authenticated. The `auth_settings` block needs to be filled out with the appropriate auth backend settings patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... auth_settings { ... enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... auth_settings { ... enabled = false ... } ... } metadata: cwe: - 'CWE-287: Improper Authentication' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled shortlink: https://sg.run/JxYw semgrep.dev: rule: r_id: 15102 rv_id: 1263755 rule_id: 0oU23p version_id: PkTR3P8 url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 message: Use the latest version of HTTP to ensure you are benefiting from security fixes. Add `http2_enabled = true` to your appservice resource block patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... site_config { ... http2_enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... site_config { ... http2_enabled = false ... } ... } metadata: cwe: - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 shortlink: https://sg.run/5DkA semgrep.dev: rule: r_id: 15103 rv_id: 1263756 rule_id: KxU7LJ version_id: JdTzx98 url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 origin: community languages: - hcl severity: INFO - id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only message: By default, clients can connect to App Service by using both HTTP or HTTPS. HTTP should be disabled enabling the HTTPS Only setting. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... https_only = true ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... https_only = false ... } metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only shortlink: https://sg.run/GOKp semgrep.dev: rule: r_id: 15104 rv_id: 1263757 rule_id: qNUXwx version_id: 5PTo1gg url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert message: Detected an AppService that was not configured to use a client certificate. Add `client_cert_enabled = true` in your resource block. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... client_cert_enabled = true ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... client_cert_enabled = false ... } metadata: cwe: - 'CWE-295: Improper Certificate Validation' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert shortlink: https://sg.run/RX1O semgrep.dev: rule: r_id: 15105 rv_id: 1263758 rule_id: lBU8D6 version_id: GxTkedE url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert origin: community languages: - hcl severity: INFO - id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version = "1.2"` in your resource block. patterns: - pattern: min_tls_version = $ANYTHING - pattern-inside: | resource "azurerm_app_service" "$NAME" { ... } - pattern-not-inside: min_tls_version = "1.2" metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy shortlink: https://sg.run/AXRp semgrep.dev: rule: r_id: 15106 rv_id: 1263759 rule_id: YGUDbZ version_id: RGT0L4x url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled message: Enabling authentication ensures that all communications in the application are authenticated. The `auth_settings` block needs to be filled out with the appropriate auth backend settings patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_function_app" "..." { ... auth_settings { ... enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_function_app" "..." { ... } - pattern-inside: | resource "azurerm_function_app" "..." { ... auth_settings { ... enabled = false ... } ... } metadata: cwe: - 'CWE-287: Improper Authentication' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/function_app#enabled owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled shortlink: https://sg.run/B6AW semgrep.dev: rule: r_id: 15107 rv_id: 1263800 rule_id: 6JU1X8 version_id: JdTzxr8 url: https://semgrep.dev/playground/r/JdTzxr8/terraform.azure.security.functionapp.functionapp-authentication-enabled.functionapp-authentication-enabled origin: community languages: - hcl severity: INFO - id: terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 message: Use the latest version of HTTP to ensure you are benefiting from security fixes. Add `http2_enabled = true` to your function app resource block patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_function_app" "..." { ... site_config { ... http2_enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_function_app" "..." { ... } - pattern-inside: | resource "azurerm_function_app" "..." { ... site_config { ... http2_enabled = false ... } ... } metadata: cwe: - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/function_app#http2_enabled owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 shortlink: https://sg.run/DzDY semgrep.dev: rule: r_id: 15108 rv_id: 1263801 rule_id: oqU41L version_id: 5PTo1Dg url: https://semgrep.dev/playground/r/5PTo1Dg/terraform.azure.security.functionapp.functionapp-enable-http2.functionapp-enable-http2 origin: community languages: - hcl severity: INFO - id: terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny message: Detected a Storage that was not configured to deny action by default. Add `default_action = "Deny"` in your resource block. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_storage_account_network_rules" "..." { ... default_action = "Deny" ... } - pattern-inside: | resource "azurerm_storage_account_network_rules" "..." { ... default_action = "Allow" ... } metadata: cwe: - 'CWE-16: CWE CATEGORY: Configuration' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account_network_rules#default_action - https://docs.microsoft.com/en-us/azure/firewall/rule-processing owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny shortlink: https://sg.run/WpN4 semgrep.dev: rule: r_id: 15109 rv_id: 1263804 rule_id: zdUY3N version_id: A8Tgd7d url: https://semgrep.dev/playground/r/A8Tgd7d/terraform.azure.security.storage.storage-default-action-deny.storage-default-action-deny origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https message: Detected a Storage that was not configured to deny action by default. Add `enable_https_traffic_only = true` in your resource block. patterns: - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... enable_https_traffic_only = true ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... enable_https_traffic_only = false ... } metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only - https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https shortlink: https://sg.run/0y9v semgrep.dev: rule: r_id: 15110 rv_id: 1263805 rule_id: pKUpDA version_id: BjTkZ0A url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted patterns: - pattern-not-inside: | resource "aws_backup_vault" $BACKUP { ... kms_key_arn = ... ... } - pattern: resource "aws_backup_vault" $BACKUP {...} message: The AWS Backup vault is unencrypted. The AWS KMS encryption key protects backups in the Backup vault. To create your own, create a aws_kms_key resource or use the ARN string of a key in your account. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted shortlink: https://sg.run/18yw semgrep.dev: rule: r_id: 15122 rv_id: 946662 rule_id: x8UxrP version_id: GxTP79j url: https://semgrep.dev/playground/r/GxTP79j/terraform.aws.security.aws-backup-vault-unencrypted.aws-backup-vault-unencrypted origin: community - id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind metadata: cwe: - 'CWE-287: Improper Authentication' owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS category: security technology: - kotlin references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind shortlink: https://sg.run/rY2n semgrep.dev: rule: r_id: 15125 rv_id: 1263258 rule_id: v8U9Q7 version_id: WrTqKgJ url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind origin: community message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html for more information. severity: WARNING pattern: | $ENV.put($CTX.SECURITY_AUTHENTICATION, "none") ... $DCTX = InitialDirContext($ENV, ...) languages: - kt - id: kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion metadata: cwe: - 'CWE-704: Incorrect Type Conversion or Cast' owasp: A03:2017 - Sensitive Data Exposure source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BAD_HEXA_CONVERSION category: security technology: - kotlin references: - https://cwe.mitre.org/data/definitions/704.html subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion shortlink: https://sg.run/b25p semgrep.dev: rule: r_id: 15126 rv_id: 945937 rule_id: d8UegG version_id: xyTqnDy url: https://semgrep.dev/playground/r/xyTqnDy/kotlin.lang.security.bad-hexa-conversion.bad-hexa-conversion origin: community message: '''Integer.toHexString()'' strips leading zeroes from each byte if read byte-by-byte. This mistake weakens the hash value computed since it introduces more collisions. Use ''String.format("%02X", ...)'' instead.' severity: WARNING languages: - kt pattern: |- fun $METHOD(...) { ... val $MD: MessageDigest = ... ... $MD.digest(...) ... Integer.toHexString(...) } - id: kotlin.lang.security.use-of-sha1.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - kt severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1 shortlink: https://sg.run/N1pp semgrep.dev: rule: r_id: 15127 rv_id: 1263268 rule_id: ZqUOdd version_id: 2KTv2XZ url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1 origin: community pattern-either: - patterns: - pattern: | $VAR = $MD.getInstance("$ALGO") - metavariable-regex: metavariable: $ALGO regex: (SHA1|SHA-1) - pattern: | $DU.getSha1Digest().digest(...) - id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits based on NIST recommendation. languages: - kt severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - kotlin subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key shortlink: https://sg.run/krq7 semgrep.dev: rule: r_id: 15128 rv_id: 1263269 rule_id: nJUZNL version_id: X0TzypE url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key origin: community patterns: - pattern-either: - pattern: | $KEY = $G.getInstance("RSA") ... $KEY.initialize($BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048 - id: terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret message: Key vault Secret should have a content type set patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault_secret" "..." { ... content_type = "..." ... } - pattern-inside: | resource "azurerm_key_vault_secret" "..." { ... } metadata: category: correctness technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_secret#content_type - https://docs.microsoft.com/en-us/azure/key-vault/secrets/about-secrets license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret shortlink: https://sg.run/eoAb semgrep.dev: rule: r_id: 15132 rv_id: 946862 rule_id: 8GUzld version_id: JdTDP3Y url: https://semgrep.dev/playground/r/JdTDP3Y/terraform.azure.security.keyvault.keyvault-content-type-for-secret.keyvault-content-type-for-secret origin: community languages: - hcl severity: INFO - id: terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires message: Ensure that the expiration date is set on all keys patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault_key" "..." { ... expiration_date = "..." ... } - pattern-inside: | resource "azurerm_key_vault_key" "..." { ... } metadata: cwe: - 'CWE-262: Not Using Password Aging' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_key#expiration_date - https://docs.microsoft.com/en-us/powershell/module/az.keyvault/update-azkeyvaultkey?view=azps-5.8.0#example-1--modify-a-key-to-enable-it--and-set-the-expiration-date-and-tags subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires shortlink: https://sg.run/vq9A semgrep.dev: rule: r_id: 15133 rv_id: 946863 rule_id: gxUgXq version_id: 5PT94PR url: https://semgrep.dev/playground/r/5PT94PR/terraform.azure.security.keyvault.keyvault-ensure-key-expires.keyvault-ensure-key-expires origin: community languages: - hcl severity: INFO - id: terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires message: Ensure that the expiration date is set on all secrets patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault_secret" "..." { ... expiration_date = "..." ... } - pattern-not-inside: | resource "azurerm_key_vault_secret" "..." { ... expiration_date = ... ... } - pattern-inside: | resource "azurerm_key_vault_secret" "..." { ... } metadata: cwe: - 'CWE-262: Not Using Password Aging' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault_secret#expiration_date - https://docs.microsoft.com/en-us/azure/key-vault/secrets/about-secrets subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires shortlink: https://sg.run/d2RZ semgrep.dev: rule: r_id: 15134 rv_id: 1028693 rule_id: QrUdNy version_id: 0bTl7og url: https://semgrep.dev/playground/r/0bTl7og/terraform.azure.security.keyvault.keyvault-ensure-secret-expires.keyvault-ensure-secret-expires origin: community languages: - hcl severity: INFO - id: terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled message: Key vault should have purge protection enabled patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault" "..." { ... purge_protection_enabled = true ... } - pattern-either: - pattern-inside: | resource "azurerm_key_vault" "..." { ... } - pattern-inside: | resource "azurerm_key_vault" "..." { ... purge_protection_enabled = false ... } metadata: cwe: - 'CWE-693: Protection Mechanism Failure' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault#purge_protection_enabled - https://docs.microsoft.com/en-us/azure/key-vault/general/soft-delete-overview#purge-protection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled shortlink: https://sg.run/Z4xD semgrep.dev: rule: r_id: 15135 rv_id: 946865 rule_id: 3qUjw9 version_id: RGTAPQ7 url: https://semgrep.dev/playground/r/RGTAPQ7/terraform.azure.security.keyvault.keyvault-purge-enabled.keyvault-purge-enabled origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl message: Network ACLs allow you to reduce your exposure to risk by limiting what can access your key vault. The default action of the Network ACL should be set to deny for when IPs are not matched. Azure services can be allowed to bypass. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault" "..." { ... network_acls { ... default_action = "Deny" ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_key_vault" "..." { ... } - pattern-inside: | resource "azurerm_key_vault" "..." { ... network_acls { ... default_action = "Allow" ... } ... } metadata: cwe: - 'CWE-1220: Insufficient Granularity of Access Control' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/key_vault#network_acls - https://docs.microsoft.com/en-us/azure/key-vault/general/network-security owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl shortlink: https://sg.run/nKgX semgrep.dev: rule: r_id: 15136 rv_id: 1263802 rule_id: 4bU1jy version_id: GxTkeEE url: https://semgrep.dev/playground/r/GxTkeEE/terraform.azure.security.keyvault.keyvault-specify-network-acl.keyvault-specify-network-acl origin: community languages: - hcl severity: ERROR - id: json.aws.security.wildcard-assume-role.wildcard-assume-role patterns: - pattern-inside: | "Statement": [...] - pattern-inside: | {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} - pattern: | "Principal": {..., "AWS": "*", ...} message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone with your AWS account ID and the name of the role can assume the role. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - aws references: - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role shortlink: https://sg.run/7YEZ semgrep.dev: rule: r_id: 15138 rv_id: 1263256 rule_id: JDULx5 version_id: BjTkZoy url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role origin: community languages: - json severity: ERROR - id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role patterns: - pattern-inside: | resource "aws_iam_role" $NAME { ... } - pattern: assume_role_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-inside: | {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} - pattern: | "Principal": {..., "AWS": "*", ...} message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone with your AWS account ID and the name of the role can assume the role. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - aws references: - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role shortlink: https://sg.run/LXWr semgrep.dev: rule: r_id: 15139 rv_id: 1263749 rule_id: 5rUL1P version_id: LjTkg8D url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass message: Some Microsoft services that interact with storage accounts operate from networks that can't be granted access through network rules. To help this type of service work as intended, allow the set of trusted Microsoft services to bypass the network rules patterns: - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... network_rules { ... bypass = ["...", "AzureServices"] ... } ... } - pattern-not-inside: | resource "azurerm_storage_account_network_rules" "..." { ... bypass = ["...", "AzureServices"] ... } - pattern-either: - pattern-inside: | resource "azurerm_storage_account_network_rules" "..." { ... bypass = [$ANYTHING] ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... network_rules { ... bypass = [$ANYTHING] ... } ... } metadata: cwe: - 'CWE-1220: Insufficient Granularity of Access Control' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#bypass - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account_network_rules#bypass - https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security#trusted-microsoft-services owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass shortlink: https://sg.run/WpX4 semgrep.dev: rule: r_id: 15153 rv_id: 1263803 rule_id: GdUreY version_id: RGT0LGx url: https://semgrep.dev/playground/r/RGT0LGx/terraform.azure.security.storage.storage-allow-microsoft-service-bypass.storage-allow-microsoft-service-bypass origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging message: Storage Analytics logs detailed information about successful and failed requests to a storage service. This information can be used to monitor individual requests and to diagnose issues with a storage service. Requests are logged on a best-effort basis. patterns: - pattern-either: - pattern-inside: | resource "azurerm_storage_account" "..." { ... queue_properties { ... } ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... } - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... queue_properties { ... logging { ... } ... } ... } metadata: cwe: - 'CWE-778: Insufficient Logging' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#logging - https://docs.microsoft.com/en-us/azure/storage/common/storage-analytics-logging?tabs=dotnet owasp: - A10:2017 - Insufficient Logging & Monitoring - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging shortlink: https://sg.run/0yEv semgrep.dev: rule: r_id: 15154 rv_id: 1263806 rule_id: ReU3L9 version_id: DkTRb05 url: https://semgrep.dev/playground/r/DkTRb05/terraform.azure.security.storage.storage-queue-services-logging.storage-queue-services-logging origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0, 1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0 and TLS 1.1 are still supported for backward compatibility. This check will warn if the minimum TLS is not set to TLS1_2.' patterns: - pattern-either: - pattern-inside: | resource "azurerm_storage_account" "..." { ... min_tls_version = "$ANYTHING" ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... } - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... min_tls_version = "TLS1_2" ... } metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version - https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy shortlink: https://sg.run/KXD7 semgrep.dev: rule: r_id: 15155 rv_id: 1263807 rule_id: AbUQdL version_id: WrTqKpv url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy origin: community languages: - hcl severity: ERROR - id: python.lang.security.audit.python-reverse-shell.python-reverse-shell patterns: - pattern-either: - pattern: pty.spawn("$BINPATH",...) - pattern: subprocess.call(["$BINPATH",...],...) - metavariable-regex: metavariable: $BINPATH regex: /bin/.*?sh\b - pattern-inside: | import socket ... $S = socket.socket(...) ... $S.connect(($IP,$PORT),...) ... message: Semgrep found a Python reverse shell using $BINPATH to $IP at $PORT metadata: cwe: - 'CWE-553: Command Shell in Externally Accessible Directory' category: security technology: - python references: - https://cwe.mitre.org/data/definitions/553.html subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.python-reverse-shell.python-reverse-shell shortlink: https://sg.run/gYZJ semgrep.dev: rule: r_id: 15185 rv_id: 946375 rule_id: nJUZRY version_id: BjT1NZ4 url: https://semgrep.dev/playground/r/BjT1NZ4/python.lang.security.audit.python-reverse-shell.python-reverse-shell origin: community languages: - python severity: WARNING - id: scala.lang.security.audit.insecure-random.insecure-random metadata: cwe: - 'CWE-330: Use of Insufficiently Random Values' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - scala - cryptography resources: - https://find-sec-bugs.github.io/bugs.htm confidence: LOW references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.lang.security.audit.insecure-random.insecure-random shortlink: https://sg.run/JxAw semgrep.dev: rule: r_id: 15190 rv_id: 1263674 rule_id: gxUgDk version_id: jQTn5Px url: https://semgrep.dev/playground/r/jQTn5Px/scala.lang.security.audit.insecure-random.insecure-random origin: community message: Flags the use of a predictable random value from `scala.util.Random`. This can lead to vulnerabilities when used in security contexts, such as in a CSRF token, password reset token, or any other secret value. To fix this, use java.security.SecureRandom instead. severity: WARNING languages: - scala patterns: - pattern: | import scala.util.Random - id: scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - scala resources: - https://find-sec-bugs.github.io/bugs.htm confidence: LOW references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile shortlink: https://sg.run/5D1A semgrep.dev: rule: r_id: 15191 rv_id: 1263676 rule_id: QrUdOZ version_id: 9lT4bpj url: https://semgrep.dev/playground/r/9lT4bpj/scala.lang.security.audit.path-traversal-fromfile.path-traversal-fromfile origin: community message: Flags cases of possible path traversal. If an unfiltered parameter is passed into 'fromFile', file from an arbitrary filesystem location could be read. This could lead to sensitive data exposure and other provles. Instead, sanitize the user input instead of performing direct string concatenation. severity: WARNING languages: - scala patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $FILENAME = "..." + $VAR ... - pattern-inside: | $FILENAME = $VAR + "..." ... - pattern-inside: | $FILENAME = $STR.concat($VAR) ... - pattern-inside: | $FILENAME = "...".format(..., $VAR, ...) ... - pattern: Source.fromFile($FILENAME, ...) - patterns: - pattern-either: - pattern: Source.fromFile("..." + $VAR, ...) - pattern: Source.fromFile($VAR + "...", ...) - pattern: Source.fromFile($STR.concat($VAR), ...) - pattern: Source.fromFile("...".format(..., $VAR, ...), ...) - pattern-inside: | def $FUNC(..., $VAR: $TYPE, ...) = Action { ... } - id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set metadata: cwe: - 'CWE-780: Use of RSA Algorithm without OAEP' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - scala - cryptography resources: - https://blog.codacy.com/9-scala-security-issues/ confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set shortlink: https://sg.run/GO5p semgrep.dev: rule: r_id: 15192 rv_id: 1263677 rule_id: 3qUj1Q version_id: yeTxpoX url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set origin: community message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken encryption. This could lead to sensitive data exposure. Instead, use RSA with `OAEPWithMD5AndMGF1Padding` instead. severity: WARNING languages: - scala patterns: - pattern: | $VAR = $CIPHER.getInstance($MODE) - metavariable-regex: metavariable: $MODE regex: .*RSA/.*/NoPadding.* - id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" to the bucket props for Bucket construct $X' metadata: cwe: - 'CWE-311: Missing Encryption of Sensitive Data' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption shortlink: https://sg.run/eowX semgrep.dev: rule: r_id: 15276 rv_id: 1263903 rule_id: bwU8qz version_id: GxTkeRx url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption origin: community languages: - typescript severity: ERROR pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3' ... - pattern: const $X = new Bucket(...) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...}) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3' ... - pattern: const $X = new $Y.Bucket(...) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...}) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...}) - id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl message: Bucket $X is not set to enforce encryption-in-transit, if not explictly setting this on the bucket policy - the property "enforceSSL" should be set to true metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl shortlink: https://sg.run/vqBX semgrep.dev: rule: r_id: 15277 rv_id: 1263904 rule_id: NbUN8B version_id: RGT0Llg url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl origin: community languages: - ts severity: ERROR pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3'; ... - pattern: const $X = new Bucket(...) - pattern-not: | const $X = new Bucket(..., {enforceSSL: true}, ...) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3'; ... - pattern: const $X = new $Y.Bucket(...) - pattern-not: | const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...}) - id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption at rest for the queue.' metadata: category: security cwe: - 'CWE-311: Missing Encryption of Sensitive Data' technology: - AWS-CDK references: - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue shortlink: https://sg.run/d23P semgrep.dev: rule: r_id: 15278 rv_id: 1263905 rule_id: kxUwqO version_id: A8Tgd2W url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Queue} from '@aws-cdk/aws-sqs' ... - pattern: const $X = new Queue(...) - pattern-not: | const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-sqs' ... - pattern: const $X = new $Y.Queue(...) - pattern-not: | const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...}) - id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod message: Using the GrantPublicAccess method on bucket contruct $X will make the objects in the bucket world accessible. Verify if this is intentional. metadata: cwe: - 'CWE-306: Missing Authentication for Critical Function' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod shortlink: https://sg.run/Z4p7 semgrep.dev: rule: r_id: 15279 rv_id: 1263906 rule_id: wdUjZK version_id: BjTkZA7 url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3' ... - pattern: | const $X = new Bucket(...) ... $X.grantPublicAccess(...) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3' ... - pattern: | const $X = new $Y.Bucket(...) ... $X.grantPublicAccess(...) - id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public message: CodeBuild Project $X is set to have a public URL. This will make the build results, logs, artifacts publically accessible, including builds prior to the project being public. Ensure this is acceptable for the project. metadata: category: security cwe: - 'CWE-306: Missing Authentication for Critical Function' technology: - AWS-CDK references: - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public shortlink: https://sg.run/nK7G semgrep.dev: rule: r_id: 15280 rv_id: 1263907 rule_id: x8UxXZ version_id: DkTRbj1 url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Project} from '@aws-cdk/aws-codebuild' ... - pattern: | const $X = new Project(..., {..., badge: true, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-codebuild' ... - pattern: | const $X = new $Y.Project(..., {..., badge: true, ...}) - id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text mode: taint pattern-sinks: - pattern: | sqlalchemy.text(...) pattern-sources: - patterns: - pattern: | $X + $Y - metavariable-type: metavariable: $X type: string - patterns: - pattern: | $X + $Y - metavariable-type: metavariable: $Y type: string - patterns: - pattern: | f"..." - patterns: - pattern: | $X.format(...) - metavariable-type: metavariable: $X type: string - patterns: - pattern: | $X % $Y - metavariable-type: metavariable: $X type: string message: sqlalchemy.text passes the constructed SQL statement to the database mostly unchanged. This means that the usual SQL injection protections are not applied and this function is vulnerable to SQL injection if user input can reach here. Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct SQL. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - sqlalchemy confidence: MEDIUM references: - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text shortlink: https://sg.run/yP1O semgrep.dev: rule: r_id: 15824 rv_id: 1263577 rule_id: r6U2wE version_id: rxTAKqq url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text origin: community languages: - python severity: ERROR - id: terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption patterns: - pattern: resource "aws_athena_workgroup" $ANYTHING {...} - pattern-not-inside: | resource "aws_athena_workgroup" $ANYTHING { ... encryption_configuration {...} ... } message: 'The AWS Athena Workgroup is unencrypted. Encryption protects query results in your workgroup. To enable, add: `encryption_configuration { encryption_option = "SSE_KMS" kms_key_arn = aws_kms_key.example.arn }` within `result_configuration { }` in your resource block, where `encryption_option` is your chosen encryption method and `kms_key_arn` is your KMS key ARN.' languages: - hcl severity: WARNING metadata: technology: - aws - terraform category: security owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption shortlink: https://sg.run/kzro semgrep.dev: rule: r_id: 15828 rv_id: 946736 rule_id: wdUljO version_id: jQTzqko url: https://semgrep.dev/playground/r/jQTzqko/terraform.aws.security.missing-athena-workgroup-encryption.missing-athena-workgroup-encryption origin: community - id: terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging patterns: - pattern: | name = ... - pattern-inside: | resource "aws_eks_cluster" "..." { ... } - pattern-not-inside: | resource "aws_eks_cluster" "..." { ... enabled_cluster_log_types = [..., "api", ..., "audit", ...] ... } - pattern-not-inside: | resource "aws_eks_cluster" "..." { ... enabled_cluster_log_types = [..., "audit", ..., "api", ...] ... } languages: - hcl message: Missing EKS control plane logging. It is recommended to enable at least Kubernetes API server component logs ("api") and audit logs ("audit") of the EKS control plane through the enabled_cluster_log_types attribute. severity: WARNING metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eks_cluster#enabling-control-plane-logging - https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html category: security cwe: - 'CWE-778: Insufficient Logging' technology: - terraform - aws owasp: - A10:2017 - Insufficient Logging & Monitoring - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging shortlink: https://sg.run/wZ3n semgrep.dev: rule: r_id: 15829 rv_id: 1263886 rule_id: x8UGx7 version_id: O9Tpxxw url: https://semgrep.dev/playground/r/O9Tpxxw/terraform.lang.security.eks-insufficient-control-plane-logging.eks-insufficient-control-plane-logging origin: community - id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code pattern-either: - patterns: - pattern: password = "..." - pattern-inside: | resource "aws_db_instance" "..." { ... } - patterns: - pattern: master_password = "..." - pattern-inside: | resource "aws_rds_cluster" "..." { ... } languages: - hcl severity: WARNING message: RDS instance or cluster with hardcoded credentials in source code. It is recommended to pass the credentials at runtime, or generate random credentials using the random_password resource. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password - https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password cwe: - 'CWE-522: Insufficiently Protected Credentials' category: security technology: - terraform - aws - secrets owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code shortlink: https://sg.run/x4qA semgrep.dev: rule: r_id: 15830 rv_id: 1263896 rule_id: OrUl6W version_id: gETB77b url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code origin: community - id: terraform.lang.security.rds-public-access.rds-public-access patterns: - pattern: publicly_accessible = true - pattern-inside: | resource "aws_db_instance" "..." { ... } languages: - hcl severity: WARNING message: RDS instance accessible from the Internet detected. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#publicly_accessible - https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_VPC.WorkingWithRDSInstanceinaVPC.html#USER_VPC.Hiding cwe: - 'CWE-1220: Insufficient Granularity of Access Control' category: security technology: - terraform - aws owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.lang.security.rds-public-access.rds-public-access shortlink: https://sg.run/Oye2 semgrep.dev: rule: r_id: 15831 rv_id: 1263897 rule_id: eqUrzK version_id: QkTGqqJ url: https://semgrep.dev/playground/r/QkTGqqJ/terraform.lang.security.rds-public-access.rds-public-access origin: community - id: generic.ci.security.bash-reverse-shell.bash_reverse_shell metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - ci confidence: HIGH owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell shortlink: https://sg.run/4l9l semgrep.dev: rule: r_id: 16200 rv_id: 1262664 rule_id: gxUJrJ version_id: jQTn5QE url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell origin: community message: Semgrep found a bash reverse shell severity: ERROR languages: - generic pattern-either: - pattern: | sh -i >& /dev/udp/.../... 0>&1 - pattern: | <...>/dev/tcp/.../...; sh <&... >&... 2>& - pattern: | <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done - pattern: | sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& - id: ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection pattern: skip_forgery_protection message: This call turns off CSRF protection allowing CSRF attacks against the application languages: - ruby severity: WARNING metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' category: security technology: - rails references: - https://api.rubyonrails.org/classes/ActionController/RequestForgeryProtection/ClassMethods.html#method-i-skip_forgery_protection owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection shortlink: https://sg.run/PgwY semgrep.dev: rule: r_id: 16201 rv_id: 1263627 rule_id: QrUnEk version_id: pZT03ZD url: https://semgrep.dev/playground/r/pZT03ZD/ruby.rails.security.audit.rails-skip-forgery-protection.rails-skip-forgery-protection origin: community - id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket patterns: - pattern: a - pattern: b languages: - hcl severity: INFO message: This rule has been deprecated, as all s3 buckets are encrypted by default with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration for more info. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html cwe: - 'CWE-311: Missing Encryption of Sensitive Data' category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM deprecated: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket shortlink: https://sg.run/Jezw semgrep.dev: rule: r_id: 16202 rv_id: 1263901 rule_id: 3qU62L version_id: JdTzxjN url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket origin: community - id: php.lang.security.injection.tainted-filename.tainted-filename severity: WARNING message: File name based on user input risks server-side request forgery. metadata: technology: - php category: security cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename shortlink: https://sg.run/Ayqp semgrep.dev: rule: r_id: 16250 rv_id: 1263287 rule_id: 5rUpro version_id: 7ZTE3J1 url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: basename($PATH, ...) - pattern-inside: linkinfo($PATH, ...) - pattern-inside: readlink($PATH, ...) - pattern-inside: realpath($PATH, ...) pattern-sinks: - patterns: - pattern-either: - pattern-inside: opcache_compile_file($FILENAME, ...) - pattern-inside: opcache_invalidate($FILENAME, ...) - pattern-inside: opcache_is_script_cached($FILENAME, ...) - pattern-inside: runkit7_import($FILENAME, ...) - pattern-inside: readline_read_history($FILENAME, ...) - pattern-inside: readline_write_history($FILENAME, ...) - pattern-inside: rar_open($FILENAME, ...) - pattern-inside: zip_open($FILENAME, ...) - pattern-inside: gzfile($FILENAME, ...) - pattern-inside: gzopen($FILENAME, ...) - pattern-inside: readgzfile($FILENAME, ...) - pattern-inside: hash_file($ALGO, $FILENAME, ...) - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) - pattern-inside: pg_trace($FILENAME, ...) - pattern-inside: dio_open($FILENAME, ...) - pattern-inside: finfo_file($FINFO, $FILENAME, ...) - pattern-inside: mime_content_type($FILENAME, ...) - pattern-inside: chgrp($FILENAME, ...) - pattern-inside: chmod($FILENAME, ...) - pattern-inside: chown($FILENAME, ...) - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) - pattern-inside: file_exists($FILENAME, ...) - pattern-inside: file_get_contents($FILENAME, ...) - pattern-inside: file_put_contents($FILENAME, ...) - pattern-inside: file($FILENAME, ...) - pattern-inside: fileatime($FILENAME, ...) - pattern-inside: filectime($FILENAME, ...) - pattern-inside: filegroup($FILENAME, ...) - pattern-inside: fileinode($FILENAME, ...) - pattern-inside: filemtime($FILENAME, ...) - pattern-inside: fileowner($FILENAME, ...) - pattern-inside: fileperms($FILENAME, ...) - pattern-inside: filesize($FILENAME, ...) - pattern-inside: filetype($FILENAME, ...) - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) - pattern-inside: fopen($FILENAME, ...) - pattern-inside: is_dir($FILENAME, ...) - pattern-inside: is_executable($FILENAME, ...) - pattern-inside: is_file($FILENAME, ...) - pattern-inside: is_link($FILENAME, ...) - pattern-inside: is_readable($FILENAME, ...) - pattern-inside: is_uploaded_file($FILENAME, ...) - pattern-inside: is_writable($FILENAME, ...) - pattern-inside: lchgrp($FILENAME, ...) - pattern-inside: lchown($FILENAME, ...) - pattern-inside: lstat($FILENAME, ...) - pattern-inside: parse_ini_file($FILENAME, ...) - pattern-inside: readfile($FILENAME, ...) - pattern-inside: stat($FILENAME, ...) - pattern-inside: touch($FILENAME, ...) - pattern-inside: unlink($FILENAME, ...) - pattern-inside: xattr_get($FILENAME, ...) - pattern-inside: xattr_list($FILENAME, ...) - pattern-inside: xattr_remove($FILENAME, ...) - pattern-inside: xattr_set($FILENAME, ...) - pattern-inside: xattr_supported($FILENAME, ...) - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) - pattern-inside: pspell_new_personal($FILENAME, ...) - pattern-inside: exif_imagetype($FILENAME, ...) - pattern-inside: getimagesize($FILENAME, ...) - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) - pattern-inside: imagecreatefromavif($FILENAME, ...) - pattern-inside: imagecreatefrombmp($FILENAME, ...) - pattern-inside: imagecreatefromgd2($FILENAME, ...) - pattern-inside: imagecreatefromgd2part($FILENAME, ...) - pattern-inside: imagecreatefromgd($FILENAME, ...) - pattern-inside: imagecreatefromgif($FILENAME, ...) - pattern-inside: imagecreatefromjpeg($FILENAME, ...) - pattern-inside: imagecreatefrompng($FILENAME, ...) - pattern-inside: imagecreatefromtga($FILENAME, ...) - pattern-inside: imagecreatefromwbmp($FILENAME, ...) - pattern-inside: imagecreatefromwebp($FILENAME, ...) - pattern-inside: imagecreatefromxbm($FILENAME, ...) - pattern-inside: imagecreatefromxpm($FILENAME, ...) - pattern-inside: imageloadfont($FILENAME, ...) - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, ...) - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) - pattern-inside: fdf_open($FILENAME, ...) - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) - pattern-inside: posix_access($FILENAME, ...) - pattern-inside: posix_mkfifo($FILENAME, ...) - pattern-inside: posix_mknod($FILENAME, ...) - pattern-inside: ftok($FILENAME, ...) - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) - pattern-inside: fann_read_train_from_file($FILENAME, ...) - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) - pattern-inside: highlight_file($FILENAME, ...) - pattern-inside: php_strip_whitespace($FILENAME, ...) - pattern-inside: stream_resolve_include_path($FILENAME, ...) - pattern-inside: swoole_async_read($FILENAME, ...) - pattern-inside: swoole_async_readfile($FILENAME, ...) - pattern-inside: swoole_async_write($FILENAME, ...) - pattern-inside: swoole_async_writefile($FILENAME, ...) - pattern-inside: swoole_load_module($FILENAME, ...) - pattern-inside: tidy_parse_file($FILENAME, ...) - pattern-inside: tidy_repair_file($FILENAME, ...) - pattern-inside: get_meta_tags($FILENAME, ...) - pattern-inside: yaml_emit_file($FILENAME, ...) - pattern-inside: yaml_parse_file($FILENAME, ...) - pattern-inside: curl_file_create($FILENAME, ...) - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) - pattern-inside: ftp_delete($FTP, $FILENAME, ...) - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) - pattern-inside: ftp_size($FTP, $FILENAME, ...) - pattern-inside: rrd_create($FILENAME, ...) - pattern-inside: rrd_fetch($FILENAME, ...) - pattern-inside: rrd_graph($FILENAME, ...) - pattern-inside: rrd_info($FILENAME, ...) - pattern-inside: rrd_last($FILENAME, ...) - pattern-inside: rrd_lastupdate($FILENAME, ...) - pattern-inside: rrd_tune($FILENAME, ...) - pattern-inside: rrd_update($FILENAME, ...) - pattern-inside: snmp_read_mib($FILENAME, ...) - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) - pattern-inside: apache_lookup_uri($FILENAME, ...) - pattern-inside: md5_file($FILENAME, ...) - pattern-inside: sha1_file($FILENAME, ...) - pattern-inside: simplexml_load_file($FILENAME, ...) - pattern: $FILENAME - id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation languages: - php severity: WARNING message: <- A new object is created where the class name is based on user input. This could lead to remote code execution, as it allows to instantiate any class in the application. metadata: cwe: - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe Reflection'')' category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation shortlink: https://sg.run/7ndw semgrep.dev: rule: r_id: 16438 rv_id: 1263288 rule_id: v8U4DA version_id: LjTkgLy url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sinks: - patterns: - pattern-either: - pattern-inside: new $SINK(...) - pattern: $SINK - id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials patterns: - pattern-inside: | provider "aws" { ... secret_key = "$SECRET" } - focus-metavariable: $SECRET message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). languages: - hcl severity: WARNING metadata: technology: - secrets - aws - terraform category: security cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials shortlink: https://sg.run/L3kn semgrep.dev: rule: r_id: 16439 rv_id: 1263735 rule_id: d8U4n0 version_id: rxTAK76 url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials origin: community - id: ruby.rails.security.audit.detailed-exceptions.detailed-exceptions metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_detailed_exceptions.rb category: security technology: - rails references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/ruby.rails.security.audit.detailed-exceptions.detailed-exceptions shortlink: https://sg.run/Je0d semgrep.dev: rule: r_id: 16546 rv_id: 1263626 rule_id: 8GUAo4 version_id: zyTb2oJ url: https://semgrep.dev/playground/r/zyTb2oJ/ruby.rails.security.audit.detailed-exceptions.detailed-exceptions origin: community message: Found that the setting for providing detailed exception reports in Rails is set to true. This can lead to information exposure, where sensitive system or internal information is displayed to the end user. Instead, turn this setting off. languages: - ruby severity: WARNING patterns: - pattern-either: - patterns: - pattern: | config.consider_all_requests_local = true - patterns: - pattern-inside: | class $CONTROLLER < ApplicationController ... end - pattern: | def show_detailed_exceptions? (...) ... return $RETURN end - metavariable-pattern: metavariable: $RETURN patterns: - pattern-not: | false - id: php.laravel.security.laravel-sql-injection.laravel-sql-injection metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - laravel references: - https://laravel.com/docs/8.x/queries cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection shortlink: https://sg.run/x40p semgrep.dev: rule: r_id: 16830 rv_id: 1263313 rule_id: j2UQdp version_id: BjTkZ45 url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection origin: community severity: WARNING message: Detected a SQL query based on user input. This could lead to SQL injection, which could potentially result in sensitive data being exfiltrated by attackers. Instead, use parameterized queries and prepared statements. languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $SQL - pattern-either: - pattern-inside: DB::table(...)->whereRaw($SQL, ...) - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) - pattern-inside: DB::table(...)->havingRaw($SQL, ...) - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) - patterns: - pattern: $EXPRESSION - pattern-either: - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) - patterns: - pattern: $COLUMNS - pattern-either: - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) - pattern-inside: DB::table(...)->orWhereNull($COLUMN) - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) - pattern-inside: DB::table(...)->find($ID, $COLUMNS) - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) - pattern-inside: DB::table(...)->select($COLUMNS) - pattern-inside: DB::table(...)->get($COLUMNS) - pattern-inside: DB::table(...)->count($COLUMNS) - patterns: - pattern: $COLUMN - pattern-either: - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) - pattern-inside: DB::table(...)->having($COLUMN, ...) - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) - pattern-inside: DB::table(...)->orderByDesc($COLUMN) - pattern-inside: DB::table(...)->latest($COLUMN) - pattern-inside: DB::table(...)->oldest($COLUMN) - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) - pattern-inside: DB::table(...)->value($COLUMN) - pattern-inside: DB::table(...)->pluck($COLUMN, ...) - pattern-inside: DB::table(...)->implode($COLUMN, ...) - pattern-inside: DB::table(...)->min($COLUMN) - pattern-inside: DB::table(...)->max($COLUMN) - pattern-inside: DB::table(...)->sum($COLUMN) - pattern-inside: DB::table(...)->avg($COLUMN) - pattern-inside: DB::table(...)->average($COLUMN) - pattern-inside: DB::table(...)->increment($COLUMN, ...) - pattern-inside: DB::table(...)->decrement($COLUMN, ...) - pattern-inside: DB::table(...)->where($COLUMN, ...) - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) - pattern-inside: DB::table(...)->addSelect($COLUMN) - patterns: - pattern: $QUERY - pattern-inside: DB::unprepared($QUERY) - id: trailofbits.python.automatic-memory-pinning.automatic-memory-pinning message: If possible, it is better to rely on automatic pinning in PyTorch to avoid undefined behavior and for efficiency languages: - python severity: WARNING metadata: category: security cwe: 'CWE-676: Use of Potentially Dangerous Function' subcategory: - audit confidence: HIGH likelihood: LOW impact: LOW technology: - pytorch description: '`PyTorch` memory not automatically pinned' references: - https://pytorch.org/docs/stable/data.html#memory-pinning license: AGPL-3.0 license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/trailofbits.python.automatic-memory-pinning.automatic-memory-pinning shortlink: https://sg.run/jz5N semgrep.dev: rule: r_id: 17165 rv_id: 833289 rule_id: WAUN1Z version_id: gETy20E url: https://semgrep.dev/playground/r/gETy20E/trailofbits.python.automatic-memory-pinning.automatic-memory-pinning origin: community pattern-either: - patterns: - pattern: torch.utils.data.DataLoader(...) - pattern-not: torch.utils.data.DataLoader(..., pin_memory=$VALUE, ...) - pattern: torch.utils.data.DataLoader(..., pin_memory=False, ...) - id: trailofbits.python.lxml-in-pandas.lxml-in-pandas message: Found usage of the `$FLAVOR` library, which is vulnerable to attacks such as XML external entity (XXE) attacks languages: - python severity: ERROR metadata: category: security cwe: 'CWE-611: Improper Restriction of XML External Entity Reference' subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: MEDIUM technology: - pandas description: Potential XXE attacks from loading `lxml` in pandas references: - https://lxml.de/FAQ.html license: AGPL-3.0 license vulnerability_class: - XML Injection source: https://semgrep.dev/r/trailofbits.python.lxml-in-pandas.lxml-in-pandas shortlink: https://sg.run/1z1G semgrep.dev: rule: r_id: 17166 rv_id: 833290 rule_id: 0oUrdJ version_id: QkTkr22 url: https://semgrep.dev/playground/r/QkTkr22/trailofbits.python.lxml-in-pandas.lxml-in-pandas origin: community pattern-either: - patterns: - pattern: pandas.read_html($IO) - pattern-not: pandas.read_html(**$KWARGS) - patterns: - metavariable-pattern: metavariable: $FLAVOR patterns: - pattern: '...' - pattern-not: | "bs4" - pattern-not: | "html5lib" - pattern-either: - pattern: pandas.read_html(..., flavor=$FLAVOR, ...) - patterns: - pattern-inside: | $KWARGS = {..., "flavor": $FLAVOR, ...} ... - pattern: | pandas.read_html(**$KWARGS) - id: trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules message: Usage of NumPy library inside PyTorch `$MODULE` module was found. Avoid mixing these libraries for efficiency and proper ONNX loading languages: - python severity: WARNING metadata: category: performance subcategory: - audit confidence: MEDIUM technology: - pytorch - numpy description: Uses of `NumPy` functions inside `PyTorch` modules references: - https://tanelp.github.io/posts/a-bug-that-plagues-thousands-of-open-source-ml-projects license: AGPL-3.0 license source: https://semgrep.dev/r/trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules shortlink: https://sg.run/9vxr semgrep.dev: rule: r_id: 17167 rv_id: 833295 rule_id: KxU507 version_id: 5PTyDEK url: https://semgrep.dev/playground/r/5PTyDEK/trailofbits.python.numpy-in-pytorch-modules.numpy-in-pytorch-modules origin: community patterns: - pattern-either: - pattern: numpy.$FN(...) - pattern: numpy. ... .$FN(...) - pattern-inside: | class $MODULE(torch.nn.Module): ... - id: trailofbits.python.pickles-in-numpy.pickles-in-numpy message: Functions reliant on pickle can result in arbitrary code execution. Consider using fickling or switching to a safer serialization method languages: - python severity: ERROR metadata: category: security cwe: 'CWE-502: Deserialization of Untrusted Data' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: HIGH technology: - numpy description: Potential arbitrary code execution from `NumPy` functions reliant on pickling references: - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ license: AGPL-3.0 license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/trailofbits.python.pickles-in-numpy.pickles-in-numpy shortlink: https://sg.run/ryKe semgrep.dev: rule: r_id: 17169 rv_id: 833301 rule_id: lBUWjy version_id: WrTdpJ9 url: https://semgrep.dev/playground/r/WrTdpJ9/trailofbits.python.pickles-in-numpy.pickles-in-numpy origin: community patterns: - pattern: numpy.load(..., allow_pickle=$VALUE, ...) - pattern-not: numpy.load("...", ...) - pattern-not: numpy.load(..., file="...", ...) - metavariable-pattern: metavariable: $VALUE patterns: - pattern-not: | False - pattern-not: | [] - pattern-not: | None - pattern-not: | "" - id: trailofbits.python.pickles-in-pandas.pickles-in-pandas message: Functions reliant on pickle can result in arbitrary code execution. Consider using fickling or switching to a safer serialization method languages: - python severity: ERROR metadata: category: security cwe: 'CWE-502: Deserialization of Untrusted Data' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: HIGH technology: - pandas description: Potential arbitrary code execution from `Pandas` functions reliant on pickling references: - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ license: AGPL-3.0 license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/trailofbits.python.pickles-in-pandas.pickles-in-pandas shortlink: https://sg.run/bXQW semgrep.dev: rule: r_id: 17170 rv_id: 833302 rule_id: PeU06j version_id: 0bTwbqN url: https://semgrep.dev/playground/r/0bTwbqN/trailofbits.python.pickles-in-pandas.pickles-in-pandas origin: community patterns: - pattern-either: - pattern: pandas.read_pickle(...) - pattern: pandas.to_pickle(...) - patterns: - pattern-inside: | import pandas ... - pattern: $SMTH.to_pickle(...) - pattern-not: pandas.read_pickle("...") - pattern-not: pandas.to_pickle(..., "...") - pattern-not: $SMTH.to_pickle("...") - id: trailofbits.python.pickles-in-pytorch.pickles-in-pytorch message: Functions reliant on pickle can result in arbitrary code execution. Consider loading from `state_dict`, using fickling, or switching to a safer serialization method like ONNX languages: - python severity: ERROR metadata: category: security cwe: 'CWE-502: Deserialization of Untrusted Data' subcategory: - vuln confidence: MEDIUM likelihood: MEDIUM impact: HIGH technology: - pytorch description: Potential arbitrary code execution from `PyTorch` functions reliant on pickling references: - https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files/ license: AGPL-3.0 license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/trailofbits.python.pickles-in-pytorch.pickles-in-pytorch shortlink: https://sg.run/NwQy semgrep.dev: rule: r_id: 17171 rv_id: 833304 rule_id: JDU6WD version_id: qkTQnJ3 url: https://semgrep.dev/playground/r/qkTQnJ3/trailofbits.python.pickles-in-pytorch.pickles-in-pytorch origin: community patterns: - pattern-either: - pattern: torch.save(...) - pattern: torch.load(...) - pattern-not: torch.load("...") - pattern-not: torch.save(..., "...") - pattern-not: torch.save($M.state_dict(), ...) - pattern-not-inside: $M.load_state_dict(...) - pattern-not: patterns: - pattern: torch.save($STATE_DICT, ...) - pattern-inside: | $STATE_DICT = $M.state_dict() ... - id: trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable message: Variable `$X` is likely modified and later used on error. In some cases this could result in panics due to a nil dereference languages: - go severity: WARNING metadata: category: security cwe: 'CWE-665: Improper Initialization' subcategory: - audit confidence: HIGH likelihood: MEDIUM impact: MEDIUM technology: - --no-technology-- description: Possible unintentional assignment when an error occurs references: - https://blog.trailofbits.com/2019/11/07/attacking-go-vr-ttps/ license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable shortlink: https://sg.run/WWQ2 semgrep.dev: rule: r_id: 17197 rv_id: 833265 rule_id: kxU6Xb version_id: zyTWJNZ url: https://semgrep.dev/playground/r/zyTWJNZ/trailofbits.go.invalid-usage-of-modified-variable.invalid-usage-of-modified-variable origin: community patterns: - pattern: | ..., $X, ..., $ERR = ... if $ERR != nil { ... <... $X.$Y ...> } - pattern-not: | ..., $X, ..., $ERR = ... if $ERR != nil { ... $X, ... = ... ... <... $X.$Y ...> } - pattern-not: | ..., $X, ..., $ERR = ... if $ERR != nil { ... $X = ... ... <... $X.$Y ...> } - pattern-not: | ..., $X, ..., $ERR = ... if $ERR != nil { ... if $X != nil { <... $X.$Y ...> } ... } - pattern-not: | ..., $X, ..., $ERR := ... if $ERR != nil { ... if $X != nil && <... $X.$Y ...> { ... } ... } - id: trailofbits.go.iterate-over-empty-map.iterate-over-empty-map message: Iteration over a possibly empty map `$C`. This is likely a bug or redundant code languages: - go severity: WARNING metadata: category: security cwe: 'CWE-665: Improper Initialization' subcategory: - audit confidence: MEDIUM likelihood: LOW impact: LOW technology: - --no-technology-- description: Probably redundant iteration over an empty map references: - https://blog.trailofbits.com/2019/11/07/attacking-go-vr-ttps/ license: AGPL-3.0 license vulnerability_class: - Other source: https://semgrep.dev/r/trailofbits.go.iterate-over-empty-map.iterate-over-empty-map shortlink: https://sg.run/08jj semgrep.dev: rule: r_id: 17198 rv_id: 1039527 rule_id: wdUlww version_id: ExTNqnL url: https://semgrep.dev/playground/r/ExTNqnL/trailofbits.go.iterate-over-empty-map.iterate-over-empty-map origin: community patterns: - pattern: | $C = make(map[$T1] $T2) ... for $K := range $C { ... } - pattern-not: | $C = make(map[$T1] $T2, ...) ... $C[$X] = $V ... for $K := range $C { ... } - pattern-not: | $C = make(map[$T1] $T2, ...) ... $C[$X]++ ... for $K := range $C { ... } - pattern-not: | $C = make(map[$T1] $T2, ...) ... $C[$X]-- ... for $K := range $C { ... } - pattern-not: | $C = make(map[$T1] $T2, ...) ... $CODEC.Unmarshal($BYTES, &$C) ... for $K := range $C { ... } - id: csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug message: ASP.NET applications built with `debug` set to true in production may leak debug information to attackers. Debug mode also affects performance and reliability. Set `debug` to `false` or remove it from `` severity: WARNING metadata: likelihood: LOW impact: LOW confidence: LOW category: security cwe: - 'CWE-11: ASP.NET Misconfiguration: Creating Debug Binary' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://web.archive.org/web/20190919105353/https://blogs.msdn.microsoft.com/prashant_upadhyay/2011/07/14/why-debugfalse-in-asp-net-applications-in-production-environment/ - https://msdn.microsoft.com/en-us/library/e8z01xdh.aspx subcategory: - audit technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug shortlink: https://sg.run/yPWx semgrep.dev: rule: r_id: 17324 rv_id: 1262620 rule_id: 0oUrvj version_id: jQTn53E url: https://semgrep.dev/playground/r/jQTn53E/csharp.dotnet.security.net-webconfig-debug.net-webconfig-debug origin: community languages: - generic paths: include: - '*web.config*' patterns: - pattern: | - pattern-inside: | ... - id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use HMAC instead. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::java.security owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 shortlink: https://sg.run/ryJn semgrep.dev: rule: r_id: 17325 rv_id: 1263013 rule_id: KxU5lW version_id: 0bTKzGX url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 origin: community patterns: - pattern: | java.security.MessageDigest.getInstance($ALGO, ...); - metavariable-regex: metavariable: $ALGO regex: (?i)(.MD5.) - focus-metavariable: $ALGO fix: | "SHA-512" - id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function applications. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::javax.crypto owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 shortlink: https://sg.run/bXNp semgrep.dev: rule: r_id: 17326 rv_id: 1263016 rule_id: qNUWNn version_id: l4TJRpL url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 origin: community pattern-either: - patterns: - pattern: | java.security.MessageDigest.getInstance("$ALGO", ...); - metavariable-regex: metavariable: $ALGO regex: (SHA1|SHA-1) - pattern: | $DU.getSha1Digest().digest(...) - id: java.lang.security.audit.crypto.weak-random.weak-random message: Detected use of the functions `Math.random()` or `java.util.Random()`. These are both not cryptographically strong random number generators (RNGs). If you are using these RNGs to create passwords or secret tokens, use `java.security.SecureRandom` instead. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::randomness::java.security owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-330: Use of Insufficiently Random Values' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-random.weak-random shortlink: https://sg.run/NwBp semgrep.dev: rule: r_id: 17327 rv_id: 1263018 rule_id: lBUW5D version_id: 6xT29RK url: https://semgrep.dev/playground/r/6xT29RK/java.lang.security.audit.crypto.weak-random.weak-random origin: community pattern-either: - pattern: | new java.util.Random(...).$FUNC(...) - pattern: | java.lang.Math.random(...) - id: php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate patterns: - pattern: openssl_decrypt(...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... if($DECRYPTED_STRING === false){ ... } - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... if($DECRYPTED_STRING == false){ ... } - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... if(false === $DECRYPTED_STRING){ ... } - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... if(false == $DECRYPTED_STRING){ ... } - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... assertTrue(false !== $DECRYPTED_STRING,...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... assertTrue($DECRYPTED_STRING !== false,...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... $REFERENCE::assertTrue(false !== $DECRYPTED_STRING,...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... $REFERENCE::assertTrue($DECRYPTED_STRING !== false,...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... assert(false !== $DECRYPTED_STRING,...); - pattern-not-inside: | $DECRYPTED_STRING = openssl_decrypt(...); ... assert($DECRYPTED_STRING !== false,...); message: The function `openssl_decrypt` returns either a string of the decrypted data on success or `false` on failure. If the failure case is not handled, this could lead to undefined behavior in your application. Please handle the case where `openssl_decrypt` returns `false`. languages: - php severity: WARNING metadata: references: - https://www.php.net/manual/en/function.openssl-decrypt.php cwe: - 'CWE-252: Unchecked Return Value' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures technology: - php - openssl category: security subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate shortlink: https://sg.run/kzn7 semgrep.dev: rule: r_id: 17328 rv_id: 1263274 rule_id: YGUAoe version_id: rxTAKXz url: https://semgrep.dev/playground/r/rxTAKXz/php.lang.security.audit.openssl-decrypt-validate.openssl-decrypt-validate origin: community - id: scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run patterns: - pattern-either: - pattern: $X.! - pattern: $X.!! - pattern: $X.lazyLines - pattern-inside: | import sys.process ... - pattern-not: | "...".! - pattern-not: | "...".!! - pattern-not: | "...".lazyLines - pattern-not: | Seq(...).! - pattern-not: | Seq(...).!! - pattern-not: | Seq(...).lazyLines - pattern-not-inside: | val $X = "..." ... - pattern-not-inside: | val $X = Seq(...) ... message: Found dynamic content used for the external process. This is dangerous if arbitrary data can reach this function call because it allows a malicious actor to execute commands. Use `Seq(...)` for dynamically generated commands. languages: - scala severity: ERROR metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - scala confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run shortlink: https://sg.run/wZBY semgrep.dev: rule: r_id: 17329 rv_id: 1263679 rule_id: 6JUEeo version_id: bZT53y0 url: https://semgrep.dev/playground/r/bZT53y0/scala.lang.security.audit.scala-dangerous-process-run.scala-dangerous-process-run origin: community - id: terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted patterns: - pattern: | resource "aws_athena_workgroup" $ANYTHING { ... configuration { ... result_configuration { ... } ... } ... } - pattern-not-inside: | resource "aws_athena_workgroup" $ANYTHING { ... configuration { ... result_configuration { ... encryption_configuration { ... } ... } ... } ... } message: The AWS Athena Work Group is unencrypted. The AWS KMS encryption key protects backups in the work group. To create your own, create a aws_kms_key resource or use the ARN string of a key in your account. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: MEDIUM confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted shortlink: https://sg.run/gX7J semgrep.dev: rule: r_id: 17341 rv_id: 1263699 rule_id: NbUXOA version_id: JdTzx8e url: https://semgrep.dev/playground/r/JdTzx8e/terraform.aws.security.aws-athena-workgroup-unencrypted.aws-athena-workgroup-unencrypted origin: community - id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version patterns: - pattern: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2018" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2019" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2021" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2025" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.3_2025" ... } ... } message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS versions less than 1.2 are considered insecure because they can be broken. To fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019", "TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version shortlink: https://sg.run/Q6o4 semgrep.dev: rule: r_id: 17342 rv_id: 1263700 rule_id: kxU6A8 version_id: 5PTo1bY url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk patterns: - pattern: | resource "aws_cloudtrail" $ANYTHING { ... } - pattern-not-inside: | resource "aws_cloudtrail" $ANYTHING { ... kms_key_id = ... ... } message: Ensure CloudTrail logs are encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk shortlink: https://sg.run/38kr semgrep.dev: rule: r_id: 17343 rv_id: 946664 rule_id: wdUl2j version_id: A8TJzbz url: https://semgrep.dev/playground/r/A8TJzbz/terraform.aws.security.aws-cloudtrail-encrypted-with-cmk.aws-cloudtrail-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention patterns: - pattern: | resource "aws_cloudwatch_log_group" $ANYTHING { ... } - pattern-not-inside: | resource "aws_cloudwatch_log_group" $ANYTHING { ... retention_in_days = ... ... } message: The AWS CloudWatch Log Group has no retention. Missing retention in log groups can cause losing important event information. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention shortlink: https://sg.run/4lwl semgrep.dev: rule: r_id: 17344 rv_id: 946665 rule_id: x8UGBG version_id: BjT1N2B url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention origin: community - id: terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted patterns: - pattern: | resource "aws_cloudwatch_log_group" $ANYTHING { ... } - pattern-not-inside: | resource "aws_cloudwatch_log_group" $ANYTHING { ... kms_key_id = ... ... } message: By default, AWS CloudWatch Log Group is encrypted using AWS-managed keys. However, for added security, it's recommended to configure your own AWS KMS encryption key to protect your log group in CloudWatch. You can either create a new aws_kms_key resource or use the ARN of an existing key in your AWS account to do so. languages: - hcl severity: WARNING metadata: owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' technology: - aws - terraform category: security references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted shortlink: https://sg.run/Pg6Y semgrep.dev: rule: r_id: 17345 rv_id: 1263701 rule_id: OrUl0J version_id: GxTkep4 url: https://semgrep.dev/playground/r/GxTkep4/terraform.aws.security.aws-cloudwatch-log-group-unencrypted.aws-cloudwatch-log-group-unencrypted origin: community - id: terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted patterns: - pattern: | resource "aws_codebuild_project" $ANYTHING { ... artifacts { ... encryption_disabled = true ... } ... } - pattern-not-inside: | resource "aws_codebuild_project" $ANYTHING { ... artifacts { type = "NO_ARTIFACTS" encryption_disabled = true } ... } - pattern-not-inside: | resource "aws_codebuild_project" $ANYTHING { ... artifacts { type = "NO_ARTIFACTS" } ... } message: The AWS CodeBuild Project Artifacts are unencrypted. The AWS KMS encryption key protects artifacts in the CodeBuild Projects. To create your own, create a aws_kms_key resource or use the ARN string of a key in your account. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted shortlink: https://sg.run/JeWw semgrep.dev: rule: r_id: 17346 rv_id: 946668 rule_id: eqUrdZ version_id: 0bT15Wr url: https://semgrep.dev/playground/r/0bT15Wr/terraform.aws.security.aws-codebuild-project-artifacts-unencrypted.aws-codebuild-project-artifacts-unencrypted origin: community - id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted patterns: - pattern: | resource "aws_codebuild_project" $ANYTHING { ... } - pattern-not-inside: | resource "aws_codebuild_project" $ANYTHING { ... encryption_key = ... ... } message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects projects in the CodeBuild. To create your own, create a aws_kms_key resource or use the ARN string of a key in your account. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted shortlink: https://sg.run/5yxA semgrep.dev: rule: r_id: 17347 rv_id: 946669 rule_id: v8U4kG version_id: K3TJbNr url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted origin: community - id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging patterns: - pattern: | resource "aws_db_instance" $ANYTHING { ... } - pattern-not-inside: | resource "aws_db_instance" $ANYTHING { ... enabled_cloudwatch_logs_exports = [$SOMETHING, ...] ... } message: Database instance has no logging. Missing logs can cause missing important event information. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - vuln likelihood: MEDIUM impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging shortlink: https://sg.run/GyAp semgrep.dev: rule: r_id: 17348 rv_id: 1263704 rule_id: d8U4RA version_id: BjTkZ6j url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging origin: community - id: terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk patterns: - pattern: | resource "aws_docdb_cluster" $ANYTHING { ... } - pattern-not-inside: | resource "aws_docdb_cluster" $ANYTHING { ... kms_key_id = ... ... } message: Ensure DocDB is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk shortlink: https://sg.run/RyzO semgrep.dev: rule: r_id: 17349 rv_id: 946672 rule_id: ZqUGEp version_id: YDTvRX2 url: https://semgrep.dev/playground/r/YDTvRX2/terraform.aws.security.aws-docdb-encrypted-with-cmk.aws-docdb-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted patterns: - pattern: | resource "aws_dynamodb_table" $ANYTHING { ... } - pattern-not-inside: | resource "aws_dynamodb_table" $ANYTHING { ... server_side_encryption { enabled = true kms_key_arn = ... } ... } message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However, for added security, it's recommended to configure your own AWS KMS encryption key to protect your data in the DynamoDB table. You can either create a new aws_kms_key resource or use the ARN of an existing key in your AWS account to do so. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted shortlink: https://sg.run/Ay4p semgrep.dev: rule: r_id: 17350 rv_id: 1263707 rule_id: nJUGe2 version_id: 0bTKzj8 url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted origin: community - id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk patterns: - pattern: | resource "aws_ebs_snapshot_copy" $ANYTHING { ... encrypted = true ... } - pattern-not-inside: | resource "aws_ebs_snapshot_copy" $ANYTHING { ... encrypted = true kms_key_id = ... ... } message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk shortlink: https://sg.run/ByPW semgrep.dev: rule: r_id: 17351 rv_id: 946677 rule_id: EwUqko version_id: A8TJzb0 url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted patterns: - pattern: | resource "aws_ebs_encryption_by_default" $ANYTHING { ... enabled = false ... } message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the EBS. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted shortlink: https://sg.run/Dy5Y semgrep.dev: rule: r_id: 17352 rv_id: 946678 rule_id: 7KUW7K version_id: BjT1N2v url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted origin: community - id: terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk patterns: - pattern: | resource "aws_ebs_volume" $ANYTHING { ... encrypted = true ... } - pattern-not-inside: | resource "aws_ebs_volume" $ANYTHING { ... encrypted = true kms_key_id = ... ... } message: Ensure EBS Volume is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk shortlink: https://sg.run/WW14 semgrep.dev: rule: r_id: 17353 rv_id: 946679 rule_id: L1UPY9 version_id: DkTNpzv url: https://semgrep.dev/playground/r/DkTNpzv/terraform.aws.security.aws-ebs-volume-encrypted-with-cmk.aws-ebs-volume-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip patterns: - pattern-either: - pattern: | resource "aws_instance" $ANYTHING { ... associate_public_ip_address = true ... } - pattern: | resource "aws_launch_template" $ANYTHING { ... network_interfaces { ... associate_public_ip_address = true ... } ... } message: EC2 instances should not have a public IP address attached in order to block public access to the instances. To fix this, set your `associate_public_ip_address` to `"false"`. metadata: category: security technology: - terraform - aws owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip shortlink: https://sg.run/08rv semgrep.dev: rule: r_id: 17354 rv_id: 1263709 rule_id: 8GUA2n version_id: qkTR73G url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk patterns: - pattern: | resource "aws_efs_file_system" $ANYTHING { ... encrypted = true ... } - pattern-not-inside: | resource "aws_efs_file_system" $ANYTHING { ... encrypted = true kms_key_id = ... ... } message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk shortlink: https://sg.run/Kk07 semgrep.dev: rule: r_id: 17355 rv_id: 946690 rule_id: gxUJ4n version_id: 2KTYbWy url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled patterns: - pattern-either: - pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... node_to_node_encryption { ... enabled = false ... } ... } - pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... cluster_config { ... instance_count = $COUNT ... } } - pattern-not-inside: | resource "aws_elasticsearch_domain" $ANYTHING { ... cluster_config { ... instance_count = $COUNT ... } node_to_node_encryption { ... enabled = true ... } } - metavariable-comparison: metavariable: $COUNT comparison: $COUNT > 1 message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t" metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled shortlink: https://sg.run/lp3y semgrep.dev: rule: r_id: 17357 rv_id: 1263719 rule_id: 3qU6J7 version_id: WrTqK0v url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled patterns: - pattern-either: - pattern: | resource "aws_lb" $ANYTHING { ... } - pattern: | resource "aws_alb" $ANYTHING { ... } - pattern-not-inside: | resource $ANYLB $ANYTHING { ... access_logs { ... enabled = true ... } ... } - pattern-not-inside: "resource $ANYLB $ANYTHING {\n ...\n subnet_mapping {\n \ ...\n }\n ...\n} \n" message: ELB has no logging. Missing logs can cause missing important event information. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled shortlink: https://sg.run/Yrye semgrep.dev: rule: r_id: 17358 rv_id: 1263720 rule_id: 4bUg3J version_id: 0bTKzj4 url: https://semgrep.dev/playground/r/0bTKzj4/terraform.aws.security.aws-elb-access-logs-not-enabled.aws-elb-access-logs-not-enabled origin: community - id: terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk patterns: - pattern-inside: | resource "aws_emr_security_configuration" $ANYTHING { ... } - pattern: configuration = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | "AwsKmsKey": ... message: Ensure EMR is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk shortlink: https://sg.run/6gOo semgrep.dev: rule: r_id: 17359 rv_id: 946694 rule_id: PeU0L7 version_id: 9lTy1D0 url: https://semgrep.dev/playground/r/9lTy1D0/terraform.aws.security.aws-emr-encrypted-with-cmk.aws-emr-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk patterns: - pattern: | resource "aws_fsx_lustre_file_system" $ANYTHING { ... } - pattern-not-inside: | resource "aws_fsx_lustre_file_system" $ANYTHING { ... kms_key_id = ... ... } - pattern-regex: (^aws_kms_key\.(.*)) message: Ensure FSX Lustre file system is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk shortlink: https://sg.run/oNG9 semgrep.dev: rule: r_id: 17360 rv_id: 1263721 rule_id: JDU6gw version_id: K3TKk1l url: https://semgrep.dev/playground/r/K3TKk1l/terraform.aws.security.aws-fsx-lustre-files-ystem.aws-fsx-lustre-filesystem-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk patterns: - pattern: | resource "aws_fsx_lustre_file_system" $ANYTHING { ... } - pattern-not-inside: | resource "aws_fsx_lustre_file_system" $ANYTHING { ... kms_key_id = ... ... } message: Ensure FSX Lustre file system is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk shortlink: https://sg.run/zJ6G semgrep.dev: rule: r_id: 17361 rv_id: 1263722 rule_id: 5rUp50 version_id: qkTR73q url: https://semgrep.dev/playground/r/qkTR73q/terraform.aws.security.aws-fsx-lustre-filesystem-encrypted-with-cmk.aws-fsx-lustre-filesystem-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk patterns: - pattern: | resource "aws_fsx_ontap_file_system" $ANYTHING { ... } - pattern-not-inside: | resource "aws_fsx_ontap_file_system" $ANYTHING { ... kms_key_id = ... ... } message: Ensure FSX ONTAP file system is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk shortlink: https://sg.run/pyRg semgrep.dev: rule: r_id: 17362 rv_id: 946697 rule_id: GdUzwK version_id: bZTXw0d url: https://semgrep.dev/playground/r/bZTXw0d/terraform.aws.security.aws-fsx-ontapfs-encrypted-with-cmk.aws-fsx-ontapfs-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk patterns: - pattern: | resource "aws_fsx_windows_file_system" $ANYTHING { ... } - pattern-not-inside: | resource "aws_fsx_windows_file_system" $ANYTHING { ... kms_key_id = ... ... } message: Ensure FSX Windows file system is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk shortlink: https://sg.run/2pN0 semgrep.dev: rule: r_id: 17363 rv_id: 946698 rule_id: ReUqv6 version_id: NdTqknl url: https://semgrep.dev/playground/r/NdTqknl/terraform.aws.security.aws-fsx-windows-encrypted-with-cmk.aws-fsx-windows-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal patterns: - pattern-inside: | resource "aws_glacier_vault" $ANYTHING { ... } - pattern: access_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-inside: | {..., "Effect": "Allow", ...} - pattern-either: - pattern: | "Principal": "*" - pattern: | "Principal": {..., "AWS": "*", ...} - pattern-inside: | "Principal": {..., "AWS": ..., ...} - pattern-regex: | (^\"arn:aws:iam::\*:(.*)\"$) message: 'Detected wildcard access granted to Glacier Vault. This means anyone within your AWS account ID can perform actions on Glacier resources. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::`.' metadata: category: security technology: - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal shortlink: https://sg.run/XN9K semgrep.dev: rule: r_id: 17364 rv_id: 1263723 rule_id: AbUeYK version_id: l4TJRGB url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin patterns: - pattern-inside: | resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING { ... } - pattern: inline_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} - pattern: | {..., "Action": "*", "Resource": "*", ...} - pattern: | {..., "Action": "*", "Resource": [...], ...} - pattern: | {..., "Action": [...], "Resource": "*", ...} message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative actions. Instead, limit actions and resources to what you need according to least privilege. metadata: category: security technology: - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin shortlink: https://sg.run/jzgY semgrep.dev: rule: r_id: 17365 rv_id: 1263724 rule_id: BYUzY5 version_id: YDTZe9q url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy patterns: - pattern-inside: | resource "aws_iam_policy" $ANYTHING { ... } - pattern: policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} - pattern: | {..., "Action": "*", "Resource": "*", ...} - pattern: | {..., "Action": "*", "Resource": [...], ...} - pattern: | {..., "Action": [...], "Resource": "*", ...} message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative actions. Instead, limit actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy shortlink: https://sg.run/1zbw semgrep.dev: rule: r_id: 17366 rv_id: 1263725 rule_id: DbUx8l version_id: 6xT29Pv url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk patterns: - pattern: | resource "aws_imagebuilder_component" $ANYTHING { ... } - pattern-not-inside: | resource "aws_imagebuilder_component" $ANYTHING { ... kms_key_id = ... ... } message: Ensure ImageBuilder component is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk shortlink: https://sg.run/9vdY semgrep.dev: rule: r_id: 17367 rv_id: 946702 rule_id: WAUNxL version_id: O9TX3o0 url: https://semgrep.dev/playground/r/O9TX3o0/terraform.aws.security.aws-imagebuilder-component-encrypted-with-cmk.aws-imagebuilder-component-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration patterns: - pattern: | resource "aws_redshift_parameter_group" $ANYTHING { ... } - pattern-not-inside: | resource "aws_redshift_parameter_group" $ANYTHING { ... parameter { name = "require_ssl" value = "true" } ... } - pattern-not-inside: | resource "aws_redshift_parameter_group" $ANYTHING { ... parameter { name = "require_ssl" value = true } ... } message: Detected an AWS Redshift configuration with a SSL disabled. To fix this, set your `require_ssl` to `"true"`. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration shortlink: https://sg.run/yPYx semgrep.dev: rule: r_id: 17368 rv_id: 1263727 rule_id: 0oUrOj version_id: zyTb27A url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk patterns: - pattern: | resource "aws_kinesis_stream" $ANYTHING { ... } - pattern-not-inside: | resource "aws_kinesis_stream" $ANYTHING { ... kms_key_id = ... ... } message: Ensure Kinesis stream is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk shortlink: https://sg.run/ryBn semgrep.dev: rule: r_id: 17369 rv_id: 946705 rule_id: KxU5yW version_id: d6TPzwr url: https://semgrep.dev/playground/r/d6TPzwr/terraform.aws.security.aws-kinesis-stream-encrypted-with-cmk.aws-kinesis-stream-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk patterns: - pattern: | resource "aws_kinesis_video_stream" $ANYTHING { ... } - pattern-not-inside: | resource "aws_kinesis_video_stream" $ANYTHING { ... kms_key_id = ... ... } message: Ensure Kinesis video stream is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk shortlink: https://sg.run/bXvp semgrep.dev: rule: r_id: 17370 rv_id: 946707 rule_id: qNUWqn version_id: nWTpYW8 url: https://semgrep.dev/playground/r/nWTpYW8/terraform.aws.security.aws-kinesis-video-stream-encrypted-with-cmk.aws-kinesis-video-stream-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal patterns: - pattern-inside: | resource "aws_kms_key" $ANYTHING { ... } - pattern: policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...} message: Detected wildcard access granted in your KMS key. This means anyone with this policy can perform administrative actions over the keys. Instead, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal shortlink: https://sg.run/Nwlp semgrep.dev: rule: r_id: 17371 rv_id: 1263729 rule_id: lBUWPD version_id: 2KTv2J4 url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation patterns: - pattern-either: - pattern: | resource "aws_kms_key" $ANYTHING { ... enable_key_rotation = false ... } - pattern: | resource "aws_kms_key" $ANYTHING { ... customer_master_key_spec = "SYMMETRIC_DEFAULT" enable_key_rotation = false ... } - pattern: | resource "aws_kms_key" $ANYTHING { ... } - pattern-not-inside: | resource "aws_kms_key" $ANYTHING { ... enable_key_rotation = true ... } - pattern-not-inside: | resource "aws_kms_key" $ANYTHING { ... customer_master_key_spec = "RSA_2096" ... } message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be used by attackers. To fix this, set a `enable_key_rotation`. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation shortlink: https://sg.run/kz47 semgrep.dev: rule: r_id: 17372 rv_id: 1263730 rule_id: PeU0L3 version_id: X0Tzy67 url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation origin: community - id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials patterns: - pattern-inside: | resource "$ANYTING" $ANYTHING { ... environment { variables = { ... } } ... } - pattern-either: - pattern-inside: | AWS_ACCESS_KEY_ID = "$Y" - pattern-regex: | (? - pattern-inside: | ... - id: csharp.dotnet.security.razor-template-injection.razor-template-injection message: User-controllable string passed to Razor.Parse. This leads directly to code execution in the context of the process. severity: WARNING metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' cwe2022-top25: true owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/ subcategory: - vuln technology: - .net - razor - asp license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection shortlink: https://sg.run/oyj0 semgrep.dev: rule: r_id: 18216 rv_id: 1262621 rule_id: EwUr68 version_id: 1QTypdj url: https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection origin: community languages: - csharp mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public ActionResult $METHOD(..., string $ARG,...){...} pattern-sinks: - pattern: | Razor.Parse(...) pattern-sanitizers: - not_conflicting: true pattern: $F(...) - id: csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings message: Cookie Secure flag is explicitly disabled. You should enforce this value to avoid accidentally presenting sensitive cookie values over plaintext HTTP connections. severity: WARNING metadata: likelihood: LOW impact: LOW confidence: LOW category: security cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://docs.microsoft.com/en-us/aspnet/web-api/overview/advanced/http-cookies - https://docs.microsoft.com/en-us/dotnet/api/system.web.security.formsauthentication.requiressl?redirectedfrom=MSDN&view=netframework-4.8#System_Web_Security_FormsAuthentication_RequireSSL - https://docs.microsoft.com/en-us/dotnet/api/system.web.security.roles.cookierequiressl?redirectedfrom=MSDN&view=netframework-4.8#System_Web_Security_Roles_CookieRequireSSL subcategory: - audit technology: - .net - asp - webforms license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings shortlink: https://sg.run/z1jd semgrep.dev: rule: r_id: 18217 rv_id: 1262626 rule_id: 7KUxPg version_id: NdTzyXg url: https://semgrep.dev/playground/r/NdTzyXg/csharp.dotnet.security.web-config-insecure-cookie-settings.web-config-insecure-cookie-settings origin: community languages: - generic paths: include: - '*web.config' patterns: - pattern-either: - pattern: | requireSSL="false" - pattern: | cookieRequireSSL="false" - pattern-either: - pattern-inside: | - pattern-inside: | - pattern-inside: | - id: csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation severity: WARNING languages: - csharp metadata: cwe: - 'CWE-295: Improper Certificate Validation' owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.issuernameregistry?view=netframework-4.8 category: security technology: - .net confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation shortlink: https://sg.run/XZ6B semgrep.dev: rule: r_id: 18220 rv_id: 1262629 rule_id: gxUy01 version_id: xyTjzGW url: https://semgrep.dev/playground/r/xyTjzGW/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation origin: community message: Validating certificates based on subject name is bad practice. Use the X509Certificate2.Verify() method instead. patterns: - pattern-inside: | using System.IdentityModel.Tokens; ... - pattern-either: - patterns: - pattern-either: - pattern-inside: | X509SecurityToken $TOK = $RHS; ... - pattern-inside: | $T $M(..., X509SecurityToken $TOK, ...) { ... } - metavariable-pattern: metavariable: $RHS pattern-either: - pattern: $T as X509SecurityToken - pattern: new X509SecurityToken(...) - patterns: - pattern-either: - pattern-inside: | X509Certificate2 $CERT = new X509Certificate2(...); ... - pattern-inside: | $T $M(..., X509Certificate2 $CERT, ...) { ... } - pattern-inside: | foreach (X509Certificate2 $CERT in $COLLECTION) { ... } - patterns: - pattern-either: - pattern: String.Equals($NAME, "...") - pattern: String.Equals("...", $NAME) - pattern: $NAME.Equals("...") - pattern: $NAME == "..." - pattern: $NAME != "..." - pattern: | "..." == $NAME - pattern: | "..." != $NAME - metavariable-pattern: metavariable: $NAME pattern-either: - pattern: $TOK.Certificate.SubjectName.Name - pattern: $CERT.SubjectName.Name - pattern: $CERT.GetNameInfo(...) - id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine mode: taint pattern-sources: - patterns: - pattern: $A - pattern-inside: | Path.Combine(...,$A,...) - pattern-inside: | public $TYPE $M(...,$A,...){...} - pattern-not-inside: | <... Path.GetFileName($A) != $A ...> pattern-sinks: - patterns: - focus-metavariable: $X - pattern: | File.$METHOD($X,...) - metavariable-regex: metavariable: $METHOD regex: (?i)^(read|write) pattern-sanitizers: - pattern: | Path.GetFileName(...) - patterns: - pattern-inside: | $X = Path.GetFileName(...); ... - pattern: $X - patterns: - pattern: $X - pattern-inside: | if(<... Path.GetFileName($X) != $X ...>){ ... throw new $EXCEPTION(...); } ... message: String argument $A is used to read or write data from a file via Path.Combine without direct sanitization via Path.GetFileName. If the path is user-supplied data this can lead to path traversal. languages: - csharp severity: WARNING metadata: category: security confidence: MEDIUM references: - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks technology: - .net cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine shortlink: https://sg.run/1RvG semgrep.dev: rule: r_id: 18222 rv_id: 1262632 rule_id: 3qU3bE version_id: vdT0644 url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine origin: community - id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings severity: WARNING languages: - C# metadata: cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0 category: security technology: - .net confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings shortlink: https://sg.run/9LJr semgrep.dev: rule: r_id: 18223 rv_id: 1262633 rule_id: 4bUQ81 version_id: d6Tyx4K url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings origin: community message: The top level wildcard bindings $PREFIX leaves your application open to security vulnerabilities and give attackers more control over where traffic is routed. If you must use wildcards, consider using subdomain wildcard binding. For example, you can use "*.asdf.gov" if you own all of "asdf.gov". patterns: - pattern-inside: | using System.Net; ... - pattern: $LISTENER.Prefixes.Add("$PREFIX") - metavariable-regex: metavariable: $PREFIX regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+ - id: csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver shortlink: https://sg.run/yXjP semgrep.dev: rule: r_id: 18224 rv_id: 1262636 rule_id: PeUxb0 version_id: ExTExqN url: https://semgrep.dev/playground/r/ExTExqN/csharp.lang.security.insecure-deserialization.data-contract-resolver.data-contract-resolver origin: community message: Only use DataContractResolver if you are completely sure of what information is being serialized. Malicious types can cause unexpected behavior. patterns: - pattern: | class $MYDCR : DataContractResolver { ... } - id: csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.typefilterlevel?view=net-6.0 - https://www.synacktiv.com/en/publications/izi-izi-pwn2own-ics-miami.html category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full shortlink: https://sg.run/rere semgrep.dev: rule: r_id: 18225 rv_id: 1262639 rule_id: JDUlKl version_id: 8KT5rAN url: https://semgrep.dev/playground/r/8KT5rAN/csharp.lang.security.insecure-deserialization.insecure-typefilterlevel-full.insecure-typefilterlevel-full origin: community message: Using a .NET remoting service can lead to RCE, even if you try to configure TypeFilterLevel. Recommended to switch from .NET Remoting to WCF https://docs.microsoft.com/en-us/dotnet/framework/wcf/migrating-from-net-remoting-to-wcf pattern-either: - patterns: - pattern-either: - pattern: new BinaryServerFormatterSinkProvider { TypeFilterLevel = $LEVEL } - patterns: - pattern-inside: | $TYPE $SP = new BinaryServerFormatterSinkProvider(...); ... - pattern: | $SP.TypeFilterLevel = $LEVEL - metavariable-regex: metavariable: $LEVEL regex: (.*)TypeFilterLevel\.(Full|Low) - patterns: - pattern-inside: | $DICT["typeFilterLevel"] = $VAL; ... - pattern: new BinaryServerFormatterSinkProvider(..., $DICT, ...) - metavariable-regex: metavariable: $VAL regex: (\"Full\"|\"Low\") - id: csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span severity: WARNING languages: - C# metadata: cwe: - 'CWE-125: Out-of-bounds Read' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.memorymarshal.createspan?view=net-6.0 - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.interopservices.memorymarshal.createreadonlyspan?view=net-6.0 category: security technology: - .net confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Memory Issues source: https://semgrep.dev/r/csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span shortlink: https://sg.run/b4eW semgrep.dev: rule: r_id: 18226 rv_id: 1262645 rule_id: 5rUyEN version_id: JdTzx62 url: https://semgrep.dev/playground/r/JdTzx62/csharp.lang.security.memory.memory-marshal-create-span.memory-marshal-create-span origin: community message: MemoryMarshal.CreateSpan and MemoryMarshal.CreateReadOnlySpan should be used with caution, as the length argument is not checked. pattern-either: - pattern: MemoryMarshal.CreateSpan(...) - pattern: MemoryMarshal.CreateReadOnlySpan(...) - id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout severity: WARNING languages: - C# metadata: cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' owasp: A01:2017 - Injection references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0 category: security technology: - .net confidence: MEDIUM subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout shortlink: https://sg.run/NgRy semgrep.dev: rule: r_id: 18227 rv_id: 945224 rule_id: GdUDBP version_id: yeT0nDq url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout origin: community message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based Denial of Service (DoS) attack. Consider setting the timeout to a short amount of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double check that your context meets the conditions outlined in the "Notes to Callers" section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0' patterns: - pattern-inside: | using System.Text.RegularExpressions; ... - pattern-either: - pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout) - patterns: - pattern: new Regex(..., TimeSpan.FromSeconds($TIME)) - metavariable-comparison: metavariable: $TIME comparison: $TIME > 5 - pattern: new Regex(..., TimeSpan.FromMinutes(...)) - pattern: new Regex(..., TimeSpan.FromHours(...)) - id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | $XMLDOCUMENT.$METHOD(...) - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver = new XmlUrlResolver(...);\n... \n" message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override shortlink: https://sg.run/k98P semgrep.dev: rule: r_id: 18228 rv_id: 1262654 rule_id: ReUK9k version_id: K3TKk5E url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override origin: community - id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | XmlReader $READER = XmlReader.Create(...,$RS,...); - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing = DtdProcessing.Parse;\n... \n" message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override shortlink: https://sg.run/wXjA semgrep.dev: rule: r_id: 18229 rv_id: 1262655 rule_id: AbU3pX version_id: qkTR7WD url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override origin: community - id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | $READER.$METHOD(...) - pattern-not-inside: | $READER.DtdProcessing = DtdProcessing.Prohibit; ... - pattern-inside: | XmlTextReader $READER = new XmlTextReader(...); ... message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults shortlink: https://sg.run/xXjL semgrep.dev: rule: r_id: 18230 rv_id: 1262656 rule_id: BYUevk version_id: l4TJRWG url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults origin: community - id: go.aws-lambda.security.database-sqli.database-sqli languages: - go message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' calls. mode: taint metadata: references: - https://pkg.go.dev/database/sql#DB.Query category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - database - sql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli shortlink: https://sg.run/e5e8 semgrep.dev: rule: r_id: 18232 rv_id: 1262909 rule_id: WAUdJ7 version_id: BjTkZkQ url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.Exec($QUERY,...) - pattern: $DB.ExecContent($QUERY,...) - pattern: $DB.Query($QUERY,...) - pattern: $DB.QueryContext($QUERY,...) - pattern: $DB.QueryRow($QUERY,...) - pattern: $DB.QueryRowContext($QUERY,...) - pattern-inside: | import "database/sql" ... pattern-sources: - patterns: - pattern-either: - pattern-inside: | func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} ... lambda.Start($HANDLER, ...) - patterns: - pattern-inside: | func $HANDLER($EVENT $TYPE) {...} ... lambda.Start($HANDLER, ...) - pattern-not-inside: | func $HANDLER($EVENT context.Context) {...} ... lambda.Start($HANDLER, ...) - focus-metavariable: $EVENT severity: WARNING - id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - go severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/vX3Y semgrep.dev: rule: r_id: 18233 rv_id: 1262910 rule_id: 0oUwqg version_id: DkTRbRL url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} ... lambda.Start($HANDLER, ...) - patterns: - pattern-inside: | func $HANDLER($EVENT $TYPE) {...} ... lambda.Start($HANDLER, ...) - pattern-not-inside: | func $HANDLER($EVENT context.Context) {...} ... lambda.Start($HANDLER, ...) - focus-metavariable: $EVENT pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | "$SQLSTR" + ... - metavariable-regex: metavariable: $SQLSTR regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$SQLSTR", ...) - pattern: fmt.Sprintf("$SQLSTR", ...) - pattern: fmt.Printf("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* - pattern-not-inside: | log.$PRINT(...) pattern-sanitizers: - pattern: strconv.Atoi(...) - id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse message: '`Clean` is not intended to sanitize against path traversal attacks. This function is for finding the shortest path name equivalent to the given input. Using `Clean` to sanitize file reads may expose this application to path traversal attacks, where an attacker could access arbitrary files on the server. To fix this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, "/")))` However, a better solution is using the `SecureJoin` function in the package `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' severity: ERROR languages: - go mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sinks: - patterns: - pattern-either: - pattern: filepath.Clean($...INNER) - pattern: path.Clean($...INNER) pattern-sanitizers: - pattern-either: - pattern: | "/" + ... fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) options: interfile: true metadata: references: - https://pkg.go.dev/path#Clean - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ - https://dzx.cz/2021/04/02/go_path_traversal/ - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - go cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse shortlink: https://sg.run/ZKzw semgrep.dev: rule: r_id: 18235 rv_id: 1262967 rule_id: qNUQJe version_id: jQTn5Bj url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse origin: community - id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - java severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. options: interfile: true metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/EBYN semgrep.dev: rule: r_id: 18237 rv_id: 1262977 rule_id: YGUl4z version_id: O9TpxQN url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - focus-metavariable: $EVENT - pattern-either: - pattern: | $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } - pattern: | $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - pattern-not-inside: | System.out.$PRINTLN(...) - id: java.aws-lambda.security.tainted-sqli.tainted-sqli message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize user input instead. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - focus-metavariable: $EVENT - pattern-either: - pattern: | $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } - pattern: | $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" - pattern: | (java.sql.Statement $STMT) = ...; - pattern: | (java.sql.PreparedStatement $STMT) = ...; - pattern: | $VAR = $CONN.prepareStatement(...) - pattern: | $PATH.queryForObject(...); - pattern: | (java.util.Map $STMT) = $PATH.queryForMap(...); - pattern: | (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; - patterns: - pattern-inside: | (String $SQL) = "$SQLSTR" + ...; ... - pattern: $PATH.$SQLCMD(..., $SQL, ...); - metavariable-regex: metavariable: $SQLSTR regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) - metavariable-regex: metavariable: $SQLCMD regex: (execute|query|executeUpdate|batchUpdate) options: interfile: true metadata: category: security technology: - sql - java - aws-lambda cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli shortlink: https://sg.run/7942 semgrep.dev: rule: r_id: 18238 rv_id: 1262978 rule_id: 6JUDWk version_id: e1Tyj4g url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli origin: community - id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request message: Detected input from a HTTPServletRequest going into a SQL sink or statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize user input instead. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' cwe2021-top25: true cwe2022-top25: true owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html - https://owasp.org/www-community/attacks/SQL_Injection subcategory: - vuln technology: - sql - java - servlets - spring license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request shortlink: https://sg.run/Lg56 semgrep.dev: rule: r_id: 18239 rv_id: 1409390 rule_id: oqUBJG version_id: 7ZTKJNj url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request origin: community languages: - java mode: taint options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ).$REQFUNC(...) - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" - metavariable-regex: metavariable: $REQFUNC regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) pattern-sinks: - patterns: - pattern-either: - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" - pattern: | (java.sql.Statement $STMT) = ...; ... $OUTPUT = $STMT.$FUNC(...); - pattern: | (java.sql.PreparedStatement $STMT) = ...; - pattern: | $VAR = $CONN.prepareStatement(...) - pattern: | $PATH.queryForObject(...); - pattern: | (java.util.Map $STMT) = $PATH.queryForMap(...); - pattern: | (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; - pattern: | (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) - patterns: - pattern-inside: | (String $SQL) = "$SQLSTR" + ...; ... - pattern: $PATH.$SQLCMD(..., $SQL, ...); - metavariable-regex: metavariable: $SQLSTR regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) - metavariable-regex: metavariable: $SQLCMD regex: (execute|query|executeUpdate|batchUpdate) - id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' or 'exec' command. This could lead to command injection if variables passed into the exec commands are not properly sanitized. Instead, avoid using these OS commands with user-supplied input, or, if you must use these commands, use a whitelist of specific values. languages: - java severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (ProcessBuilder $PB) = ...; - patterns: - pattern: | (Process $P) = ...; - pattern-not: | (Process $P) = (java.lang.Runtime $R).exec(...); - patterns: - pattern: (java.lang.Runtime $R).exec($CMD, ...); - focus-metavariable: $CMD - patterns: - pattern-either: - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n...\n$PB.command($ARGLIST);\n" - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n" - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process $P) = ...;\n" - pattern: | $ARGLIST.add(...); metadata: category: security technology: - java cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request shortlink: https://sg.run/8zPN semgrep.dev: rule: r_id: 18240 rv_id: 1263042 rule_id: zdUWrg version_id: LjTkg9J url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request origin: community - id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request message: Detected input from a HTTPServletRequest going into an LDAP query. This could lead to LDAP injection if the input is not properly sanitized, which could result in attackers modifying objects in the LDAP tree structure. Ensure data passed to an LDAP query is not controllable or properly sanitize the data. metadata: cwe: - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection category: security technology: - java subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - LDAP Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request shortlink: https://sg.run/gRg0 semgrep.dev: rule: r_id: 18241 rv_id: 1409392 rule_id: pKUXAv version_id: 8KT3Pe6 url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request origin: community severity: WARNING languages: - java mode: taint pattern-sources: - patterns: - pattern: (HttpServletRequest $REQ) pattern-sinks: - patterns: - pattern-either: - pattern: | (javax.naming.directory.InitialDirContext $IDC).search(...) - pattern: | (javax.naming.directory.DirContext $CTX).search(...) - pattern-not: | (javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...) - pattern-not: | (javax.naming.directory.DirContext $CTX).search($Y, "...", ...) - id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request message: Detected input from a HTTPServletRequest going into a session command, like `setAttribute`. User input into such a command could lead to an attacker inputting malicious code into your session parameters, blurring the line between what's trusted and untrusted, and therefore leading to a trust boundary violation. This could lead to programmers trusting unvalidated data. Instead, thoroughly sanitize user input before passing it into such function calls. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - patterns: - pattern: | (HttpServletRequest $REQ).$FUNC(...) - pattern-not: | (HttpServletRequest $REQ).getSession() - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) - patterns: - pattern-inside: | $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... ); ... - pattern: | $PARAM = $VALS[$INDEX]; - patterns: - pattern-inside: | $HEADERS = (HttpServletRequest $REQ).getHeaders(...); ... $PARAM = $HEADERS.$FUNC(...); ... - pattern: | java.net.URLDecoder.decode($PARAM, ...) pattern-sinks: - patterns: - pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE); - metavariable-regex: metavariable: $FUNC regex: ^(putValue|setAttribute)$ - focus-metavariable: $VALUE options: interfile: true metadata: category: security technology: - java cwe: - 'CWE-501: Trust Boundary Violation' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request shortlink: https://sg.run/QbDZ semgrep.dev: rule: r_id: 18242 rv_id: 1409393 rule_id: 2ZU7Eo version_id: gETrv9j url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request origin: community - id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request message: Detected input from a HTTPServletRequest going into a XPath evaluate or compile command. This could lead to xpath injection if variables passed into the evaluate or compile commands are not properly sanitized. Xpath injection could lead to unauthorized access to sensitive information in XML documents. Instead, thoroughly sanitize user input or use parameterized xpath queries if you can. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - pattern: | (HttpServletRequest $REQ).$FUNC(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (javax.xml.xpath.XPath $XP).evaluate(...) - pattern: | (javax.xml.xpath.XPath $XP).compile(...).evaluate(...) metadata: category: security technology: - java cwe: - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XPath Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request shortlink: https://sg.run/3BvK semgrep.dev: rule: r_id: 18243 rv_id: 1409394 rule_id: X5U5nj version_id: QkTERKP url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request origin: community - id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false shortlink: https://sg.run/4Dv5 semgrep.dev: rule: r_id: 18244 rv_id: 1263057 rule_id: j2UrJ8 version_id: 0bTKzgX url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false origin: community message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external entity declarations, this is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. patterns: - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", false); - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing shortlink: https://sg.run/PYBz semgrep.dev: rule: r_id: 18245 rv_id: 1263058 rule_id: 10UPQB version_id: K3TKk80 url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing origin: community message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = DocumentBuilderFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newDocumentBuilder(); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); $FACTORY.newDocumentBuilder(); languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true shortlink: https://sg.run/JgPy semgrep.dev: rule: r_id: 18246 rv_id: 1263059 rule_id: 9AUJ6r version_id: qkTR7Lk url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true origin: community message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" to false. pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", true); fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true shortlink: https://sg.run/5Lv0 semgrep.dev: rule: r_id: 18247 rv_id: 1263060 rule_id: yyUNeo version_id: l4TJRoL url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true origin: community message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" to false. pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", true); fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); languages: - java - id: javascript.aws-lambda.security.detect-child-process.detect-child-process message: Allowing spawning arbitrary programs or running shell processes with arbitrary arguments may end up in a command injection vulnerability. Try to avoid non-literal values for the command string. If it is not possible, then do not let running arbitrary commands, use a white list for inputs. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - javascript - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process shortlink: https://sg.run/Ggoq semgrep.dev: rule: r_id: 18248 rv_id: 1263105 rule_id: r6UDNQ version_id: YDTZe4o url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: exec($CMD,...) - pattern: execSync($CMD,...) - pattern: spawn($CMD,...) - pattern: spawnSync($CMD,...) - pattern: $CP.exec($CMD,...) - pattern: $CP.execSync($CMD,...) - pattern: $CP.spawn($CMD,...) - pattern: $CP.spawnSync($CMD,...) - pattern-either: - pattern-inside: | require('child_process') ... - pattern-inside: | import 'child_process' ... - id: javascript.aws-lambda.security.knex-sqli.knex-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from table'', [userinput])`' metadata: references: - https://knexjs.org/#Builder-fromRaw - https://knexjs.org/#Builder-whereRaw category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - knex cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli shortlink: https://sg.run/RgWq semgrep.dev: rule: r_id: 18249 rv_id: 1263106 rule_id: bwUBlj version_id: JdTzxKg url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $KNEX.fromRaw($QUERY, ...) - pattern: $KNEX.whereRaw($QUERY, ...) - pattern: $KNEX.raw($QUERY, ...) - pattern-either: - pattern-inside: | require('knex') ... - pattern-inside: | import 'knex' ... - id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `connection.query(''SELECT $1 from table'', [userinput])`' metadata: references: - https://www.npmjs.com/package/mysql2 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql - mysql2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli shortlink: https://sg.run/A502 semgrep.dev: rule: r_id: 18250 rv_id: 1263107 rule_id: NbUBJ2 version_id: 5PTo1En url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $POOL.query($QUERY, ...) - pattern: $POOL.execute($QUERY, ...) - pattern-either: - pattern-inside: | require('mysql') ... - pattern-inside: | require('mysql2') ... - pattern-inside: | require('mysql2/promise') ... - pattern-inside: | import 'mysql' ... - pattern-inside: | import 'mysql2' ... - pattern-inside: | import 'mysql2/promise' ... - id: javascript.aws-lambda.security.pg-sqli.pg-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `connection.query(''SELECT $1 from table'', [userinput])`' metadata: references: - https://node-postgres.com/features/queries category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - postgres - pg cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli shortlink: https://sg.run/BGKA semgrep.dev: rule: r_id: 18251 rv_id: 1263108 rule_id: kxU25P version_id: GxTkeJL url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.query($QUERY, ...) - pattern-either: - pattern-inside: | require('pg') ... - pattern-inside: | import 'pg' ... - id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `sequelize.query(''SELECT * FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT });`' metadata: references: - https://sequelize.org/master/manual/raw-queries.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sequelize cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli shortlink: https://sg.run/DAlP semgrep.dev: rule: r_id: 18252 rv_id: 1263109 rule_id: wdUA5o version_id: RGT0LrD url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.query($QUERY, ...) - pattern-either: - pattern-inside: | require('sequelize') ... - pattern-inside: | import 'sequelize' ... - id: javascript.aws-lambda.security.tainted-eval.tainted-eval message: The `eval()` function evaluates JavaScript code represented as a string. Executing JavaScript from a string is an enormous security risk. It is far too easy for a bad actor to run arbitrary code when you use `eval()`. Ensure evaluated content is not definable by external sources. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - javascript - aws-lambda subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-eval.tainted-eval shortlink: https://sg.run/WjY2 semgrep.dev: rule: r_id: 18253 rv_id: 1263110 rule_id: x8UNw5 version_id: A8TgdLk url: https://semgrep.dev/playground/r/A8TgdLk/javascript.aws-lambda.security.tainted-eval.tainted-eval origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - focus-metavariable: $CODE - pattern-either: - pattern: eval($CODE) - pattern: Function(...,$CODE) - pattern: new Function(...,$CODE) - id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/0Gvj semgrep.dev: rule: r_id: 18254 rv_id: 1263111 rule_id: OrUJBY version_id: BjTkZ8D url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $BODY - pattern-inside: | {..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... } - id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection message: The `vm` module enables compiling and running code within V8 Virtual Machine contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted code. If code passed to `vm` functions is controlled by user input it could result in command injection. Do not let user input in `vm` functions. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - javascript - aws-lambda cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection shortlink: https://sg.run/q9w7 semgrep.dev: rule: r_id: 18256 rv_id: 1263114 rule_id: v8UOdZ version_id: 0bTKz9J url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('vm'); ... - pattern-inside: | import 'vm' ... - pattern-either: - pattern: $VM.runInContext($X,...) - pattern: $VM.runInNewContext($X,...) - pattern: $VM.runInThisContext($X,...) - pattern: $VM.compileFunction($X,...) - pattern: new $VM.Script($X,...) - pattern: new $VM.SourceTextModule($X,...) - pattern: runInContext($X,...) - pattern: runInNewContext($X,...) - pattern: runInThisContext($X,...) - pattern: compileFunction($X,...) - pattern: new Script($X,...) - pattern: new SourceTextModule($X,...) - id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT $1 from table'', [userinput])` can help prevent SQLi.' metadata: confidence: MEDIUM references: - https://knexjs.org/#Builder-fromRaw - https://knexjs.org/#Builder-whereRaw - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - express - nodejs - knex cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli shortlink: https://sg.run/l9eE semgrep.dev: rule: r_id: 18257 rv_id: 1263205 rule_id: d8UKLD version_id: l4TJRey url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options) - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern-inside: $KNEX.fromRaw($QUERY, ...) - pattern-inside: $KNEX.whereRaw($QUERY, ...) - pattern-inside: $KNEX.raw($QUERY, ...) - pattern-either: - pattern-inside: | require('knex') ... - pattern-inside: | import 'knex' ... pattern-sanitizers: - patterns: - pattern: parseInt(...) - id: javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli message: Detected a `$IMPORT` SQL statement that comes from a function argument. This could lead to SQL injection if the variable is user-controlled and is not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared statements. metadata: references: - https://www.npmjs.com/package/mysql2 - https://www.npmjs.com/package/mysql - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' confidence: LOW technology: - mysql - mysql2 - javascript - nodejs cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli shortlink: https://sg.run/Y0oy semgrep.dev: rule: r_id: 18258 rv_id: 1263207 rule_id: ZqUlWE version_id: JdTzx2D url: https://semgrep.dev/playground/r/JdTzx2D/javascript.lang.security.audit.sqli.node-mysql-sqli.node-mysql-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: function ... (..., $Y,...) {...} - pattern: $Y - pattern-not-inside: | function ... (..., $Y: number,...) {...} - pattern-not-inside: $Y.query - pattern-not-inside: $Y.body - pattern-not-inside: $Y.params - pattern-not-inside: $Y.cookies - pattern-not-inside: $Y.headers pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern-inside: $POOL.query($QUERY, ...) - pattern-inside: $POOL.execute($QUERY, ...) - pattern-either: - pattern-inside: | import $S from "$IMPORT" ... - pattern-inside: | import { ... } from "$IMPORT" ... - pattern-inside: | import * as $S from "$IMPORT" ... - pattern-inside: | require("$IMPORT") ... - metavariable-regex: metavariable: $IMPORT regex: (mysql|mysql2) pattern-sanitizers: - patterns: - pattern: parseInt(...) - id: php.lang.security.deserialization.extract-user-data mode: taint pattern-sources: - pattern-either: - pattern: $_GET[...] - pattern: $_FILES[...] - pattern: $_POST[...] pattern-sinks: - pattern: extract(...) pattern-sanitizers: - pattern: extract($VAR, EXTR_SKIP,...) message: Do not call 'extract()' on user-controllable data. If you must, then you must also provide the EXTR_SKIP flag to prevent overwriting existing variables. languages: - php metadata: category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures technology: - php references: - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data shortlink: https://sg.run/6bv1 semgrep.dev: rule: r_id: 18259 rv_id: 1263278 rule_id: nJUykq version_id: w8TRovw url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data origin: community severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) message: Detected 'create_subprocess_exec' function with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec - https://docs.python.org/3/library/shlex.html category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec shortlink: https://sg.run/oyv0 semgrep.dev: rule: r_id: 18260 rv_id: 1263331 rule_id: EwUrX8 version_id: rxTAKgo url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec shortlink: https://sg.run/z14d semgrep.dev: rule: r_id: 18261 rv_id: 1263332 rule_id: 7KUxXg version_id: bZT53Ww url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) - pattern: asyncio.create_subprocess_shell($CMD, ...) message: Detected asyncio subprocess function with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-subprocess.html - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell shortlink: https://sg.run/p9vZ semgrep.dev: rule: r_id: 18262 rv_id: 1263333 rule_id: L1UEl7 version_id: NdTzyWA url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process mode: taint message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach this function call because it allows a malicious actor to execute commands. Ensure no external data reaches here. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - python - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process shortlink: https://sg.run/2AjL semgrep.dev: rule: r_id: 18263 rv_id: 1263334 rule_id: 8GUGBq version_id: kbTzGv8 url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - patterns: - pattern: os.$METHOD($MODE, $CMD, ...) - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) - patterns: - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) - metavariable-regex: metavariable: $METHOD regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use mode: taint message: Detected subprocess function with argument tainted by an `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. The default option for `shell` is False, and this is secure by default. Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` means you have to split the command string into an array of strings for the command and its arguments. You may consider using 'shlex.split()' for this purpose. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/subprocess.html - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use shortlink: https://sg.run/XZ7B semgrep.dev: rule: r_id: 18264 rv_id: 1263335 rule_id: gxUyn1 version_id: w8TRogj url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern: subprocess.$FUNC(..., shell=True, ...) pattern-sanitizers: - pattern: shlex.split(...) - pattern: pipes.quote(...) - pattern: shlex.quote(...) - id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call mode: taint message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach this function call because it allows a malicious actor to execute commands. Use the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection vulnerability. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call shortlink: https://sg.run/jDvN semgrep.dev: rule: r_id: 18265 rv_id: 1263336 rule_id: QrUkg6 version_id: xyTjzbG url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: os.system($CMD,...) - pattern: os.popen($CMD,...) - pattern: os.popen2($CMD,...) - pattern: os.popen3($CMD,...) - pattern: os.popen4($CMD,...) - id: python.aws-lambda.security.mysql-sqli.mysql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', (''active''))`' mode: taint metadata: references: - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli shortlink: https://sg.run/1RjG semgrep.dev: rule: r_id: 18266 rv_id: 1263337 rule_id: 3qU3eE version_id: O9TpxLJ url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $CURSOR.execute($QUERY,...) - pattern: $CURSOR.executemany($QUERY,...) - pattern-either: - pattern-inside: | import mysql ... - pattern-inside: | import mysql.cursors ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', ''active'')`' mode: taint metadata: references: - https://www.psycopg.org/docs/cursor.html#cursor.execute - https://www.psycopg.org/docs/cursor.html#cursor.executemany - https://www.psycopg.org/docs/cursor.html#cursor.mogrify category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - psycopg - psycopg2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli shortlink: https://sg.run/9L8r semgrep.dev: rule: r_id: 18267 rv_id: 1263338 rule_id: 4bUQG1 version_id: e1TyjPZ url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $CURSOR.execute($QUERY,...) - pattern: $CURSOR.executemany($QUERY,...) - pattern: $CURSOR.mogrify($QUERY,...) - pattern-inside: | import psycopg2 ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', ''active'')`' mode: taint metadata: references: - https://pypi.org/project/pymssql/ category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - pymssql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli shortlink: https://sg.run/yXvP semgrep.dev: rule: r_id: 18268 rv_id: 1263339 rule_id: PeUxO0 version_id: vdT06bG url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-inside: | import pymssql ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', (''active''))`' mode: taint metadata: references: - https://pypi.org/project/PyMySQL/#id4 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - pymysql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli shortlink: https://sg.run/reve semgrep.dev: rule: r_id: 18269 rv_id: 1263340 rule_id: JDUlel version_id: d6TyxNA url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-either: - pattern-inside: | import pymysql ... - pattern-inside: | import pymysql.cursors ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = ?'', ''active'')`' mode: taint metadata: references: - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sqlalchemy cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli shortlink: https://sg.run/b48W semgrep.dev: rule: r_id: 18270 rv_id: 1263341 rule_id: 5rUy3N version_id: ZRTKARp url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-inside: | import sqlalchemy ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern-either: - pattern: eval($CODE, ...) - pattern: exec($CODE, ...) message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec shortlink: https://sg.run/Ng7y semgrep.dev: rule: r_id: 18271 rv_id: 1263342 rule_id: GdUDJP version_id: nWT2LD2 url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec origin: community languages: - python severity: WARNING - id: python.aws-lambda.security.tainted-html-response.tainted-html-response mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern: $BODY - pattern-inside: | {..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... } message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/k9vP semgrep.dev: rule: r_id: 18272 rv_id: 1263343 rule_id: ReUKrk version_id: ExTEx5o url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response origin: community languages: - python severity: WARNING - id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - python message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/wXvA semgrep.dev: rule: r_id: 18273 rv_id: 1263346 rule_id: AbU3LX version_id: 8KT5ron url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR" % ... - pattern: | "$SQLSTR".format(...) - pattern: | f"$SQLSTR{...}..." - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= - pattern-not-inside: | print(...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: ERROR - id: python.django.security.nan-injection.nan-injection message: Found user input going directly into typecast for bool(), float(), or complex(). This allows an attacker to inject Python's not-a-number (NaN) into the typecast. This results in undefind behavior, particularly when doing comparisons. Either cast to a different type, or add a guard checking for all capitalizations of the string 'nan'. languages: - python severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] pattern-sinks: - patterns: - pattern-either: - pattern: float(...) - pattern: bool(...) - pattern: complex(...) - pattern-not-inside: | if $COND: ... ... pattern-sanitizers: - pattern: $ANYTHING(...) not_conflicting: true metadata: references: - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ category: security cwe: - 'CWE-704: Incorrect Type Conversion or Cast' technology: - django subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.django.security.nan-injection.nan-injection shortlink: https://sg.run/Og7L semgrep.dev: rule: r_id: 18275 rv_id: 946193 rule_id: DbUGvk version_id: NdTqk7G url: https://semgrep.dev/playground/r/NdTqk7G/python.django.security.nan-injection.nan-injection origin: community - id: python.flask.security.injection.nan-injection.nan-injection message: Found user input going directly into typecast for bool(), float(), or complex(). This allows an attacker to inject Python's not-a-number (NaN) into the typecast. This results in undefind behavior, particularly when doing comparisons. Either cast to a different type, or add a guard checking for all capitalizations of the string 'nan'. languages: - python severity: ERROR mode: taint pattern-sources: - pattern-either: - pattern: flask.request.$SOMETHING.get(...) - pattern: flask.request.$SOMETHING[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR pattern-sinks: - pattern-either: - pattern: float(...) - pattern: bool(...) - pattern: complex(...) pattern-sanitizers: - not_conflicting: true pattern: $ANYTHING(...) metadata: references: - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ category: security cwe: - 'CWE-704: Incorrect Type Conversion or Cast' technology: - flask subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.flask.security.injection.nan-injection.nan-injection shortlink: https://sg.run/e598 semgrep.dev: rule: r_id: 18276 rv_id: 946222 rule_id: WAUdj7 version_id: qkT4j85 url: https://semgrep.dev/playground/r/qkT4j85/python.flask.security.injection.nan-injection.nan-injection origin: community - id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`' mode: taint metadata: references: - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - active-record cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli shortlink: https://sg.run/vXvY semgrep.dev: rule: r_id: 18277 rv_id: 1263581 rule_id: 0oUw9g version_id: w8TRor7 url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: ActiveRecord::Base.connection.execute($QUERY,...) - pattern: $MODEL.find_by_sql($QUERY,...) - pattern: $MODEL.select_all($QUERY,...) - pattern-inside: | require 'active_record' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' mode: taint metadata: references: - https://github.com/brianmario/mysql2 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli shortlink: https://sg.run/dJLE semgrep.dev: rule: r_id: 18278 rv_id: 1263582 rule_id: KxUrQ3 version_id: xyTjzOe url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: $CLIENT.query($QUERY,...) - pattern: $CLIENT.prepare($QUERY,...) - pattern-inside: | require 'mysql2' ... pattern-sanitizers: - pattern: $CLIENT.escape(...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.pg-sqli.pg-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`' mode: taint metadata: references: - https://www.rubydoc.info/gems/pg/PG/Connection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - postgres - pg cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli shortlink: https://sg.run/ZKww semgrep.dev: rule: r_id: 18279 rv_id: 1263583 rule_id: qNUQee version_id: O9Tpxz7 url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: $CONN.exec($QUERY,...) - pattern: $CONN.exec_params($QUERY,...) - pattern: $CONN.exec_prepared($QUERY,...) - pattern: $CONN.async_exec($QUERY,...) - pattern: $CONN.async_exec_params($QUERY,...) - pattern: $CONN.async_exec_prepared($QUERY,...) - pattern-inside: | require 'pg' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `DB[''select * from items where name = ?'', name]`' mode: taint metadata: references: - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sequel cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli shortlink: https://sg.run/n9vY semgrep.dev: rule: r_id: 18280 rv_id: 1263584 rule_id: lBUy2N version_id: e1Tyj5j url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: DB[$QUERY,...] - pattern: DB.run($QUERY,...) - pattern-inside: | require 'sequel' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - ruby severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/EB7N semgrep.dev: rule: r_id: 18281 rv_id: 1263586 rule_id: PeUxOE version_id: d6Tyx1Z url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | "...#{...}..." - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* - patterns: - pattern-either: - pattern: Kernel::sprintf("$SQLSTR", ...) - pattern: | "$SQLSTR" + $EXPR - pattern: | "$SQLSTR" % $EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* - pattern-not-inside: | puts(...) - id: scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run patterns: - pattern: Seq($CMD, ...) - pattern-not: Seq("...", ...) - pattern-inside: | import sys.process ... - pattern-not-inside: | $CMD = "..." ... - pattern-either: - pattern-inside: Seq(...).! - pattern-inside: Seq(...).!! - pattern-inside: Seq(...).lazyLines message: Found dynamic content used for the external process. This is dangerous if arbitrary data can reach this function call because it allows a malicious actor to execute commands. Ensure your variables are not controlled by users or sufficiently sanitized. languages: - scala severity: ERROR metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - scala confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run shortlink: https://sg.run/79b2 semgrep.dev: rule: r_id: 18282 rv_id: 1263670 rule_id: JDUle4 version_id: zyTb2zJ url: https://semgrep.dev/playground/r/zyTb2zJ/scala.lang.security.audit.dangerous-seq-run.dangerous-seq-run origin: community - id: scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run patterns: - pattern: Seq($SH, "-c", $CMD, ...) - pattern-not: Seq($SH, "-c", "...", ...) - pattern-inside: | import sys.process ... - pattern-not-inside: | $CMD = "..." ... - pattern-either: - pattern-inside: Seq(...).! - pattern-inside: Seq(...).!! - pattern-inside: Seq(...).lazyLines - metavariable-regex: metavariable: $SH regex: '"(sh|bash|ksh|csh|tcsh|zsh)"' message: Found dynamic content used for the external process. This is dangerous if arbitrary data can reach this function call because it allows a malicious actor to execute commands. Ensure your variables are not controlled by users or sufficiently sanitized. languages: - scala severity: ERROR metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - scala confidence: LOW references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run shortlink: https://sg.run/Lg76 semgrep.dev: rule: r_id: 18283 rv_id: 1263671 rule_id: 5rUy3K version_id: pZT03ED url: https://semgrep.dev/playground/r/pZT03ED/scala.lang.security.audit.dangerous-shell-run.dangerous-shell-run origin: community - id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings patterns: - pattern: secure = false - pattern-inside: | session = { ... } message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration file. languages: - generic severity: WARNING paths: include: - '*.conf' metadata: category: security references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security - https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration technology: - play - scala cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings shortlink: https://sg.run/8z8N semgrep.dev: rule: r_id: 18284 rv_id: 1263685 rule_id: GdUDJO version_id: e1TyjJv url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings origin: community - id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli mode: taint metadata: references: - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - scala - slick - play confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli shortlink: https://sg.run/k9K2 semgrep.dev: rule: r_id: 18328 rv_id: 1263687 rule_id: GdUDWO version_id: d6TyxJe url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli origin: community message: Detected a tainted SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using using user input for generating SQL strings. pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: $MODEL.overrideSql(...) - pattern: sql"..." - pattern-inside: | import slick.$DEPS ... severity: ERROR languages: - scala - id: scala.play.security.webservice-ssrf.webservice-ssrf patterns: - pattern: $WS.url($URL) - pattern-either: - pattern-inside: | class $CLASS (..., $WS: WSClient, ...) { ... } - pattern-inside: | def $FUNC(..., $WS: WSClient, ...) = { ... } - pattern-inside: | $WS = AhcWSClient(...) ... - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } message: A parameter being passed directly into `WSClient` most likely lead to SSRF. This could allow an attacker to send data to their own server, potentially exposing sensitive data sent with this request. They could also probe internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://www.playframework.com/documentation/2.8.x/ScalaWS category: security technology: - scala - play confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/scala.play.security.webservice-ssrf.webservice-ssrf shortlink: https://sg.run/reRR semgrep.dev: rule: r_id: 18369 rv_id: 1263690 rule_id: PeUxEE version_id: ExTExz1 url: https://semgrep.dev/playground/r/ExTExz1/scala.play.security.webservice-ssrf.webservice-ssrf origin: community languages: - scala severity: WARNING - id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check patterns: - pattern-inside: | import ("github.com/gorilla/websocket") ... - patterns: - pattern-not-inside: | $UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...} ... - pattern-not-inside: | $UPGRADER.CheckOrigin = $FN2 ... - pattern: | $UPGRADER.Upgrade(...) message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee that the connection accepted by the WebSocket is from a trusted origin domain. Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" documentation: "A CheckOrigin function should carefully validate the request origin to prevent cross-site request forgery."' languages: - go severity: WARNING metadata: category: security cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader technology: - gorilla confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check shortlink: https://sg.run/xXpz semgrep.dev: rule: r_id: 18430 rv_id: 1262914 rule_id: ReUKdz version_id: qkTR7RP url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check origin: community - id: scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf patterns: - pattern: Http($URL) - pattern-inside: | import scalaj.http.$HTTP ... - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } message: A parameter being passed directly into `Http` can likely lead to SSRF. This could allow an attacker to send data to their own server, potentially exposing sensitive data sent with this request. They could also probe internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://github.com/scalaj/scalaj-http#simplified-http category: security technology: - scala - scalaj-http confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf shortlink: https://sg.run/OgjB semgrep.dev: rule: r_id: 18431 rv_id: 1263680 rule_id: AbU3xA version_id: NdTzy7D url: https://semgrep.dev/playground/r/NdTzy7D/scala.lang.security.audit.scalaj-http-ssrf.scalaj-http-ssrf origin: community languages: - scala severity: WARNING - id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string shortlink: https://sg.run/Lgqr semgrep.dev: rule: r_id: 18483 rv_id: 1263112 rule_id: PeUxwW version_id: DkTRbvp url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$HTMLSTR" + $EXPR - pattern: | "$HTMLSTR".concat(...) - pattern: $UTIL.format($HTMLSTR, ...) - pattern: format($HTMLSTR, ...) - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - patterns: - pattern: | `...${...}...` - pattern-regex: | .*<\w+.* - pattern-not-inside: | console.$LOG(...) - id: python.aws-lambda.security.tainted-html-string.tainted-html-string languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string shortlink: https://sg.run/8zNy semgrep.dev: rule: r_id: 18484 rv_id: 1263344 rule_id: JDUlwy version_id: 7ZTE36K url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string origin: community mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - pattern-not-inside: | print(...) - id: scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf patterns: - pattern: url($URL) - pattern-inside: | import dispatch._ ... - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } message: A parameter being passed directly into `url` most likely lead to SSRF. This could allow an attacker to send data to their own server, potentially exposing sensitive data sent with this request. They could also probe internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://dispatchhttp.org/Dispatch.html category: security technology: - scala - dispatch confidence: LOW cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf shortlink: https://sg.run/gR6J semgrep.dev: rule: r_id: 18485 rv_id: 1263672 rule_id: 5rUyl4 version_id: 2KTv282 url: https://semgrep.dev/playground/r/2KTv282/scala.lang.security.audit.dispatch-ssrf.dispatch-ssrf origin: community languages: - scala severity: WARNING - id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf patterns: - pattern-either: - pattern: Source.fromURL($URL,...) - pattern: Source.fromURI($URL,...) - pattern-inside: | import scala.io.$SOURCE ... - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } message: A parameter being passed directly into `fromURL` most likely lead to SSRF. This could allow an attacker to send data to their own server, potentially exposing sensitive data sent with this request. They could also probe internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource category: security technology: - scala confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf shortlink: https://sg.run/Qbz4 semgrep.dev: rule: r_id: 18486 rv_id: 1263675 rule_id: GdUDOZ version_id: 1QTypG9 url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf origin: community languages: - scala severity: WARNING - id: scala.lang.security.audit.scalac-debug.scalac-debug patterns: - pattern-either: - pattern: scalacOptions ... "-Vdebug" - pattern: scalacOptions ... "-Ydebug" message: Scala applications built with `debug` set to true in production may leak debug information to attackers. Debug mode also affects performance and reliability. Remove it from configuration. languages: - generic severity: WARNING paths: include: - '*.sbt*' metadata: category: security cwe: - 'CWE-489: Active Debug Code' owasp: A05:2021 - Security Misconfiguration technology: - scala - sbt references: - https://docs.scala-lang.org/overviews/compiler-options/index.html confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug shortlink: https://sg.run/QbGd semgrep.dev: rule: r_id: 18686 rv_id: 946569 rule_id: JDUlE0 version_id: qkT4j0N url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug origin: community - id: scala.play.security.tainted-html-response.tainted-html-response mode: taint metadata: category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection technology: - scala - play confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/BG96 semgrep.dev: rule: r_id: 18795 rv_id: 1263686 rule_id: 0oUwn2 version_id: vdT06yj url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response origin: community message: Detected a request with potential user-input going into an `Ok()` response. This bypasses any view or template environments, including HTML escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. Consider using a view technology such as Twirl which automatically escapes HTML views. pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sanitizers: - pattern-either: - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) - pattern: org.owasp.encoder.Encode.forHtml(...) pattern-sinks: - pattern-either: - pattern: Html.apply(...) - pattern: Ok(...).as(HTML) - pattern: Ok(...).as(ContentTypes.HTML) - patterns: - pattern: Ok(...).as($CTYPE) - metavariable-regex: metavariable: $CTYPE regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' - patterns: - pattern: Ok(...).as($CTYPE) - pattern-not: Ok(...).as("...") - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } severity: WARNING languages: - scala - id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv patterns: - pattern-either: - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); - metavariable-comparison: metavariable: $M comparison: re.match(".*-CBC",$M) message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext attacks against encrypted data. languages: - php severity: ERROR metadata: cwe: - 'CWE-329: Generation of Predictable IV with CBC Mode' references: - https://csrc.nist.gov/publications/detail/sp/800-38a/final owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures technology: - php - openssl category: security subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv shortlink: https://sg.run/LgWJ semgrep.dev: rule: r_id: 19039 rv_id: 1263295 rule_id: DbUGbE version_id: JdTzxOD url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv origin: community - id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode patterns: - pattern-inside: | import pdi.jwt.$DEPS ... - pattern-either: - pattern: $JWT.encode($X, "...", ...) - pattern: $JWT.decode($X, "...", ...) - pattern: $JWT.decodeRawAll($X, "...", ...) - pattern: $JWT.decodeRaw($X, "...", ...) - pattern: $JWT.decodeAll($X, "...", ...) - pattern: $JWT.validate($X, "...", ...) - pattern: $JWT.isValid($X, "...", ...) - pattern: $JWT.decodeJson($X, "...", ...) - pattern: $JWT.decodeJsonAll($X, "...", ...) - patterns: - pattern-either: - pattern: $JWT.encode($X, $KEY, ...) - pattern: $JWT.decode($X, $KEY, ...) - pattern: $JWT.decodeRawAll($X, $KEY, ...) - pattern: $JWT.decodeRaw($X, $KEY, ...) - pattern: $JWT.decodeAll($X, $KEY, ...) - pattern: $JWT.validate($X, $KEY, ...) - pattern: $JWT.isValid($X, $KEY, ...) - pattern: $JWT.decodeJson($X, $KEY, ...) - pattern: $JWT.decodeJsonAll($X, $KEY, ...) - pattern: $JWT.encode($X, this.$KEY, ...) - pattern: $JWT.decode($X, this.$KEY, ...) - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) - pattern: $JWT.decodeRaw($X, this.$KEY, ...) - pattern: $JWT.decodeAll($X, this.$KEY, ...) - pattern: $JWT.validate($X, this.$KEY, ...) - pattern: $JWT.isValid($X, this.$KEY, ...) - pattern: $JWT.decodeJson($X, this.$KEY, ...) - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) - pattern-either: - pattern-inside: | class $CL { ... $KEY = "..." ... } - pattern-inside: | object $CL { ... $KEY = "..." ... } - metavariable-pattern: metavariable: $JWT patterns: - pattern-either: - pattern: Jwt - pattern: JwtArgonaut - pattern: JwtCirce - pattern: JwtJson4s - pattern: JwtJson - pattern: JwtUpickle message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' languages: - scala severity: WARNING metadata: references: - https://jwt-scala.github.io/jwt-scala/ category: security cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design technology: - scala confidence: HIGH cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode shortlink: https://sg.run/8zE7 semgrep.dev: rule: r_id: 19040 rv_id: 1263669 rule_id: WAUdK0 version_id: o5TbDA8 url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode origin: community - id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled patterns: - pattern-either: - pattern: | $DF = DocumentBuilderFactory.newInstance(...) ... $DB = $DF.newDocumentBuilder(...) - patterns: - pattern: $DB = DocumentBuilderFactory.newInstance(...) - pattern-not-inside: | ... $X = $DB.newDocumentBuilder(...) - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) message: Document Builder being instantiated without calling the `setFeature` functions that are generally used for disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled shortlink: https://sg.run/gRQn semgrep.dev: rule: r_id: 19041 rv_id: 1263673 rule_id: 0oUwzP version_id: X0TzyRq url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled origin: community - id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled patterns: - pattern-either: - pattern: $SR = new SAXReader(...) - pattern: | $SF = SAXParserFactory.newInstance(...) ... $SR = $SF.newSAXParser(...) - patterns: - pattern: $SR = SAXParserFactory.newInstance(...) - pattern-not-inside: | ... $X = $SR.newSAXParser(...) - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) - pattern: $SR = new SAXBuilder(...) - pattern-not-inside: | ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) message: XML processor being instantiated without calling the `setFeature` functions that are generally used for disabling entity processing. User controlled data in XML Parsers can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled shortlink: https://sg.run/QbYP semgrep.dev: rule: r_id: 19042 rv_id: 1263678 rule_id: KxUrkq version_id: rxTAKWY url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled origin: community - id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled patterns: - pattern-not-inside: | ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) - pattern-either: - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) - pattern: $XMLFACTORY = new XMLInputFactory(...) message: XMLInputFactory being instantiated without calling the setProperty functions that are generally used for disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled shortlink: https://sg.run/3BEb semgrep.dev: rule: r_id: 19043 rv_id: 1263683 rule_id: qNUQ7w version_id: xyTjzkA url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled origin: community - id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... domain_endpoint_options { ... enforce_https = true tls_security_policy = "Policy-Min-TLS-1-0-2019-07" ... } ... } message: Detected an AWS Elasticsearch domain using an insecure version of TLS. To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07". languages: - terraform severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - aws - terraform references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version shortlink: https://sg.run/PYlq semgrep.dev: rule: r_id: 19045 rv_id: 1263718 rule_id: YGUle7 version_id: DkTRbA5 url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version origin: community - id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage message: User data from `$REQ` is being compiled into the template, which can lead to a Server Side Template Injection (SSTI) vulnerability. options: interfile: true metadata: interfile: true category: security cwe: - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' owasp: - A03:2021 - Injection - A01:2017 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html technology: - javascript - typescript - express - pug - jade - dot - ejs - nunjucks - lodash - handlbars - mustache - hogan.js - eta - squirrelly source_rule_url: - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage shortlink: https://sg.run/b49v semgrep.dev: rule: r_id: 19226 rv_id: 1263165 rule_id: EwUr9k version_id: zyTb2eD url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-propagators: - pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) from: $E to: $S pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $PUG = require('pug') ... - pattern-inside: | import * as $PUG from 'pug' ... - pattern-inside: | $PUG = require('jade') ... - pattern-inside: | import * as $PUG from 'jade' ... - pattern-either: - pattern: $PUG.compile(...) - pattern: $PUG.compileClient(...) - pattern: $PUG.compileClientWithDependenciesTracked(...) - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('dot') ... - pattern-inside: | import * as $PUG from 'dot' ... - pattern-either: - pattern: $PUG.template(...) - pattern: $PUG.compile(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('ejs') ... - pattern-inside: | import * as $PUG from 'ejs' ... - pattern-either: - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('nunjucks') ... - pattern-inside: | import * as $PUG from 'nunjucks' ... - pattern-either: - pattern: $PUG.renderString(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('lodash') ... - pattern-inside: | import * as $PUG from 'lodash' ... - pattern-either: - pattern: $PUG.template(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('mustache') ... - pattern-inside: | import * as $PUG from 'mustache' ... - pattern-inside: | $PUG = require('eta') ... - pattern-inside: | import * as $PUG from 'eta' ... - pattern-inside: | $PUG = require('squirrelly') ... - pattern-inside: | import * as $PUG from 'squirrelly' ... - pattern-either: - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('hogan.js') ... - pattern-inside: | import * as $PUG from 'hogan.js' ... - pattern-inside: | $PUG = require('handlebars') ... - pattern-inside: | import * as $PUG from 'handlebars' ... - pattern-either: - pattern: $PUG.compile(...) - id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include mode: taint pattern-sources: - patterns: - pattern: params[...] pattern-sinks: - patterns: - pattern-either: - pattern: | render ..., file: $X - pattern: | render ..., inline: $X - pattern: | render ..., template: $X - pattern: | render ..., action: $X - pattern: | render $X, ... - focus-metavariable: $X pattern-sanitizers: - patterns: - pattern: $MAP[...] - metavariable-pattern: metavariable: $MAP patterns: - pattern-not-regex: params - pattern: File.basename(...) message: Found request parameters in a call to `render`. This can allow end users to request arbitrary local files which may result in leaking sensitive information persisted on disk. Where possible, avoid letting users specify template paths for `render`. If you must allow user input, use an allow-list of known templates or normalize the user-supplied value with `File.basename(...)`. languages: - ruby severity: WARNING metadata: technology: - ruby - rails category: security cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb references: - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM vulnerability_class: - Path Traversal license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include shortlink: https://sg.run/Jw8Z semgrep.dev: rule: r_id: 20046 rv_id: 1409407 rule_id: ReU2pZ version_id: K3TgANN url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include origin: community - id: ruby.rails.security.brakeman.check-send-file.check-send-file mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: | send_file ... message: Allowing user input to `send_file` allows a malicious user to potentially read arbitrary files from the server. Avoid accepting user input in `send_file` or normalize with `File.basename(...)` languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb category: security cwe: - 'CWE-73: External Control of File Name or Path' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design technology: - ruby - rails references: - https://owasp.org/www-community/attacks/Path_Traversal - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file shortlink: https://sg.run/GbY1 semgrep.dev: rule: r_id: 20048 rv_id: 1263660 rule_id: BYUKbl version_id: BjTkZRj url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file origin: community - id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request languages: - scala severity: ERROR mode: taint message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html category: security technology: - scala - play confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request shortlink: https://sg.run/BeW9 semgrep.dev: rule: r_id: 20051 rv_id: 1263688 rule_id: 0oUpon version_id: ZRTKAoG url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request origin: community pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".format(...) - patterns: - pattern-inside: | $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR" ... - pattern: $VAR += ... - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - patterns: - pattern: s"..." - pattern-regex: | .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* - pattern-not-inside: println(...) - id: dockerfile.security.last-user-is-root.last-user-is-root patterns: - pattern: USER root - pattern-not-inside: patterns: - pattern: | USER root ... USER $X - metavariable-pattern: metavariable: $X patterns: - pattern-not: root message: The last user in the container is 'root'. This is a security hazard because if an attacker gains control of the container they will have root access. Switch back to another user after running commands as 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-269: Improper Privilege Management' source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 references: - https://github.com/hadolint/hadolint/wiki/DL3002 category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root shortlink: https://sg.run/5Z43 semgrep.dev: rule: r_id: 20147 rv_id: 1262658 rule_id: ReU2n5 version_id: 6xT29Eg url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root origin: community - id: dockerfile.security.missing-user.missing-user patterns: - pattern: | CMD $...VARS - pattern-not-inside: | USER $USER ... - pattern-not-inside: | HEALTHCHECK ... CMD ... fix: | USER non-root CMD $...VARS message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user shortlink: https://sg.run/Gbvn semgrep.dev: rule: r_id: 20148 rv_id: 1262660 rule_id: AbUN06 version_id: zyTb2n2 url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user origin: community - id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends selecting Argon2id unless you can guarantee an adversary has no direct access to the computing environment. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html - https://eprint.iacr.org/2016/759.pdf - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf - https://datatracker.ietf.org/doc/html/rfc9106#section-4 category: security cwe: - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' technology: - argon2 - cryptography owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln impact: LOW likelihood: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config shortlink: https://sg.run/ALq4 semgrep.dev: rule: r_id: 20150 rv_id: 1263103 rule_id: DbU2X8 version_id: qkTR7Jk url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | $ARGON = require('argon2'); ... - pattern: | {type: ...} pattern-sinks: - patterns: - pattern: | $Y - pattern-inside: | $ARGON.hash(...,$Y) pattern-sanitizers: - patterns: - pattern: '{type: $ARGON.argon2id}' - id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] - patterns: - pattern: $Y - pattern-either: - pattern-inside: | $RECORD.read_attribute($Y) - pattern-inside: | $RECORD[$Y] - metavariable-regex: metavariable: $RECORD regex: '[A-Z][a-z]+' pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $Y - pattern-inside: | /...#{...}.../ - patterns: - pattern: $Y - pattern-inside: | Regexp.new(...) message: Found a potentially user-controllable argument in the construction of a regular expressions. This may result in excessive resource consumption when applied to certain inputs, or when the user is allowed to control the match target. Avoid allowing users to specify regular expressions processed by the server. If you must support user-controllable input in a regular expression, use an allow-list to restrict the expressions users may supply to limit catastrophic backtracking. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb category: security cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' owasp: - A03:2017 - Sensitive Data Exposure technology: - ruby - rails references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos shortlink: https://sg.run/qZwx semgrep.dev: rule: r_id: 20156 rv_id: 1409406 rule_id: YGUY4R version_id: 0bTG0WO url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos origin: community - id: ruby.rails.security.brakeman.check-sql.check-sql mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sanitizers: - patterns: - pattern-either: - patterns: - pattern: $X - pattern-either: - pattern-inside: | :$KEY => $X - pattern-inside: | ["...",$X,...] - pattern: | params[...].to_i - pattern: | params[...].to_f - patterns: - pattern: | params[...] ? $A : $B - metavariable-pattern: metavariable: $A patterns: - pattern-not: | params[...] - metavariable-pattern: metavariable: $B patterns: - pattern-not: | params[...] pattern-sinks: - patterns: - pattern: $X - pattern-not-inside: | $P.where("...",...) - pattern-not-inside: | $P.where(:$KEY => $VAL,...) - pattern-either: - pattern-inside: | $P.$M(...) - pattern-inside: | $P.$M("...",...) - pattern-inside: | class $P < ActiveRecord::Base ... end - metavariable-regex: metavariable: $M regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) message: Found potential SQL injection due to unsafe SQL query construction via $X. Where possible, prefer parameterized queries. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://owasp.org/www-community/attacks/SQL_Injection - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql shortlink: https://sg.run/vpgb semgrep.dev: rule: r_id: 20533 rv_id: 1263661 rule_id: OrUv2z version_id: DkTRbE4 url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql origin: community - id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: $X - pattern-either: - pattern-inside: | $X. ... .to_proc - patterns: - pattern-inside: | $Y.method($Z) - focus-metavariable: $Z - patterns: - pattern-inside: | $Y.tap($Z) - focus-metavariable: $Z - patterns: - pattern-inside: | $Y.tap{ |$ANY| $Z } - focus-metavariable: $Z message: Found user-controllable input to a reflection method. This may allow a user to alter program behavior and potentially execute arbitrary instructions in the context of the process. Do not provide arbitrary user input to `tap`, `method`, or `to_proc` languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods shortlink: https://sg.run/dPYd semgrep.dev: rule: r_id: 20534 rv_id: 1263662 rule_id: eqUZ2Q version_id: WrTqKLA url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods origin: community - id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase message: Found the use of an hardcoded passphrase for RSA. The passphrase can be easily discovered, and therefore should not be stored in source-code. It is recommended to remove the passphrase from source-code, and use system environment variables or a restricted configuration file. languages: - ruby severity: WARNING metadata: technology: - ruby - secrets category: security references: - https://cwe.mitre.org/data/definitions/522.html cwe: - 'CWE-798: Use of Hard-coded Credentials' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase shortlink: https://sg.run/xPEe semgrep.dev: rule: r_id: 20730 rv_id: 1263607 rule_id: bwULyN version_id: K3TKkEo url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase origin: community patterns: - pattern-either: - pattern: OpenSSL::PKey::RSA.new(..., '...') - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') - patterns: - pattern-inside: | $OPENSSL = OpenSSL::PKey::RSA.new(...) ... - pattern-either: - pattern: | $OPENSSL.export(...,'...') - pattern: | $OPENSSL.to_pem(...,'...') - patterns: - pattern-either: - patterns: - pattern-inside: | $ASSIGN = '...' ... - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = '...' ... end ... def $METHOD2(...) ... end - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) - patterns: - pattern-inside: | $ASSIGN = '...' ... def $METHOD(...) $OPENSSL = OpenSSL::PKey::RSA.new(...) ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $OPENSSL = OpenSSL::PKey::RSA.new(...) ... $ASSIGN = '...' ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = '...' ... end ... def $METHOD2(...) ... $OPENSSL = OpenSSL::PKey::RSA.new(...) ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended to use a key length of 2048 or higher. languages: - ruby severity: WARNING metadata: technology: - ruby category: security references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size shortlink: https://sg.run/O4Re semgrep.dev: rule: r_id: 20731 rv_id: 1263608 rule_id: NbUe4N version_id: qkTR76v url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size origin: community patterns: - pattern-either: - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) - patterns: - pattern-either: - patterns: - pattern-inside: | $ASSIGN = $SIZE ... - pattern-either: - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = $SIZE ... end ... - pattern-either: - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 2048 - id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to mode: taint pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: cookies - pattern: request.env - pattern: url_for(params[...],...,:only_path => false,...) pattern-sanitizers: - patterns: - pattern-either: - patterns: - pattern: | $F(...) - metavariable-pattern: metavariable: $F patterns: - pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to) - pattern: | params.merge! :only_path => true ... - pattern: | params.slice(...) ... - pattern: | redirect_to [...] - patterns: - pattern: | $MODEL. ... .$M(...) ... - metavariable-regex: metavariable: $MODEL regex: '[A-Z]\w+' - metavariable-regex: metavariable: $M regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take) - patterns: - pattern: | params.$UNSAFE_HASH.merge(...,:only_path => true,...) ... - metavariable-regex: metavariable: $UNSAFE_HASH regex: to_unsafe_h(ash)? - patterns: - pattern: params.permit(...,$X,...) - metavariable-pattern: metavariable: $X patterns: - pattern-not-regex: (host|port|(sub)?domain) pattern-sinks: - patterns: - pattern: $X - pattern-inside: | redirect_to $X, ... - pattern-not-regex: params\.\w+(? true` hash value. languages: - ruby severity: WARNING metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb category: security cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' technology: - ruby - rails references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to shortlink: https://sg.run/eJNX semgrep.dev: rule: r_id: 20732 rv_id: 1263657 rule_id: kxUOJ6 version_id: GxTke14 url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to origin: community - id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: $X - pattern-either: - pattern-inside: | $X.constantize - pattern-inside: | $X. ... .safe_constantize - pattern-inside: | const_get(...) - pattern-inside: | qualified_const_get(...) message: Found user-controllable input to Ruby reflection functionality. This allows a remote user to influence runtime behavior, up to and including arbitrary remote code execution. Do not provide user-controllable input to reflection functionality. Do not call symbol conversion on user-controllable input. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection shortlink: https://sg.run/vpEX semgrep.dev: rule: r_id: 20733 rv_id: 1263663 rule_id: wdUkYA version_id: 0bTKzn8 url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection origin: community - id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern-either: - pattern: $MODEL.find(...) - pattern: $MODEL.find_by_id(...) - pattern: $MODEL.find_by_id!(...) - metavariable-regex: metavariable: $MODEL regex: '[A-Z]\S+' message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord model being searched against is sensitive, this may lead to Insecure Direct Object Reference (IDOR) behavior and allow users to read arbitrary records. Scope the find to the current user, e.g. `current_user.accounts.find(params[:id])`. languages: - ruby severity: WARNING metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb category: security cwe: - 'CWE-639: Authorization Bypass Through User-Controlled Key' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - ruby - rails references: - https://brakemanscanner.org/docs/warning_types/unscoped_find/ - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find shortlink: https://sg.run/dPbP semgrep.dev: rule: r_id: 20734 rv_id: 1263664 rule_id: x8Ud6d version_id: K3TKkxZ url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find origin: community - id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object message: Detected DynamoDB query params that are tainted by `$EVENT` object. This could lead to NoSQL injection if the variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from `$EVENT` directly to DynamoDB client. metadata: cwe: - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' owasp: - A01:2017 - Injection category: security technology: - javascript - aws-lambda - dynamodb subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object shortlink: https://sg.run/X1e4 semgrep.dev: rule: r_id: 21320 rv_id: 945766 rule_id: 0oU1xk version_id: GxTP7gN url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern: | $DC.$METHOD($SINK, ...) - metavariable-regex: metavariable: $METHOD regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) - pattern-either: - pattern-inside: | $DC = new $AWS.DocumentClient(...); ... - pattern-inside: | $DC = new $AWS.DynamoDB(...); ... - pattern-inside: | $DC = new DynamoDBClient(...); ... - pattern-inside: | $DC = DynamoDBDocumentClient.from(...); ... pattern-sanitizers: - patterns: - pattern: | {...} - id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection mode: taint metadata: cwe: - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' owasp: - A01:2017 - Injection category: security technology: - python - boto3 - aws-lambda - dynamodb references: - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection shortlink: https://sg.run/jjrl semgrep.dev: rule: r_id: 21321 rv_id: 946088 rule_id: KxUJ2B version_id: 9lTy1rQ url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection origin: community message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This could lead to NoSQL injection if the variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from `$EVENT` directly to DynamoDB client. pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sanitizers: - patterns: - pattern: | {...} pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) - pattern-either: - patterns: - pattern-inside: | $TABLE = $DB.Table(...) ... - pattern-inside: | $DB = boto3.resource('dynamodb', ...) ... - pattern-inside: | $TABLE = boto3.client('dynamodb', ...) ... severity: ERROR languages: - python - id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response message: Detected data rendered directly to the end user via 'Response'. This bypasses Pyramid's built-in cross-site scripting (XSS) defenses and could result in an XSS vulnerability. Use Pyramid's template engines to safely render HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - pyramid references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response shortlink: https://sg.run/DX8G semgrep.dev: rule: r_id: 21452 rv_id: 1263572 rule_id: gxUeA8 version_id: X0TzyEe url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response origin: community languages: - python severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern: | pyramid.request.Response.text($SINK) - pattern: | pyramid.request.Response($SINK) - pattern: | $REQ.response.body = $SINK - pattern: | $REQ.response.text = $SINK - pattern: | $REQ.response.ubody = $SINK - pattern: | $REQ.response.unicode_body = $SINK - pattern: $SINK - id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. languages: - python severity: ERROR metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data technology: - pyramid cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection shortlink: https://sg.run/W7eE semgrep.dev: rule: r_id: 21453 rv_id: 1263573 rule_id: QrUZ7l version_id: jQTn5WA url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection origin: community mode: taint pattern-sources: - patterns: - pattern-inside: | from pyramid.view import view_config ... @view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-inside: | $QUERY = $REQ.dbsession.query(...) ... - pattern-either: - pattern: | $QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) - pattern: | $QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) - pattern: $SINK - metavariable-regex: metavariable: $SQLFUNC regex: (group_by|order_by|distinct|having|filter) - metavariable-regex: metavariable: $FORMATFUNC regex: (?!bindparams) fix-regex: regex: format replacement: bindparams - id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint message: Use of angular.element can lead to XSS if user-input is treated as part of the HTML element within `$SINK`. It is recommended to contextually output encode user-input, before inserting into `$SINK`. If the HTML needs to be preserved it is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. metadata: confidence: MEDIUM cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://docs.angularjs.org/api/ng/function/angular.element - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angularjs owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint shortlink: https://sg.run/5AQ0 semgrep.dev: rule: r_id: 21503 rv_id: 1263091 rule_id: GdUP71 version_id: 44TEj8L url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: window.location.search - pattern: window.document.location.search - pattern: document.location.search - pattern: location.search - pattern: $location.search(...) - patterns: - pattern-either: - pattern: $DECODE(<... location.hash ...>) - pattern: $DECODE(<... window.location.hash ...>) - pattern: $DECODE(<... document.location.hash ...>) - pattern: $DECODE(<... location.href ...>) - pattern: $DECODE(<... window.location.href ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... document.URL ...>) - pattern: $DECODE(<... window.document.URL ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... $location.absUrl() ...>) - pattern: $DECODE(<... $location.url() ...>) - pattern: $DECODE(<... $location.hash() ...>) - metavariable-regex: metavariable: $DECODE regex: ^(unescape|decodeURI|decodeURIComponent)$ - patterns: - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|delete|head|jsonp|post|put|patch) - pattern: $RES.data pattern-sinks: - patterns: - pattern-either: - pattern-inside: | angular.element(...). ... .$SINK($QUERY) - pattern-inside: | $ANGULAR = angular.element(...) ... $ANGULAR. ... .$SINK($QUERY) - metavariable-regex: metavariable: $SINK regex: ^(after|append|html|prepend|replaceWith|wrap)$ - focus-metavariable: $QUERY pattern-sanitizers: - patterns: - pattern-either: - pattern: $sce.getTrustedHtml(...) - pattern: $sanitize(...) - pattern: DOMPurify.sanitize(...) - id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: pickle.load($SINK,...) - pattern: pickle.loads($SINK,...) - pattern: _pickle.load($SINK,...) - pattern: _pickle.loads($SINK,...) - pattern: cPickle.load($SINK,...) - pattern: cPickle.loads($SINK,...) - pattern: dill.load($SINK,...) - pattern: dill.loads($SINK,...) - pattern: shelve.open($SINK,...) message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://docs.python.org/3/library/pickle.html - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization shortlink: https://sg.run/JbjW semgrep.dev: rule: r_id: 21602 rv_id: 1263345 rule_id: JDUDQg version_id: LjTkgd9 url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization origin: community languages: - python severity: WARNING - id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...}) pattern-sanitizers: - patterns: - pattern: | DB::raw("...",[...]) pattern-sinks: - patterns: - pattern: | DB::raw(...) message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL injection via string concatenation or unsafe interpolation. languages: - php severity: WARNING metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md technology: - php - laravel cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection shortlink: https://sg.run/x94g semgrep.dev: rule: r_id: 21674 rv_id: 1263305 rule_id: zdUln0 version_id: qkTR7A9 url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection origin: community - id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator mode: taint pattern-sources: - patterns: - pattern: | public function $F(...,Request $R,...){...} - focus-metavariable: $R - patterns: - pattern-either: - pattern: | $this->$PROPERTY - pattern: | $this->$PROPERTY->$GET - metavariable-pattern: metavariable: $PROPERTY patterns: - pattern-either: - pattern: query - pattern: request - pattern: headers - pattern: cookies - pattern: cookie - pattern: files - pattern: file - pattern: allFiles - pattern: input - pattern: all - pattern: post - pattern: json - pattern-either: - pattern-inside: | class $CL extends Illuminate\Http\Request {...} - pattern-inside: | class $CL extends Illuminate\Foundation\Http\FormRequest {...} pattern-sinks: - patterns: - pattern: | Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...) - focus-metavariable: $IGNORE message: Found a request argument passed to an `ignore()` definition in a Rule constraint. This can lead to SQL injection. languages: - php severity: ERROR metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - php - laravel references: - https://laravel.com/docs/9.x/validation#rule-unique cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator shortlink: https://sg.run/vkeb semgrep.dev: rule: r_id: 21677 rv_id: 1263314 rule_id: X5ULgE version_id: DkTRbBl url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator origin: community - id: java.spring.security.injection.tainted-file-path.tainted-file-path languages: - java severity: ERROR message: Detected user input controlling a file path. An attacker could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. options: interfile: true metadata: cwe: - 'CWE-23: Relative Path Traversal' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Path_Traversal category: security technology: - java - spring subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: HIGH interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path shortlink: https://sg.run/x9o0 semgrep.dev: rule: r_id: 22074 rv_id: 1263084 rule_id: lBUxok version_id: ExTEx6Y url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE pattern-sinks: - patterns: - pattern-either: - pattern: new File(...) - pattern: new java.io.File(...) - pattern: new FileReader(...) - pattern: new java.io.FileReader(...) - pattern: new FileInputStream(...) - pattern: new java.io.FileInputStream(...) - pattern: (Paths $PATHS).get(...) - patterns: - pattern: | $CLASS.$FUNC(...) - metavariable-regex: metavariable: $FUNC regex: ^(getResourceAsStream|getResource)$ - patterns: - pattern-either: - pattern: new ClassPathResource($FILE, ...) - pattern: ResourceUtils.getFile($FILE, ...) - pattern: new FileOutputStream($FILE, ...) - pattern: new java.io.FileOutputStream($FILE, ...) - pattern: new StreamSource($FILE, ...) - pattern: new javax.xml.transform.StreamSource($FILE, ...) - pattern: FileUtils.openOutputStream($FILE, ...) - focus-metavariable: $FILE pattern-sanitizers: - pattern: org.apache.commons.io.FilenameUtils.getName(...) - id: java.spring.security.injection.tainted-html-string.tainted-html-string languages: - java severity: ERROR message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. You can use the OWASP ESAPI encoder if you must render user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html category: security technology: - java - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string shortlink: https://sg.run/ObdR semgrep.dev: rule: r_id: 22075 rv_id: 1409395 rule_id: YGUvkL version_id: 3ZT2598 url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string origin: community mode: taint pattern-sources: - label: INPUT patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE - label: CONCAT by-side-effect: true requires: INPUT patterns: - pattern-either: - pattern: | "$HTMLSTR" + ... - pattern: | "$HTMLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$HTMLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$HTMLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$HTMLSTR", ...) - patterns: - pattern-inside: | String $VAR = "$HTMLSTR"; ... - pattern: String.format($VAR, ...) - metavariable-regex: metavariable: $HTMLSTR regex: ^<\w+ pattern-propagators: - pattern: (StringBuilder $SB).append($...TAINTED) from: $...TAINTED to: $SB - pattern: $VAR += $...TAINTED from: $...TAINTED to: $VAR pattern-sinks: - requires: CONCAT patterns: - pattern-either: - pattern: new ResponseEntity<>($PAYLOAD, ...) - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) - pattern: ResponseEntity. ... .body($PAYLOAD) - patterns: - pattern: | ResponseEntity.$RESPFUNC($PAYLOAD). ... - metavariable-regex: metavariable: $RESPFUNC regex: ^(ok|of)$ - focus-metavariable: $PAYLOAD pattern-sanitizers: - pattern-either: - pattern: Encode.forHtml(...) - pattern: (PolicyFactory $POLICY).sanitize(...) - pattern: (AntiSamy $AS).scan(...) - pattern: JSoup.clean(...) - id: java.spring.security.injection.tainted-system-command.tainted-system-command languages: - java severity: ERROR mode: taint pattern-propagators: - pattern: (StringBuilder $STRB).append($INPUT) from: $INPUT to: $STRB label: CONCAT requires: INPUT pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE label: INPUT - patterns: - pattern-either: - pattern: $X + $SOURCE - pattern: $SOURCE + $Y - pattern: String.format("...", ..., $SOURCE, ...) - pattern: String.join("...", ..., $SOURCE, ...) - pattern: (String $STR).concat($SOURCE) - pattern: $SOURCE.concat(...) - pattern: $X += $SOURCE - pattern: $SOURCE += $X label: CONCAT requires: INPUT pattern-sinks: - patterns: - pattern-either: - pattern: | (Process $P) = new Process(...); - pattern: | (ProcessBuilder $PB).command(...); - patterns: - pattern-either: - pattern: | (Runtime $R).$EXEC(...); - pattern: | Runtime.getRuntime(...).$EXEC(...); - metavariable-regex: metavariable: $EXEC regex: (exec|loadLibrary|load) - patterns: - pattern: | (ProcessBuilder $PB).command(...).$ADD(...); - metavariable-regex: metavariable: $ADD regex: (add|addAll) - patterns: - pattern-either: - patterns: - pattern-inside: | $BUILDER = new ProcessBuilder(...); ... - pattern: $BUILDER.start(...) - pattern: | new ProcessBuilder(...). ... .start(...); requires: CONCAT message: 'Detected user input entering a method which executes a system command. This could result in a command injection vulnerability, which allows an attacker to inject an arbitrary system command onto the server. The attacker could download malware onto or steal data from the server. Instead, use ProcessBuilder, separating the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", targetDirectory)`. Further, make sure you hardcode or allowlist the actual command so that attackers can''t run arbitrary commands.' metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - java - spring confidence: HIGH references: - https://www.stackhawk.com/blog/command-injection-java/ - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command shortlink: https://sg.run/epY0 semgrep.dev: rule: r_id: 22076 rv_id: 1263087 rule_id: 6JUxGN version_id: 8KT5rnP url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command origin: community - id: java.spring.security.injection.tainted-url-host.tainted-url-host languages: - java severity: ERROR message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode the correct host, or ensure that the user data can only affect the path or parameters. options: interfile: true metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - java - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/vkYn semgrep.dev: rule: r_id: 22077 rv_id: 1263088 rule_id: oqUZo8 version_id: gETB708 url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE pattern-sinks: - pattern-either: - pattern: new URL($ONEARG) - patterns: - pattern-either: - pattern: | "$URLSTR" + ... - pattern: | "$URLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$URLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$URLSTR"; ... - pattern: $VAR += ... - patterns: - pattern: String.format("$URLSTR", ...) - pattern-not: String.format("$URLSTR", "...", ...) - patterns: - pattern-inside: | String $VAR = "$URLSTR"; ... - pattern: String.format($VAR, ...) - metavariable-regex: metavariable: $URLSTR regex: http(s?)://%(v|s|q).* - id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization mode: taint languages: - ruby message: Deserialization of a string tainted by `event` object found. Objects in Ruby can be serialized into strings, then later loaded from strings. However, uses of `load` can cause remote code execution. Loading user input with MARSHAL, YAML or CSV can potentially be dangerous. If you need to deserialize untrusted data, you should use JSON as it is only capable of returning 'primitive' types such as strings, arrays, hashes, numbers and nil. metadata: references: - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb category: security owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' technology: - ruby - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization shortlink: https://sg.run/dplX semgrep.dev: rule: r_id: 22078 rv_id: 1263585 rule_id: zdUlNJ version_id: vdT06gR url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization origin: community pattern-sinks: - patterns: - pattern: $SINK - pattern-either: - pattern-inside: | YAML.load($SINK,...) - pattern-inside: | CSV.load($SINK,...) - pattern-inside: | Marshal.load($SINK,...) - pattern-inside: | Marshal.restore($SINK,...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent message: The libxml library processes user-input with the `noent` attribute is set to `true` which can lead to being vulnerable to XML External Entities (XXE) type attacks. It is recommended to set `noent` to `false` when using this feature to ensure you are protected. options: interfile: true metadata: interfile: true references: - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html technology: - express category: security cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent shortlink: https://sg.run/Z75x semgrep.dev: rule: r_id: 22079 rv_id: 1263138 rule_id: pKUNeD version_id: d6TyxpX url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $XML = require('$IMPORT') ... - pattern-inside: | import $XML from '$IMPORT' ... - pattern-inside: | import * as $XML from '$IMPORT' ... - metavariable-regex: metavariable: $IMPORT regex: ^(libxmljs|libxmljs2)$ - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) - metavariable-regex: metavariable: $FUNC regex: ^(parseXmlString|parseXml)$ - focus-metavariable: $QUERY - id: javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent message: Detected use of parseXml() function with the `noent` field set to `true`. This can lead to an XML External Entities (XXE) attack if untrusted data is passed into it. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent shortlink: https://sg.run/n8Ag semgrep.dev: rule: r_id: 22080 rv_id: 1263139 rule_id: 2ZUY52 version_id: ZRTKAXb url: https://semgrep.dev/playground/r/ZRTKAXb/javascript.express.security.audit.express-libxml-vm-noent.express-libxml-vm-noent origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - patterns: - pattern-either: - pattern: $VM.runInContext("$CMD", ...) - pattern: $VM.runInNewContext("$CMD", ...) - pattern: $VM.runInThisContext("$CMD", ...) - pattern: $VM.compileFunction("$CMD", ...) - metavariable-pattern: metavariable: $CMD language: typescript pattern-either: - pattern: | $LIBXML.parseXml($DATA, {..., noent: true, ...}, ...) - patterns: - pattern-inside: | $OPTS = {..., noent: true, ...} ... - pattern: $LIBXML.parseXml( $DATA, $OPTS ) - pattern: | $LIBXML.parseXml($DATA, {..., noent: true, ...}, ...) - patterns: - pattern-inside: | $OPTS = {..., noent: true, ...} ... - pattern: $LIBXML.parseXml( $DATA, $OPTS ) - id: javascript.express.security.audit.express-open-redirect.express-open-redirect message: The application redirects to a URL specified by user-supplied input `$REQ` that is not validated. This could redirect users to malicious locations. Consider using an allow-list approach to validate URLs, or warn users they are being redirected to a third-party website. metadata: technology: - express references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect shortlink: https://sg.run/EpoP semgrep.dev: rule: r_id: 22081 rv_id: 1263140 rule_id: X5ULkq version_id: nWT2L0v url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect origin: community languages: - javascript - typescript severity: WARNING options: taint_unify_mvars: true symbolic_propagation: true mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) - metavariable-regex: metavariable: $HTTP regex: ^https?:\/\/$ - pattern-either: - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern: $RES.redirect($REQ. ... .$VALUE) - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern: $RES.redirect($REQ.$VALUE['...']) - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) - pattern: $REQ.$VALUE - patterns: - pattern-either: - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = $REQ.$VALUE['...'] ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE + $...A ... - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" - pattern-inside: | $ASSIGN = `${$REQ. ... .$VALUE}...` ... - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" - pattern-either: - pattern: $RES.redirect($ASSIGN) - pattern: $RES.redirect($ASSIGN + $...FOO) - pattern: $RES.redirect(`${$ASSIGN}...`) - focus-metavariable: $ASSIGN - id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile message: The application processes user-input, this is passed to res.sendFile which can allow an attacker to arbitrarily read files on the system through path traversal. It is recommended to perform input validation in addition to canonicalizing the path. This allows you to validate the path against the intended directory it should be accessing. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html technology: - express category: security cwe: - 'CWE-73: External Control of File Name or Path' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile shortlink: https://sg.run/7DJk semgrep.dev: rule: r_id: 22082 rv_id: 1263142 rule_id: j2UzDx version_id: 7ZTE3X9 url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | function ... (...,$REQ: $TYPE, ...) {...} - metavariable-regex: metavariable: $TYPE regex: ^(string|String) pattern-sinks: - patterns: - pattern-either: - pattern: $RES.$METH($QUERY,...) - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) - metavariable-regex: metavariable: $METH regex: ^(sendfile|sendFile)$ - focus-metavariable: $QUERY - id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: interfile: true cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - express - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret shortlink: https://sg.run/LYvG semgrep.dev: rule: r_id: 22083 rv_id: 1263143 rule_id: 10Uo39 version_id: LjTkgle url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern-inside: | $SESSION = require('express-session'); ... - pattern-inside: | import $SESSION from 'express-session' ... - pattern-inside: | import {..., $SESSION, ...} from 'express-session' ... - pattern-inside: | import * as $SESSION from 'express-session' ... - patterns: - pattern-either: - pattern-inside: $APP.use($SESSION({...})) - pattern: | $SECRET = $VALUE ... $APP.use($SESSION($SECRET)) - pattern: | secret: '$Y' - id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization message: The following function call $SER.$FUNC accepts user controlled data which can result in Remote Code Execution (RCE) through Object Deserialization. It is recommended to use secure data processing alternatives such as JSON.parse() and Buffer.from(). options: interfile: true metadata: interfile: true technology: - express category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html source_rule_url: - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization shortlink: https://sg.run/8W5j semgrep.dev: rule: r_id: 22084 rv_id: 1263145 rule_id: 9AUyqj version_id: gETB7nD url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $SER = require('$IMPORT') ... - pattern-inside: | import $SER from '$IMPORT' ... - pattern-inside: | import * as $SER from '$IMPORT' ... - metavariable-regex: metavariable: $IMPORT regex: ^(node-serialize|serialize-to-js)$ - pattern: $SER.$FUNC(...) - metavariable-regex: metavariable: $FUNC regex: ^(unserialize|deserialize)$ - id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection message: Detected a sequelize statement that is tainted by user-input. This could lead to SQL injection if the variable is user-controlled and is not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared statements. options: interfile: true metadata: interfile: true references: - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements category: security technology: - express cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection shortlink: https://sg.run/gjoe semgrep.dev: rule: r_id: 22085 rv_id: 1263241 rule_id: yyU0GX version_id: nWT2Llx url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern: sequelize.query($QUERY,...) - pattern: $DB.sequelize.query($QUERY,...) - focus-metavariable: $QUERY pattern-sanitizers: - pattern-either: - pattern: parseInt(...) - pattern: $FUNC. ... .hash(...) - id: javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization message: Detected a call to `$FUNC()` in an attempt to HTML escape the string `$STR`. Manually sanitizing input through a manually built list can be circumvented in many situations, and it's better to use a well known sanitization library such as `sanitize-html` or `DOMPurify`. metadata: category: security technology: - javascript - typescript owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://www.npmjs.com/package/dompurify - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization shortlink: https://sg.run/AzoB semgrep.dev: rule: r_id: 22550 rv_id: 1263104 rule_id: kxUYE9 version_id: l4TJR1L url: https://semgrep.dev/playground/r/l4TJR1L/javascript.audit.detect-replaceall-sanitization.detect-replaceall-sanitization origin: community languages: - javascript - typescript severity: INFO patterns: - pattern-either: - pattern: $STR.$FUNC('<', '<') - pattern: $STR.$FUNC('>', '>') - pattern: $STR.$FUNC('"', '"') - pattern: $STR.$FUNC("'", ''') - pattern: $STR.$FUNC('&', '&') - metavariable-regex: metavariable: $FUNC regex: (replace|replaceAll) - id: javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage message: A CSRF middleware was not detected in your express application. Ensure you are either using one such as `csurf` or `csrf` (see rule references) and/or you are properly doing CSRF validation in your routes with a token or cookies. metadata: category: security references: - https://www.npmjs.com/package/csurf - https://www.npmjs.com/package/csrf - https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - javascript - typescript - express cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage shortlink: https://sg.run/BxzR semgrep.dev: rule: r_id: 22551 rv_id: 1263128 rule_id: wdUKEq version_id: yeTxp5d url: https://semgrep.dev/playground/r/yeTxp5d/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage origin: community languages: - javascript - typescript severity: INFO patterns: - pattern-inside: | $EXPRESS = require('express') ... - pattern-not-inside: | import {$CSRF} from 'csurf' ... - pattern-not-inside: | require('csurf') ... - pattern-not-inside: | import {$CSRF} from 'csrf' ... - pattern-not-inside: | require('csrf') ... - pattern: | $APP = $EXPRESS() - id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing message: Directory listing/indexing is enabled, which may lead to disclosure of sensitive directories and files. It is recommended to disable directory listing unless it is a public resource. If you need directory listing, ensure that sensitive files are inaccessible when querying the resource. options: interfile: true metadata: interfile: true cwe: - 'CWE-548: Exposure of Information Through Directory Listing' owasp: - A06:2017 - Security Misconfiguration - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - express references: - https://www.npmjs.com/package/serve-index - https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/ subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing shortlink: https://sg.run/DX2G semgrep.dev: rule: r_id: 22552 rv_id: 1263129 rule_id: x8UqEb version_id: rxTAKGb url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $APP.use(require('serve-index')(...)) - patterns: - pattern-either: - pattern-inside: | $SERVEINDEX = require('serve-index') ... - pattern-inside: | import $SERVEINDEX from 'serve-index' ... - pattern-inside: | import * as $SERVEINDEX from 'serve-index' ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $SERVEINDEX(...) ... - pattern: | $VALUE(...) - pattern: | $APP.use(..., $SERVEINDEX(...), ...) - id: javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage message: Detected usage of the `notevil` package, which is unmaintained and has vulnerabilities. Using any sort of `eval()` functionality can be very dangerous, but if you must, the `eval` package is an up to date alternative. Be sure that only trusted input reaches an `eval()` function. metadata: category: security references: - https://github.com/mmckegg/notevil cwe: - 'CWE-1104: Use of Unmaintained Third Party Components' owasp: - A06:2021 - Vulnerable and Outdated Components - A03:2025 - Software Supply Chain Failures technology: - javascript - typescript subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage shortlink: https://sg.run/W70E semgrep.dev: rule: r_id: 22553 rv_id: 1263136 rule_id: OrUX9K version_id: e1TyjGl url: https://semgrep.dev/playground/r/e1TyjGl/javascript.express.security.audit.express-detect-notevil-usage.express-detect-notevil-usage origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern-inside: | import $EVAL from 'notevil' ... - pattern-inside: | import {$EVAL} from 'notevil' ... - pattern-inside: | $EVAL = require('notevil') ... - pattern-either: - patterns: - pattern: $EVAL(...) - pattern-not: $EVAL('...') - patterns: - pattern-either: - pattern: $VM.runInContext("$CMD", ...) - pattern: $VM.runInNewContext("$CMD", ...) - pattern: $VM.runInThisContext("$CMD", ...) - pattern: $VM.compileFunction("$CMD", ...) - metavariable-pattern: patterns: - pattern: $EVAL(...) - pattern-not: $EVAL('...') metavariable: $CMD language: typescript - id: javascript.express.security.audit.express-ssrf.express-ssrf message: 'The following request $REQUEST.$METHOD() was found to be crafted from user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities. It is recommended where possible to not allow user-input to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommeneded to follow OWASP best practices to prevent abuse. ' metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' technology: - express category: security owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf shortlink: https://sg.run/0PNw semgrep.dev: rule: r_id: 22554 rv_id: 1263144 rule_id: eqU9l2 version_id: 8KT5rBr url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf origin: community languages: - javascript - typescript severity: WARNING mode: taint options: taint_unify_mvars: true pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, ...) {...} - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,...) => {...} - pattern-inside: | ({ $REQ }: $EXPRESS.Request,...) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern-either: - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) - pattern: $REQ. ... .$VALUE - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) - pattern: $REQ.$VALUE - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE['...'] ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE + $...A ... - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" - pattern-inside: | $ASSIGN = `${$REQ. ... .$VALUE}...` ... - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" - patterns: - pattern-either: - pattern-inside: | $ASSIGN = "$HTTP"+ $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ.$VALUE[...] ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A ... - pattern-inside: | $ASSIGN = `$HTTP${$REQ.$VALUE[...]}...` ... - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern-either: - pattern: $REQUEST.$METHOD($ASSIGN,...) - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) - patterns: - pattern-either: - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern: $ASSIGN - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - id: javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key message: Detected a hardcoded hmac key. Avoid hardcoding secrets and consider using an alternate option such as reading the secret from a config file or using an environment variable. options: interfile: true metadata: interfile: true category: security technology: - crypto - hmac references: - https://rules.sonarsource.com/javascript/RSPEC-2068 - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#key-management owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-798: Use of Hard-coded Credentials' cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key shortlink: https://sg.run/K9bn semgrep.dev: rule: r_id: 22555 rv_id: 1263198 rule_id: v8UGEw version_id: A8Tgdyk url: https://semgrep.dev/playground/r/A8Tgdyk/javascript.lang.security.audit.hardcoded-hmac-key.hardcoded-hmac-key origin: community languages: - javascript - typescript severity: WARNING pattern-either: - pattern: $CRYPTO.createHmac($ALGO, '...') - patterns: - pattern-inside: | const $SECRET = '...' ... - pattern: $CRYPTO.createHmac($ALGO, $SECRET) - id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure patterns: - pattern: $APP.UseDeveloperExceptionPage(...); - pattern-not-inside: | if ($ENV.IsDevelopment(...)) { ... } - pattern-not-inside: | if ($ENV.EnvironmentName == "Development") { ... } message: Stacktrace information is displayed in a non-Development environment. Accidentally disclosing sensitive stack trace information in a production environment aids an attacker in reconnaissance and information gathering. metadata: category: security technology: - csharp owasp: - A06:2017 - Security Misconfiguration - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-209: Generation of Error Message Containing Sensitive Information' references: - https://cwe.mitre.org/data/definitions/209.html - https://owasp.org/Top10/A04_2021-Insecure_Design/ subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure shortlink: https://sg.run/XvkA semgrep.dev: rule: r_id: 26720 rv_id: 1262653 rule_id: lBU6Dv version_id: 0bTKzrB url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure origin: community languages: - csharp severity: WARNING - id: csharp.dotnet.security.audit.mass-assignment.mass-assignment message: Mass assignment or Autobinding vulnerability in code allows an attacker to execute over-posting attacks, which could create a new parameter in the binding request and manipulate the underlying object in the application. severity: WARNING metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://cwe.mitre.org/data/definitions/915.html - https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment shortlink: https://sg.run/7B3e semgrep.dev: rule: r_id: 26838 rv_id: 1262613 rule_id: x8Up5B version_id: YDTZeD9 url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment origin: community languages: - csharp mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | public IActionResult $METHOD(..., $TYPE $ARG, ...){ ... } - pattern: | public ActionResult $METHOD(..., $TYPE $ARG, ...){ ... } - pattern-inside: | using Microsoft.AspNetCore.Mvc; ... - pattern-not: | public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ ... } - pattern-not: | public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ ... } - focus-metavariable: $ARG pattern-sinks: - pattern: View(...) - id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $X = code.InteractiveConsole(...) ... - pattern-inside: | $X = code.InteractiveInterpreter(...) ... - pattern-either: - pattern: | $X.push($PAYLOAD,...) - pattern: | $X.runsource($PAYLOAD,...) - pattern: | $X.runcode(code.compile_command($PAYLOAD),...) - pattern: | $PL = code.compile_command($PAYLOAD,...) ... $X.runcode($PL,...) - focus-metavariable: $PAYLOAD - pattern-not: | $X.push("...",...) - pattern-not: | $X.runsource("...",...) - pattern-not: | $X.runcode(code.compile_command("..."),...) - pattern-not: | $PL = code.compile_command("...",...) ... $X.runcode($PL,...) message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if external data can reach this function call because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run shortlink: https://sg.run/9pRY semgrep.dev: rule: r_id: 27267 rv_id: 1263521 rule_id: KxUKzx version_id: l4TJRgo url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run origin: community severity: WARNING languages: - python - id: python.lang.security.dangerous-os-exec.dangerous-os-exec mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD("...", ...) - pattern: os.$METHOD(...) - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) - patterns: - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execv|execve|execvp|execvpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' confidence: MEDIUM category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec shortlink: https://sg.run/yL9x semgrep.dev: rule: r_id: 27268 rv_id: 1263523 rule_id: qNUR13 version_id: 6xT29rz url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession - patterns: - pattern-either: - pattern: os.environ['$ANYTHING'] - pattern: os.environ.get('$FOO', ...) - pattern: os.environb['$ANYTHING'] - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv[...] - pattern: sys.orig_argv[...] - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD($MODE, "...", ...) - pattern-inside: os.$METHOD($MODE, $CMD, ...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) - patterns: - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process shortlink: https://sg.run/r8Zn semgrep.dev: rule: r_id: 27269 rv_id: 1263524 rule_id: lBUJrn version_id: o5TbDO5 url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern: | _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) - pattern-not: | _xxsubinterpreters.run_string($ID, "...", ...) - focus-metavariable: $PAYLOAD message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://bugs.python.org/issue43472 - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string shortlink: https://sg.run/bPop semgrep.dev: rule: r_id: 27270 rv_id: 1263525 rule_id: PeURWr version_id: zyTb2OX url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string origin: community severity: WARNING languages: - python - id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...",...], ...) - pattern-not: subprocess.$FUNC(("...",...), ...) - pattern-not: subprocess.CalledProcessError(...) - pattern-not: subprocess.SubprocessError(...) - pattern: subprocess.$FUNC($CMD, ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) - pattern: subprocess.$FUNC("=~/(python)/", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) - focus-metavariable: $CMD message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess - https://docs.python.org/3/library/subprocess.html - https://docs.python.org/3/library/shlex.html - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use shortlink: https://sg.run/NWxp semgrep.dev: rule: r_id: 27271 rv_id: 1263526 rule_id: JDUz3R version_id: pZT038J url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-system-call.dangerous-system-call mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-not: os.$W("...", ...) - pattern-either: - pattern: os.system(...) - pattern: getattr(os, "system")(...) - pattern: __import__("os").system(...) - pattern: getattr(__import__("os"), "system")(...) - pattern: | $X = __import__("os") ... $X.system(...) - pattern: | $X = __import__("os") ... getattr($X, "system")(...) - pattern: | $X = getattr(os, "system") ... $X(...) - pattern: | $X = __import__("os") ... $Y = getattr($X, "system") ... $Y(...) - pattern: os.popen(...) - pattern: os.popen2(...) - pattern: os.popen3(...) - pattern: os.popen4(...) message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection vulnerability. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call shortlink: https://sg.run/k0W7 semgrep.dev: rule: r_id: 27272 rv_id: 1263527 rule_id: 5rUoP1 version_id: 2KTv2Zn url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern: | _testcapi.run_in_subinterp($PAYLOAD, ...) - pattern: | test.support.run_in_subinterp($PAYLOAD, ...) - focus-metavariable: $PAYLOAD - pattern-not: | _testcapi.run_in_subinterp("...", ...) - pattern-not: | test.support.run_in_subinterp("...", ...) message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp shortlink: https://sg.run/wLpY semgrep.dev: rule: r_id: 27273 rv_id: 1263528 rule_id: GdUkxR version_id: X0Tzy1e url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp origin: community severity: WARNING languages: - python - id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation patterns: - pattern-either: - patterns: - pattern: $LIFETIME = $FALSE - pattern-inside: new TokenValidationParameters {...} - patterns: - pattern: | (TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE - metavariable-regex: metavariable: $LIFETIME regex: (RequireExpirationTime|ValidateLifetime) - metavariable-regex: metavariable: $FALSE regex: (false) - focus-metavariable: $FALSE fix: | true message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the JWT tokens lifetime is not validated. This can lead to an JWT token being used after it has expired, which has security implications. It is recommended to validate the JWT lifetime to ensure only valid tokens are used. metadata: category: security technology: - csharp owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-613: Insufficient Session Expiration' references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ - https://cwe.mitre.org/data/definitions/613.html - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation shortlink: https://sg.run/KA0d semgrep.dev: rule: r_id: 28955 rv_id: 1262628 rule_id: bwU5kK version_id: w8TRolJ url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation origin: community languages: - csharp severity: WARNING - id: python.django.security.injection.command.subprocess-injection.subprocess-injection languages: - python mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-inside: | def $FUNC(..., $REQUEST, ...): ... - focus-metavariable: $REQUEST - metavariable-pattern: metavariable: $REQUEST patterns: - pattern: request - pattern-not-inside: request.build_absolute_uri pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: subprocess.$FUNC(...) - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...", ...], ...) - pattern-not-inside: | $CMD = ["...", ...] ... subprocess.$FUNC($CMD, ...) - patterns: - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) - metavariable-regex: metavariable: $SHELL regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ - patterns: - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) - metavariable-regex: metavariable: $INTERPRETER regex: ^(python|python\d)$ pattern-sanitizers: - patterns: - pattern: $DICT[$KEY] - focus-metavariable: $KEY severity: ERROR message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. metadata: category: security technology: - flask owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection shortlink: https://sg.run/49BE semgrep.dev: rule: r_id: 31144 rv_id: 1263388 rule_id: EwUepx version_id: 7ZTE3qK url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection origin: community - id: python.flask.security.injection.subprocess-injection.subprocess-injection languages: - python mode: taint options: symbolic_propagation: true pattern-sources: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: subprocess.$FUNC(...) - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...", ...], ...) - pattern-not-inside: | $CMD = ["...", ...] ... subprocess.$FUNC($CMD, ...) - patterns: - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) - metavariable-regex: metavariable: $SHELL regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ - patterns: - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) - metavariable-regex: metavariable: $INTERPRETER regex: ^(python|python\d)$ pattern-sanitizers: - patterns: - pattern: $DICT[$KEY] - focus-metavariable: $KEY severity: ERROR message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. metadata: category: security technology: - flask owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection shortlink: https://sg.run/5gW3 semgrep.dev: rule: r_id: 31147 rv_id: 1263433 rule_id: 8GU3qp version_id: bZT53gQ url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection origin: community - id: yaml.github-actions.security.github-script-injection.github-script-injection languages: - yaml message: 'Using variable interpolation `${{...}}` with `github` context data in a `actions/github-script`''s `script:` step could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment variable, like this: "$ENVVAR".' metadata: category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections - https://securitylab.github.com/research/github-actions-untrusted-input/ - https://github.com/actions/github-script technology: - github-actions cwe2022-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection shortlink: https://sg.run/g1G0 semgrep.dev: rule: r_id: 31441 rv_id: 1423394 rule_id: OrUQvK version_id: 5PT7Zyw url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | uses: $ACTION ... - pattern-inside: | with: ... script: ... ... - pattern: 'script: $SHELL' - metavariable-regex: metavariable: $ACTION regex: actions/github-script@.* - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ ... github.event.issue.title ... }} - pattern: ${{ ... github.event.issue.body ... }} - pattern: ${{ ... github.event.pull_request.title ... }} - pattern: ${{ ... github.event.pull_request.body ... }} - pattern: ${{ ... github.event.comment.body ... }} - pattern: ${{ ... github.event.review.body ... }} - pattern: ${{ ... github.event.review_comment.body ... }} - pattern: ${{ ... github.event.pages ... .page_name ... }} - pattern: ${{ ... github.event.head_commit.message ... }} - pattern: ${{ ... github.event.head_commit.author.email ... }} - pattern: ${{ ... github.event.head_commit.author.name ... }} - pattern: ${{ ... github.event.commits ... .author.email ... }} - pattern: ${{ ... github.event.commits ... .author.name ... }} - pattern: ${{ ... github.event.commits ... .message ... }} - pattern: ${{ ... github.event.pull_request.head.ref ... }} - pattern: ${{ ... github.event.pull_request.head.label ... }} - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} - pattern: ${{ ... github.ref ... }} - pattern: ${{ ... github.base_ref ... }} - pattern: ${{ ... github.head_ref ... }} - pattern: ${{ ... github.ref_name ... }} - pattern: ${{ ... github.workflow ... }} - pattern: ${{ ... github.event.inputs ... }} - pattern: ${{ ... github.event.discussion.title ... }} - pattern: ${{ ... github.event.discussion.body ... }} - pattern: ${{ ... github.event.workflow_run.head_branch ... }} - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} - pattern: ${{ ... github.event.milestone.title ... }} - pattern: ${{ ... github.event.milestone.description ... }} - pattern: ${{ ... github.event.project_card.note ... }} - pattern: ${{ ... github.event.project.name ... }} - pattern: ${{ ... github.event.project_column.name ... }} - pattern: ${{ ... github.event.release.name ... }} - pattern: ${{ ... github.event.release.body ... }} - pattern: ${{ ... github.event.deployment.ref ... }} - pattern: ${{ ... inputs ... }} - pattern-not: ${{ ... github.event.issue.title && ... }} - pattern-not: ${{ ... github.event.issue.body && ... }} - pattern-not: ${{ ... github.event.pull_request.title && ... }} - pattern-not: ${{ ... github.event.pull_request.body && ... }} - pattern-not: ${{ ... github.event.comment.body && ... }} - pattern-not: ${{ ... github.event.review.body && ... }} - pattern-not: ${{ ... github.event.review_comment.body && ... }} - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} - pattern-not: ${{ ... github.event.head_commit.message && ... }} - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .message && ... }} - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} - pattern-not: ${{ ... github.ref && ... }} - pattern-not: ${{ ... github.base_ref && ... }} - pattern-not: ${{ ... github.head_ref && ... }} - pattern-not: ${{ ... github.ref_name && ... }} - pattern-not: ${{ ... github.workflow && ... }} - pattern-not: ${{ ... github.event.inputs && ... }} - pattern-not: ${{ ... github.event.discussion.title && ... }} - pattern-not: ${{ ... github.event.discussion.body && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} - pattern-not: ${{ ... github.event.milestone.title && ... }} - pattern-not: ${{ ... github.event.milestone.description && ... }} - pattern-not: ${{ ... github.event.project_card.note && ... }} - pattern-not: ${{ ... github.event.project.name && ... }} - pattern-not: ${{ ... github.event.project_column.name && ... }} - pattern-not: ${{ ... github.event.release.name && ... }} - pattern-not: ${{ ... github.event.release.body && ... }} - pattern-not: ${{ ... github.event.deployment.ref && ... }} severity: ERROR - id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial stream output. Its use is strongly discouraged. ARC4 does not use mode constructions. Use a strong symmetric cipher such as EAS instead. With the `cryptography` package it is recommended to use the `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 shortlink: https://sg.run/xoZL semgrep.dev: rule: r_id: 33630 rv_id: 1263348 rule_id: KxU8gK version_id: QkTGq3Q url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) - metavariable-regex: metavariable: $ARC4 regex: ^(ARC4)$ - focus-metavariable: $ARC4 fix: AES - id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish message: Blowfish is a block cipher developed by Bruce Schneier. It is known to be susceptible to attacks when using weak keys. The author has recommended that users of Blowfish move to newer algorithms such as AES. With the `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers - https://tools.ietf.org/html/rfc5469 category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish shortlink: https://sg.run/OdzL semgrep.dev: rule: r_id: 33631 rv_id: 1263349 rule_id: qNULvO version_id: 3ZT4XK7 url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) - metavariable-regex: metavariable: $BLOWFISH regex: ^(Blowfish)$ - focus-metavariable: $BLOWFISH fix: AES - id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B303 references: - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - cryptography subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 shortlink: https://sg.run/eY88 semgrep.dev: rule: r_id: 33632 rv_id: 1263352 rule_id: lBUopp version_id: JdTzxww url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.hashes.$MD5() - metavariable-regex: metavariable: $MD5 regex: ^(MD5)$ - focus-metavariable: $MD5 fix: SHA256 - id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish shortlink: https://sg.run/dlOE semgrep.dev: rule: r_id: 33634 rv_id: 1263545 rule_id: JDUGnK version_id: ExTExln url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.Blowfish.new(...) - pattern: Crypto.Cipher.Blowfish.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des message: Detected DES cipher or Triple DES algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use a secure symmetric cipher from the cryptodome package instead. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des shortlink: https://sg.run/Z5bw semgrep.dev: rule: r_id: 33635 rv_id: 1263546 rule_id: 5rUr73 version_id: 7ZTE3G7 url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.DES.new(...) - pattern: Crypto.Cipher.DES.new(...) - pattern: Cryptodome.Cipher.DES3.new(...) - pattern: Crypto.Cipher.DES3.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 message: Detected RC2 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 shortlink: https://sg.run/nAbY semgrep.dev: rule: r_id: 33636 rv_id: 1263547 rule_id: GdUYlW version_id: LjTkgn6 url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.ARC2.new(...) - pattern: Crypto.Cipher.ARC2.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 shortlink: https://sg.run/Eo6N semgrep.dev: rule: r_id: 33637 rv_id: 1263548 rule_id: ReUnEB version_id: 8KT5rXY url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 origin: community severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.ARC4.new(...) - pattern: Crypto.Cipher.ARC4.new(...) - id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 shortlink: https://sg.run/7JP2 semgrep.dev: rule: r_id: 33638 rv_id: 1263550 rule_id: AbU0Ex version_id: QkTGqD8 url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD2.new(...) - pattern: Cryptodome.Hash.MD2.new (...) - id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 shortlink: https://sg.run/Lve6 semgrep.dev: rule: r_id: 33639 rv_id: 1263551 rule_id: BYUJy4 version_id: 3ZT4Xnp url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD4.new(...) - pattern: Cryptodome.Hash.MD4.new (...) - id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 shortlink: https://sg.run/85JN semgrep.dev: rule: r_id: 33640 rv_id: 1263552 rule_id: DbUXwo version_id: 44TEjpk url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD5.new(...) - pattern: Cryptodome.Hash.MD5.new (...) - id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout languages: - yaml message: This GitHub Actions workflow file uses `workflow_run` and checks out code from the incoming pull request. When using `workflow_run`, the Action runs in the context of the target repository, which includes access to all repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. metadata: category: security owasp: A01:2017 - Injection cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM subcategory: - vuln references: - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability technology: - github-actions license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout shortlink: https://sg.run/A0p6 semgrep.dev: rule: r_id: 35494 rv_id: 947046 rule_id: 4bU8E4 version_id: kbTYRwl url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout origin: community patterns: - pattern-inside: | on: ... workflow_run: ... ... ... - pattern-inside: | jobs: ... $JOBNAME: ... steps: ... - pattern: | ... uses: "$ACTION" with: ... ref: $EXPR - metavariable-regex: metavariable: $ACTION regex: actions/checkout@.* - metavariable-pattern: language: generic metavariable: $EXPR patterns: - pattern: ${{ github.event.workflow_run ... }} severity: WARNING - id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode message: Usage of the insecure ECB mode detected. You should use an authenticated encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode shortlink: https://sg.run/wj9n semgrep.dev: rule: r_id: 36773 rv_id: 1262623 rule_id: 0oUqWP version_id: yeTxpPw url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode origin: community languages: - csharp patterns: - pattern-either: - pattern: ($KEYTYPE $KEY).EncryptEcb(...); - pattern: ($KEYTYPE $KEY).DecryptEcb(...); - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; - metavariable-pattern: metavariable: $KEYTYPE pattern-either: - pattern: SymmetricAlgorithm - pattern: Aes - pattern: Rijndael - pattern: DES - pattern: TripleDES - pattern: RC2 - id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration message: You are using an insecure random number generator (RNG) to create a cryptographic key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator instead. severity: ERROR metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration shortlink: https://sg.run/xjrA semgrep.dev: rule: r_id: 36774 rv_id: 1262624 rule_id: KxU3Nq version_id: rxTAK2O url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration origin: community languages: - csharp mode: taint pattern-sources: - patterns: - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... - pattern: $KEY pattern-sinks: - pattern-either: - patterns: - pattern: ($KEYTYPE $CIPHER).Key = $SINK; - focus-metavariable: $SINK - metavariable-pattern: metavariable: $KEYTYPE pattern-either: - pattern: SymmetricAlgorithm - pattern: Aes - pattern: Rijndael - pattern: DES - pattern: TripleDES - pattern: RC2 - pattern: new AesGcm(...) - pattern: new AesCcm(...) - pattern: new ChaCha20Poly1305(...) - id: html.security.plaintext-http-link.plaintext-http-link metadata: category: security technology: - html cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures confidence: HIGH subcategory: - vuln references: - https://cwe.mitre.org/data/definitions/319.html likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link shortlink: https://sg.run/RA5q semgrep.dev: rule: r_id: 39193 rv_id: 1262976 rule_id: AbUnNo version_id: xyTjzRL url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link origin: community patterns: - pattern: ... - metavariable-regex: metavariable: $URL regex: ^(?i)http:// message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL if possible. severity: WARNING languages: - html - id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use HMAC instead. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::org.apache.commons owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils shortlink: https://sg.run/AWL2 semgrep.dev: rule: r_id: 39194 rv_id: 1263012 rule_id: BYUGK0 version_id: WrTqK7K url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils origin: community patterns: - pattern: | $DU.$GET_ALGO().digest(...) - metavariable-pattern: metavariable: $GET_ALGO pattern: getMd5Digest - metavariable-pattern: metavariable: $DU pattern: DigestUtils - focus-metavariable: $GET_ALGO fix: | getSha512Digest - id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid message: Dangerously accepting invalid TLS information pattern-either: - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true) - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true) metadata: references: - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs technology: - reqwest category: security cwe: 'CWE-295: Improper Certificate Validation' confidence: HIGH likelihood: LOW impact: MEDIUM subcategory: vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid shortlink: https://sg.run/DqrG semgrep.dev: rule: r_id: 40108 rv_id: 946551 rule_id: qNUKDg version_id: 7ZTrQLJ url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid origin: community languages: - rust severity: WARNING - id: rust.lang.security.rustls-dangerous.rustls-dangerous message: Dangerous client config used, ensure SSL verification pattern-either: - pattern: rustls::client::DangerousClientConfig - pattern: $CLIENT.dangerous().set_certificate_verifier(...) - pattern: | let $CLIENT = rustls::client::ClientConfig::dangerous(...); ... $CLIENT.set_certificate_verifier(...); metadata: references: - https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html - https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous technology: - rustls category: security cwe: 'CWE-295: Improper Certificate Validation' confidence: HIGH likelihood: LOW impact: MEDIUM subcategory: vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous shortlink: https://sg.run/01Rw semgrep.dev: rule: r_id: 40110 rv_id: 946553 rule_id: YGU8LK version_id: 8KTKjdO url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous origin: community languages: - rust severity: WARNING - id: rust.lang.security.ssl-verify-none.ssl-verify-none message: SSL verification disabled, this allows for MitM attacks pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE) metadata: references: - https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify technology: - openssl category: security cwe: 'CWE-295: Improper Certificate Validation' confidence: HIGH likelihood: LOW impact: MEDIUM subcategory: vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none shortlink: https://sg.run/K2Pn semgrep.dev: rule: r_id: 40111 rv_id: 946554 rule_id: 6JU0Bl version_id: gETe1bo url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none origin: community languages: - rust severity: WARNING - id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection message: Using input or workflow parameters in here-scripts can lead to command injection or code injection. Convert the parameters to env variables instead. languages: - yaml metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - "A03:2021 \u2013 Injection" confidence: MEDIUM likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://github.com/argoproj/argo-workflows/issues/5061 - https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370 technology: - ci - argo license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection - Command Injection source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection shortlink: https://sg.run/yqeZ semgrep.dev: rule: r_id: 40768 rv_id: 1151472 rule_id: 10U0zW version_id: xyTp17z url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection origin: community severity: ERROR patterns: - pattern-inside: | apiVersion: $VERSION ... - metavariable-regex: metavariable: $VERSION regex: (argoproj.io.*) - pattern-either: - patterns: - pattern-inside: | command: ... - $LANG ... ... source: $SCRIPT - metavariable-regex: metavariable: $LANG regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* - metavariable-pattern: metavariable: $SCRIPT pattern-either: - pattern-regex: (.*{{.*inputs.parameters.*}}.*) - pattern-regex: (.*{{.*workflow.parameters.*}}.*) - focus-metavariable: $SCRIPT - patterns: - pattern-either: - pattern-inside: | container: ... command: $LANG ... args: $PARAM - pattern-inside: | containerSet: ... containers: - ... command: $LANG ... args: $PARAM - metavariable-regex: metavariable: $LANG regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* - metavariable-pattern: metavariable: $PARAM pattern-either: - pattern-regex: (.*{{.*inputs.parameters.*}}.*) - pattern-regex: (.*{{.*workflow.parameters.*}}.*) - focus-metavariable: $PARAM - id: python.cryptography.security.empty-aes-key.empty-aes-key message: Potential empty AES encryption key. Using an empty key in AES encryption can result in weak encryption and may allow attackers to easily decrypt sensitive data. Ensure that a strong, non-empty key is used for AES encryption. patterns: - pattern: AES.new("",...) languages: - python severity: WARNING metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' - 'CWE-310: Cryptographic Issues' references: - https://cwe.mitre.org/data/definitions/327.html - https://cwe.mitre.org/data/definitions/310.html category: security subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM owasp: A6:2017 misconfiguration functional-categories: - crypto::search::key-length::pycrypto - crypto::search::key-length::pycryptodome technology: - python - pycrypto - pycryptodome license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key shortlink: https://sg.run/zQ9G semgrep.dev: rule: r_id: 44817 rv_id: 946105 rule_id: OrUADK version_id: 8KTKjRg url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key origin: community - id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint patterns: - pattern: | ENTRYPOINT $...VARS - pattern-not-inside: | USER $USER ... fix: | USER non-root ENTRYPOINT $...VARS message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-269: Improper Privilege Management' category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint shortlink: https://sg.run/k281 semgrep.dev: rule: r_id: 47272 rv_id: 1262659 rule_id: ReUW9E version_id: o5TbD21 url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint origin: community - id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions pattern-either: - pattern: | resource "aws_config_configuration_aggregator" $ANYTHING { ... account_aggregation_source { ... regions = ... ... } ... } - pattern: | resource "aws_config_configuration_aggregator" $ANYTHING { ... organization_aggregation_source { ... regions = ... ... } ... } message: The AWS configuration aggregator does not aggregate all AWS Config region. This may result in unmonitored configuration in regions that are thought to be unused. Configure the aggregator with all_regions for the source. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ subcategory: - audit likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions shortlink: https://sg.run/O6A7 semgrep.dev: rule: r_id: 47275 rv_id: 1263703 rule_id: DbUo7v version_id: A8Tgdwv url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions origin: community - id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext patterns: - pattern-inside: | containers: ... - pattern-inside: | - $NAME: $CONTAINER ... - pattern: | image: ... ... - pattern-not: | image: ... ... securityContext: ... - metavariable-regex: metavariable: $NAME regex: name - focus-metavariable: $NAME fix: | securityContext: allowPrivilegeEscalation: false $NAME message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. By adding a `securityContext` to your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext shortlink: https://sg.run/eleR semgrep.dev: rule: r_id: 47276 rv_id: 1263931 rule_id: WAU5J6 version_id: 2KTv2j8 url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true patterns: - pattern-inside: | containers: ... - pattern-inside: | - name: $CONTAINER ... - pattern-inside: | image: ... ... - pattern-inside: | securityContext: ... - pattern: | allowPrivilegeEscalation: $TRUE - metavariable-pattern: metavariable: $TRUE pattern: | true - focus-metavariable: $TRUE fix: | false message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. In the container `$CONTAINER` this parameter is set to `true` which makes this container much more vulnerable to privelege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true shortlink: https://sg.run/vw3W semgrep.dev: rule: r_id: 47277 rv_id: 1263932 rule_id: 0oUkqQ version_id: X0Tzyqr url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true origin: community languages: - yaml severity: WARNING - id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled patterns: - pattern: | resource "aws_docdb_cluster" $ANYTHING { ... } - pattern-not-inside: | resource "aws_docdb_cluster" $ANYTHING { ... enabled_cloudwatch_logs_exports = [..., "audit", ...] ... } message: Auditing is not enabled for DocumentDB. To ensure that you are able to accurately audit the usage of your DocumentDB cluster, you should enable auditing and export logs to CloudWatch. languages: - hcl severity: INFO metadata: category: security technology: - terraform - aws owasp: - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled shortlink: https://sg.run/xJYP semgrep.dev: rule: r_id: 48630 rv_id: 1263705 rule_id: AbU1WN version_id: DkTRbA4 url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled origin: community - id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags patterns: - pattern: | resource "aws_ecr_repository" $ANYTHING { ... } - pattern-not-inside: | resource "aws_ecr_repository" $ANYTHING { ... image_tag_mutability = "IMMUTABLE" ... } message: The ECR repository allows tag mutability. Image tags could be overwritten with compromised images. ECR images should be set to IMMUTABLE to prevent code injection through image mutation. This can be done by setting `image_tag_mutability` to IMMUTABLE. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags shortlink: https://sg.run/ZEeL semgrep.dev: rule: r_id: 48635 rv_id: 1263716 rule_id: KxUB4o version_id: A8Tgdwd url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags origin: community - id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal patterns: - pattern-inside: | resource "aws_ecr_repository_policy" $ANYTHING { ... } - pattern-either: - patterns: - pattern: policy = "$JSONPOLICY" - metavariable-pattern: metavariable: $JSONPOLICY language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], ...} - pattern: | {..., "Principal": { "AWS": "*" }, ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, ...} - patterns: - pattern-inside: policy = jsonencode(...) - pattern-not-inside: | {..., Effect = "Deny", ...} - pattern-either: - pattern: | {..., Principal = "*", ...} - pattern: | {..., Principal = [..., "*", ...], ...} - pattern: | {..., Principal = { AWS = "*" }, ...} - pattern: | {..., Principal = { AWS = [..., "*", ...] }, ...} message: Detected wildcard access granted in your ECR repository policy principal. This grants access to all users, including anonymous users (public access). Instead, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy - https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html - https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal shortlink: https://sg.run/nzqb semgrep.dev: rule: r_id: 48636 rv_id: 1263717 rule_id: qNUzov version_id: BjTkZ6A url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal origin: community languages: - hcl severity: WARNING - id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb pattern: $CIPHER.getInstance("=~/AES/ECB.*/") metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb shortlink: https://sg.run/dB2Y semgrep.dev: rule: r_id: 48734 rv_id: 1263009 rule_id: WAU2yA version_id: A8TgdEo url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb origin: community message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality and is not semantically secure so should not be used. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish pattern: $CIPHER.getInstance("Blowfish") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish shortlink: https://sg.run/ZE4n semgrep.dev: rule: r_id: 48735 rv_id: 1263010 rule_id: 0oUR28 version_id: BjTkZy0 url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish origin: community message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes pattern-either: - patterns: - pattern-either: - pattern-inside: | import javax; ... - pattern-either: - pattern: javax.crypto.Cipher.getInstance("AES") - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") - patterns: - pattern-either: - pattern-inside: | import javax.*; ... - pattern-inside: | import javax.crypto; ... - pattern-either: - pattern: crypto.Cipher.getInstance("AES") - pattern: (crypto.Cipher $CIPHER).getInstance("AES") - patterns: - pattern-either: - pattern-inside: | import javax.crypto.*; ... - pattern-inside: | import javax.crypto.Cipher; ... - pattern-either: - pattern: Cipher.getInstance("AES") - pattern: (Cipher $CIPHER).getInstance("AES") metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes shortlink: https://sg.run/nzKO semgrep.dev: rule: r_id: 48736 rv_id: 1263011 rule_id: KxUB7Z version_id: DkTRbwy url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes origin: community message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses ECB mode. ECB doesn''t provide message confidentiality and is not semantically secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 pattern: $CIPHER.getInstance("RC2") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 shortlink: https://sg.run/EEvA semgrep.dev: rule: r_id: 48737 rv_id: 1263014 rule_id: qNUzXG version_id: K3TKkg0 url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 origin: community message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 pattern: $CIPHER.getInstance("RC4") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 shortlink: https://sg.run/7OYR semgrep.dev: rule: r_id: 48738 rv_id: 1263015 rule_id: lBUw8k version_id: qkTR7vk url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 origin: community message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including stream cipher attacks and bit flipping attacks. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request message: Detected an HTTP request sent via HttpGet. This could lead to sensitive information being sent over an insecure channel. Instead, it is recommended to send requests over HTTPS. severity: WARNING metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: A03:2017 - Sensitive Data Exposure references: - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection() subcategory: - vuln technology: - java vulnerability: Insecure Transport license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request shortlink: https://sg.run/QE2q semgrep.dev: rule: r_id: 48942 rv_id: 946061 rule_id: 6JUOJ2 version_id: WrTEo9G url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request origin: community languages: - java fix-regex: regex: '[Hh][Tt][Tt][Pp]://' replacement: https:// count: 1 patterns: - pattern: | "=~/[Hh][Tt][Tt][Pp]://.*/" - pattern-inside: | $R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/"); ... $CLIENT. ... .execute($R, ...); - id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted patterns: - pattern: | resource "aws_ebs_volume" $ANYTHING { ... } - pattern-not: | resource "aws_ebs_volume" $ANYTHING { ... encrypted = true ... } message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived snapshots could be read if compromised. Volumes should be encrypted to ensure sensitive data is stored securely. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted shortlink: https://sg.run/6ZbY semgrep.dev: rule: r_id: 50759 rv_id: 1263708 rule_id: YGUKl1 version_id: K3TKk1Z url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted origin: community - id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled patterns: - pattern: | resource "aws_launch_template" $ANYTHING { ... } - pattern-not-inside: | resource "aws_launch_template" $ANYTHING { ... metadata_options { ... http_endpoint = "disabled" ... } ... } - pattern-not-inside: | resource "aws_launch_template" $ANYTHING { ... metadata_options { ... http_tokens = "required" ... } ... } message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1) enabled. IMDSv2 introduced session authentication tokens which improve security when talking to IMDS. You should either disable IMDS or require the use of IMDSv2. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-1390: Weak Authentication' references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled shortlink: https://sg.run/pg9J semgrep.dev: rule: r_id: 50762 rv_id: 1263712 rule_id: zdU0Wo version_id: JdTzx88 url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled origin: community - id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address patterns: - pattern-either: - pattern: | resource "aws_subnet" $ANYTHING { ... map_public_ip_on_launch = true ... } - pattern: | resource "aws_default_subnet" $ANYTHING { ... } - pattern-not: | resource "aws_default_subnet" $ANYTHING { ... map_public_ip_on_launch = false ... } message: Resources in the AWS subnet are assigned a public IP address. Resources should not be exposed on the public internet, but should have access limited to consumers required for the function of your application. Set `map_public_ip_on_launch` to false so that resources are not publicly-accessible. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address shortlink: https://sg.run/XJZw semgrep.dev: rule: r_id: 50764 rv_id: 1263744 rule_id: 2ZUo79 version_id: d6Tyxdb url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address origin: community - id: clojure.lang.security.use-of-md5.use-of-md5 languages: - clojure severity: WARNING message: MD5 hash algorithm detected. This is not collision resistant and leads to easily-cracked password hashes. Replace with current recommended hashing algorithms. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html technology: - clojure source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' author: Gabriel Marquet category: security subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 shortlink: https://sg.run/BgPx semgrep.dev: rule: r_id: 52195 rv_id: 1262609 rule_id: nJU1ep version_id: 0bTKz2B url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 origin: community pattern-either: - pattern: (MessageDigest/getInstance "MD5") - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) - pattern: (java.security.MessageDigest/getInstance "MD5") - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) - id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak patterns: - pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$ message: Detects potential Google Maps API keys in code languages: - generic severity: WARNING metadata: description: Detects potential Google Maps API keys in code severity: MEDIUM category: security confidence: MEDIUM impact: HIGH likelihood: MEDIUM subcategory: - audit owasp: - A3:2017 Sensitive Data Exposure references: - https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e cwe: - 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory' technology: - Google Maps license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak shortlink: https://sg.run/DL5d semgrep.dev: rule: r_id: 52196 rv_id: 945530 rule_id: EwU3kN version_id: NdTqkGz url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak origin: community - id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted patterns: - pattern: | resource "aws_kinesis_stream" $ANYTHING { ... } - pattern-not: | resource "aws_kinesis_stream" $ANYTHING { ... encryption_type = "KMS" ... } message: The AWS Kinesis stream does not encrypt data at rest. The data could be read if the Kinesis stream storage layer is compromised. Enable Kinesis stream server-side encryption. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type - https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted shortlink: https://sg.run/KZ0L semgrep.dev: rule: r_id: 52199 rv_id: 1263728 rule_id: 8GU72N version_id: pZT037O url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted origin: community - id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal patterns: - pattern-either: - pattern-inside: | resource "aws_sqs_queue_policy" $ANYTHING { ... } - pattern-inside: | resource "aws_sqs_queue" $ANYTHING { ... } - pattern-either: - patterns: - pattern: policy = "$JSONPOLICY" - metavariable-pattern: metavariable: $JSONPOLICY language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], ...} - pattern: | {..., "Principal": { "AWS": "*" }, ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, ...} - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n \ \"aws:PrincipalARN\": ...\n }\n},\n...}\n" - patterns: - pattern-inside: policy = jsonencode(...) - pattern-not-inside: | {..., Effect = "Deny", ...} - pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\" = ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\" = ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\" = ...\n }\n}\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\" = ...\n }\n},\n...}\n" - pattern-either: - pattern: | {..., Principal = "*", ...} - pattern: | {..., Principal = [..., "*", ...], ...} - pattern: | {..., Principal = { AWS = "*" }, ...} - pattern: | {..., Principal = { AWS = [..., "*", ...] }, ...} message: Wildcard used in your SQS queue policy principal. This grants access to all users, including anonymous users (public access). Unless you explicitly require anyone on the internet to be able to read or write to your queue, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml in None license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal shortlink: https://sg.run/z3eW semgrep.dev: rule: r_id: 53517 rv_id: 1263741 rule_id: PeUl9d version_id: O9TpxgE url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn patterns: - pattern: | resource "aws_lambda_permission" $ANYTHING { ... principal = "$PRINCIPAL" ... } - pattern-not: | resource "aws_lambda_permission" $ANYTHING { ... source_arn = ... ... } - metavariable-regex: metavariable: $PRINCIPAL regex: .*[.]amazonaws[.]com$ message: The AWS Lambda permission has an AWS service principal but does not specify a source ARN. If you grant permission to a service principal without specifying the source, other accounts could potentially configure resources in their account to invoke your Lambda function. Set the source_arn value to the ARN of the AWS resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule, API Gateway, or SNS topic. languages: - hcl severity: ERROR metadata: category: security technology: - terraform - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn shortlink: https://sg.run/kOP7 semgrep.dev: rule: r_id: 54772 rv_id: 1263732 rule_id: OrU9Ox version_id: 1QTypq5 url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn origin: community - id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active patterns: - pattern: | resource "aws_lambda_function" $ANYTHING { ... } - pattern-not: | resource "aws_lambda_function" $ANYTHING { ... tracing_config { ... mode = "Active" ... } ... } message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray tracing enables end-to-end debugging and analysis of all function activity. This makes it easier to trace the flow of logs and identify bottlenecks, slow downs and timeouts. languages: - hcl severity: INFO metadata: category: security technology: - aws - terraform owasp: - A09:2021 Security Logging and Monitoring Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://cwe.mitre.org/data/definitions/778.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode - https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active shortlink: https://sg.run/wO2Y semgrep.dev: rule: r_id: 54773 rv_id: 946713 rule_id: eqUl1O version_id: QkTZ6vk url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active origin: community - id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization patterns: - pattern-either: - patterns: - pattern-inside: | ObjectMapper $OM = new ObjectMapper(...); ... - pattern-inside: | $OM.enableDefaultTyping(); ... - pattern: $OM.readValue($JSON, ...); - patterns: - pattern-inside: | class $CLASS { ... @JsonTypeInfo(use = Id.CLASS,...) $TYPE $VAR; ... } - metavariable-regex: metavariable: $TYPE regex: (Object|Serializable|Comparable) - pattern: $OM.readValue($JSON, $CLASS.class); - patterns: - pattern-inside: | class $CLASS { ... ObjectMapper $OM; ... $INITMETHODTYPE $INITMETHOD(...) { ... $OM = new ObjectMapper(); ... $OM.enableDefaultTyping(); ... } ... } - pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n" - pattern: $OM.readValue($JSON, ...); message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling default typing is dangerous and can lead to RCE. If an attacker can control `$JSON` it might be possible to provide a malicious JSON which can be used to exploit unsecure deserialization. In order to prevent this issue, avoid to enable default typing (globally or by using "Per-class" annotations) and avoid using `Object` and other dangerous types for member variable declaration which creating classes for Jackson based deserialization. languages: - java severity: WARNING metadata: category: security subcategory: - audit cwe: - 'CWE-502: Deserialization of Untrusted Data' confidence: MEDIUM likelihood: LOW impact: HIGH owasp: - A8:2017 Insecure Deserialization - A8:2021 Software and Data Integrity Failures references: - https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038 - https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 - https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/ technology: - jackson license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization shortlink: https://sg.run/GDop semgrep.dev: rule: r_id: 56948 rv_id: 945724 rule_id: QrUD20 version_id: 2KTYbA9 url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization origin: community - id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing shortlink: https://sg.run/Gj32 semgrep.dev: rule: r_id: 59048 rv_id: 1263061 rule_id: j2Udpk version_id: YDTZeko url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing origin: community message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - The previous links are not meant to be clicked. They are the literal config key values that are supposed to be used to disable these features. For more information, see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = SAXParserFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newSAXParser(); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); $FACTORY.newSAXParser(); languages: - java - id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled shortlink: https://sg.run/1wyQ semgrep.dev: rule: r_id: 59622 rv_id: 1263062 rule_id: v8UeQ1 version_id: 6xT29GK url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled origin: community message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" and "accessExternalStylesheet" to "". mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = TransformerFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newTransformer(...); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); - pattern: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); - pattern: | $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); - pattern: | $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); $FACTORY.newTransformer(...); languages: - java - id: javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash patterns: - pattern-either: - pattern: | window.intercomSettings = {..., email: $EMAIL, ...}; - pattern: | window.intercomSettings = {..., user_id: $USER_ID, ...}; - pattern: | Intercom('boot', {..., email: $EMAIL, ...}); - pattern: | Intercom('boot', {..., user_id: $USER_ID, ...}); - pattern: | $VAR = {..., email: $EMAIL, ...}; ... Intercom('boot', $VAR); - pattern: | $VAR = {..., user_id: $EMAIL, ...}; ... Intercom('boot', $VAR); - pattern-not: | window.intercomSettings = {..., user_hash: $USER_HASH, ...}; - pattern-not: | Intercom('boot', {..., user_hash: $USER_HASH, ...}); - pattern-not: | $VAR = {..., user_hash: $USER_HASH, ...}; ... Intercom('boot', $VAR); message: Found an initialization of the Intercom Messenger that identifies a User, but does not specify a `user_hash`. This configuration allows users to impersonate one another. See the Intercom Identity Verification docs for more context https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile languages: - js severity: WARNING metadata: category: security subcategory: - audit cwe: - 'CWE-287: Improper Authentication' confidence: MEDIUM likelihood: MEDIUM impact: HIGH technology: - intercom references: - https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash shortlink: https://sg.run/Eb5w semgrep.dev: rule: r_id: 60237 rv_id: 945842 rule_id: QrU96W version_id: nWTpzDk url: https://semgrep.dev/playground/r/nWTpzDk/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash origin: community - id: java.android.security.exported_activity.exported_activity patterns: - pattern-not-inside: - pattern-inside: " \n" - pattern-either: - pattern: | - pattern: | ... /> message: The application exports an activity. Any application on the device can launch the exported activity which may compromise the integrity of your application or its data. Ensure that any exported activities do not have privileged access to your application's control plane. languages: - generic severity: WARNING paths: exclude: - sources/ - classes3.dex - '*.so' include: - '*AndroidManifest.xml' metadata: category: security subcategory: - vuln cwe: - 'CWE-926: Improper Export of Android Application Components' confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM owasp: - A5:2021 Security Misconfiguration technology: - Android references: - https://cwe.mitre.org/data/definitions/926.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity shortlink: https://sg.run/eNGZ semgrep.dev: rule: r_id: 60632 rv_id: 945629 rule_id: v8Ul0r version_id: rxT6rGR url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity origin: community - id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile patterns: - pattern: | RUN sudo ... message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can help reduce the potential impact of configuration errors and security vulnerabilities. metadata: category: security technology: - dockerfile cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://cwe.mitre.org/data/definitions/250.html - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile shortlink: https://sg.run/80Q7 semgrep.dev: rule: r_id: 66384 rv_id: 1262661 rule_id: kxUlx1 version_id: pZT03zY url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile origin: community languages: - dockerfile severity: WARNING - id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults message: Potentially sensitive data was observed to be stored in UserDefaults, which is not adequate protection of sensitive information. For data of a sensitive nature, applications should leverage the Keychain. severity: WARNING metadata: likelihood: LOW impact: HIGH confidence: MEDIUM category: security cwe: - 'CWE-311: Missing Encryption of Sensitive Data' masvs: - 'MASVS-STORAGE-1: The app securely stores sensitive data' owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html - https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/ subcategory: - vuln technology: - ios - macos license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults shortlink: https://sg.run/qvoO semgrep.dev: rule: r_id: 66512 rv_id: 1263696 rule_id: KxUqoZ version_id: 3ZT4Xy2 url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults origin: community languages: - swift options: symbolic_propagation: true patterns: - pattern-either: - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(api_key|apikey)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(api_key|apikey)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ - focus-metavariable: $KEY - id: swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows message: Webviews were observed that explictly allow JavaScript in an WKWebview to open windows automatically. Consider disabling this functionality if not required, following the principle of least privelege. severity: WARNING metadata: likelihood: LOW impact: LOW confidence: HIGH category: security cwe: - 'CWE-272: Least Privilege Violation' masvs: - 'MASVS-PLATFORM-2: The app uses WebViews securely' references: - https://mas.owasp.org/MASVS/controls/MASVS-PLATFORM-2/ - https://developer.apple.com/documentation/webkit/wkpreferences/1536573-javascriptcanopenwindowsautomati subcategory: - audit technology: - ios - macos license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows shortlink: https://sg.run/YWLd semgrep.dev: rule: r_id: 66514 rv_id: 946637 rule_id: lBUOZk version_id: 9lTy1KE url: https://semgrep.dev/playground/r/9lTy1KE/swift.webview.webview-js-window.swift-webview-config-allows-js-open-windows origin: community languages: - swift patterns: - pattern: | $P = WKPreferences() ... - pattern-either: - patterns: - pattern-inside: | $P.JavaScriptCanOpenWindowsAutomatically = $FALSE ... $P.JavaScriptCanOpenWindowsAutomatically = $TRUE - pattern-not-inside: | ... $P.JavaScriptCanOpenWindowsAutomatically = $TRUE ... $P.JavaScriptCanOpenWindowsAutomatically = $FALSE - pattern: | $P.JavaScriptCanOpenWindowsAutomatically = true - metavariable-regex: metavariable: $TRUE regex: ^(true)$ - metavariable-regex: metavariable: $TRUE regex: (.*(?!true)) - patterns: - pattern: | $P.JavaScriptCanOpenWindowsAutomatically = true - pattern-not-inside: | ... $P.JavaScriptCanOpenWindowsAutomatically = ... ... $P.JavaScriptCanOpenWindowsAutomatically = ... - id: solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens message: $VAULT.getPoolTokens() call on a Balancer pool is not protected from the read-only reentrancy. metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://quillaudits.medium.com/decoding-sentiment-protocols-1-million-exploit-quillaudits-f36bee77d376 - https://hackmd.io/@sentimentxyz/SJCySo1z2 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens shortlink: https://sg.run/803Q semgrep.dev: rule: r_id: 67640 rv_id: 946602 rule_id: kxUl7x version_id: e1T98xQ url: https://semgrep.dev/playground/r/e1T98xQ/solidity.security.balancer-readonly-reentrancy-getpooltokens.balancer-readonly-reentrancy-getpooltokens origin: community patterns: - pattern-either: - pattern: | function $F(...) { ... $RETURN = $VAULT.getPoolTokens(...); ... } - metavariable-pattern: metavariable: $RETURN pattern-regex: .*uint256\[].* - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } ... function $F(...) { ... $CHECKFUNC(...); ... $RETURN = $VAULT.getPoolTokens(...); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } ... function $F(...) { ... $RETURN = $VAULT.getPoolTokens(...); ... $CHECKFUNC(...); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAULT.manageUserBalance(...); ... } ... function $F(...) { ... $RETURN = $VAULT.getPoolTokens(...); ... $CHECKFUNC(...); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAULT.manageUserBalance(...); ... } ... function $F(...) { ... $CHECKFUNC(...); ... $RETURN = $VAULT.getPoolTokens(...); ... } ... } - pattern-not: | function $F(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } - pattern-not: | function $F(...) { ... $VAULT.manageUserBalance(...); ... } - pattern-not-inside: | contract LinearPool { ... } - pattern-not-inside: | contract ComposableStablePool { ... } - pattern-not-inside: "contract BalancerQueries {\n ...\n} \n" - pattern-not-inside: | contract ManagedPool { ... } - pattern-not-inside: "contract BaseWeightedPool {\n ...\n} \n" - pattern-not-inside: | contract ComposableStablePoolStorage { ... } - pattern-not-inside: | contract RecoveryModeHelper { ... } - focus-metavariable: - $VAULT languages: - solidity severity: ERROR - id: solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate message: $VAR.getRate() call on a Balancer pool is not protected from the read-only reentrancy. metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://forum.balancer.fi/t/reentrancy-vulnerability-scope-expanded/4345 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate shortlink: https://sg.run/g9e5 semgrep.dev: rule: r_id: 67641 rv_id: 946603 rule_id: wdUx3D version_id: vdTGn2l url: https://semgrep.dev/playground/r/vdTGn2l/solidity.security.balancer-readonly-reentrancy-getrate.balancer-readonly-reentrancy-getrate origin: community patterns: - pattern: | function $F(...) { ... $VAR.getRate(); ... } - pattern-not-inside: | function $F(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } - pattern-not-inside: | function $F(...) { ... $VAULT.manageUserBalance(...); ... } - pattern-not-inside: | function _updateTokenRateCache(...) { ... } - pattern-not-inside: | contract PoolRecoveryHelper { ... } - pattern-not-inside: | contract ComposableStablePoolRates { ... } - pattern-not-inside: | contract WeightedPoolProtocolFees { ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } ... function $F(...) { ... $CHECKFUNC(...); ... $VAR.getRate(); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... VaultReentrancyLib.ensureNotInVaultContext(...); ... } ... function $F(...) { ... $VAR.getRate(); ... $CHECKFUNC(...); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAULT.manageUserBalance(...); ... } ... function $F(...) { ... $VAR.getRate(); ... $CHECKFUNC(...); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAULT.manageUserBalance(...); ... } ... function $F(...) { ... $CHECKFUNC(...); ... $VAR.getRate(); ... } ... } - focus-metavariable: $VAR languages: - solidity severity: ERROR - id: solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy message: Function borrowFresh() in Compound performs state update after doTransferOut() metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: LOW impact: HIGH subcategory: - vuln references: - https://twitter.com/peckshield/status/1509431646818234369 - https://twitter.com/blocksecteam/status/1509466576848064512 - https://slowmist.medium.com/another-day-another-reentrancy-attack-5cde10bbb2b4 - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy shortlink: https://sg.run/4A19 semgrep.dev: rule: r_id: 67644 rv_id: 946606 rule_id: eqUkx4 version_id: nWTpz74 url: https://semgrep.dev/playground/r/nWTpz74/solidity.security.compound-borrowfresh-reentrancy.compound-borrowfresh-reentrancy origin: community patterns: - pattern-inside: | function borrowFresh(...) { ... } - pattern-not-inside: | accountBorrows[borrower].interestIndex = borrowIndex; ... - pattern: doTransferOut(...); languages: - solidity severity: WARNING - id: solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted message: Function sweepToken is allowed to be called by anyone metadata: category: security technology: - solidity cwe: 'CWE-284: Improper Access Control' confidence: MEDIUM likelihood: LOW impact: HIGH subcategory: - vuln references: - https://medium.com/chainsecurity/trueusd-compound-vulnerability-bc5b696d29e2 - https://chainsecurity.com/security-audit/compound-ctoken/ - https://blog.openzeppelin.com/compound-comprehensive-protocol-audit/ - https://etherscan.io/address/0xa035b9e130f2b1aedc733eefb1c67ba4c503491f license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted shortlink: https://sg.run/P4Wv semgrep.dev: rule: r_id: 67645 rv_id: 946607 rule_id: v8Uz2o version_id: ExTg2nW url: https://semgrep.dev/playground/r/ExTg2nW/solidity.security.compound-sweeptoken-not-restricted.compound-sweeptoken-not-restricted origin: community patterns: - pattern-inside: | function sweepToken(...) { ... } - pattern-not-inside: | function sweepToken(...) $M { ... } - pattern: token.transfer(...); - pattern-not-inside: | require(msg.sender == admin, "..."); ... - pattern-not-inside: | require(_msgSender() == admin, "..."); ... languages: - solidity severity: WARNING - id: solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy message: $POOL.get_virtual_price() call on a Curve pool is not protected from the read-only reentrancy. metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://chainsecurity.com/heartbreaks-curve-lp-oracles/ - https://chainsecurity.com/curve-lp-oracle-manipulation-post-mortem/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy shortlink: https://sg.run/Jk5P semgrep.dev: rule: r_id: 67646 rv_id: 946608 rule_id: d8UGDL version_id: 7ZTrQO3 url: https://semgrep.dev/playground/r/7ZTrQO3/solidity.security.curve-readonly-reentrancy.curve-readonly-reentrancy origin: community patterns: - pattern: | $POOL.get_virtual_price() - pattern-not-inside: | function $F(...) { ... $VAR.withdraw_admin_fees(...); ... } - pattern-not-inside: | function $F(...) { ... $VAR.withdraw_admin_fees(...); ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAR.withdraw_admin_fees(...); ... } ... function $F(...) { ... $CHECKFUNC(...); ... $POOL.get_virtual_price(); ... } ... } - pattern-not-inside: | contract $C { ... function $CHECKFUNC(...) { ... $VAR.withdraw_admin_fees(...); ... } ... function $F(...) { ... $POOL.get_virtual_price(); ... $CHECKFUNC(...); ... } ... } languages: - solidity severity: ERROR - id: solidity.security.encode-packed-collision.encode-packed-collision message: abi.encodePacked hash collision with variable length arguments in $F() metadata: category: security technology: - solidity cwe: 'CWE-20: Improper Input Validation' confidence: HIGH likelihood: MEDIUM impact: MEDIUM subcategory: - vuln references: - https://swcregistry.io/docs/SWC-133 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/solidity.security.encode-packed-collision.encode-packed-collision shortlink: https://sg.run/Gr46 semgrep.dev: rule: r_id: 67648 rv_id: 946610 rule_id: nJU47w version_id: 8KTKjb1 url: https://semgrep.dev/playground/r/8KTKjb1/solidity.security.encode-packed-collision.encode-packed-collision origin: community patterns: - pattern-either: - pattern-inside: | function $F(..., bytes $A, ..., bytes $B, ...) public { ... } - pattern-inside: | function $F(..., string $A, ..., string $B, ...) public { ... } - pattern-inside: | function $F(..., bytes $A, ..., string $B, ...) public { ... } - pattern-inside: | function $F(..., string $A, ..., bytes $B, ...) public { ... } - pattern-inside: | function $F(..., address[] $A, ..., address[] $B, ...) public { ... } - pattern-inside: | function $F(..., uint256[] $A, ..., uint256[] $B, ...) public { ... } - pattern-inside: | function $F(..., bytes $A, ..., bytes $B, ...) external { ... } - pattern-inside: | function $F(..., string $A, ..., string $B, ...) external { ... } - pattern-inside: | function $F(..., bytes $A, ..., string $B, ...) external { ... } - pattern-inside: | function $F(..., string $A, ..., bytes $B, ...) external { ... } - pattern-inside: | function $F(..., address[] $A, ..., address[] $B, ...) external { ... } - pattern-inside: | function $F(..., uint256[] $A, ..., uint256[] $B, ...) external { ... } - pattern-either: - pattern: | keccak256(abi.encodePacked(..., $A, $B, ...)) - pattern: | $X = abi.encodePacked(..., $A, $B, ...); ... keccak256($X); languages: - solidity severity: ERROR - id: solidity.security.erc677-reentrancy.erc677-reentrancy message: ERC677 callAfterTransfer() reentrancy metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://twitter.com/peckshield/status/1509431646818234369 - https://twitter.com/blocksecteam/status/1509466576848064512 - https://explorer.fuse.io/address/0x139Eb08579eec664d461f0B754c1F8B569044611 - https://explorer.fuse.io/address/0x5De15b5543c178C111915d6B8ae929Af01a8cC58 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.erc677-reentrancy.erc677-reentrancy shortlink: https://sg.run/BXnR semgrep.dev: rule: r_id: 67651 rv_id: 946613 rule_id: L1Ub0L version_id: 3ZTOPdd url: https://semgrep.dev/playground/r/3ZTOPdd/solidity.security.erc677-reentrancy.erc677-reentrancy origin: community patterns: - pattern-inside: | function transfer(...) { ... } - pattern: callAfterTransfer(...); languages: - solidity severity: WARNING - id: solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom message: Custom ERC721 implementation lacks access control checks in _transfer() metadata: category: security technology: - solidity cwe: 'CWE-284: Improper Access Control' confidence: MEDIUM likelihood: HIGH impact: HIGH subcategory: - vuln references: - https://twitter.com/BlockSecAlert/status/1516289618605654024 - https://etherscan.io/address/0xf3821adaceb6500c0a202971aecf840a033f236b license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom shortlink: https://sg.run/D17G semgrep.dev: rule: r_id: 67652 rv_id: 946614 rule_id: 8GUkbo version_id: 44TZko3 url: https://semgrep.dev/playground/r/44TZko3/solidity.security.erc721-arbitrary-transferfrom.erc721-arbitrary-transferfrom origin: community patterns: - pattern-inside: | function _transfer(...) { ... } - pattern-inside: | require(prevOwnership.addr == $FROM, ...); ... - pattern-not-inside: | (<... _msgSender() == $FROM ...>); ... - pattern-not-inside: | (<... _msgSender() == $PREV.$ADDR ...>); ... - pattern-not-inside: | (<... msg.sender == $FROM ...>); ... - pattern-not-inside: | require(_isApprovedOrOwner(...), ...); ... - pattern: _approve(...); languages: - solidity severity: WARNING - id: solidity.security.erc721-reentrancy.erc721-reentrancy message: ERC721 onERC721Received() reentrancy metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: LOW impact: HIGH subcategory: - vuln references: - https://blocksecteam.medium.com/when-safemint-becomes-unsafe-lessons-from-the-hypebears-security-incident-2965209bda2a - https://etherscan.io/address/0x14e0a1f310e2b7e321c91f58847e98b8c802f6ef license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.erc721-reentrancy.erc721-reentrancy shortlink: https://sg.run/WBoE semgrep.dev: rule: r_id: 67653 rv_id: 946615 rule_id: gxU2qG version_id: PkTQZYA url: https://semgrep.dev/playground/r/PkTQZYA/solidity.security.erc721-reentrancy.erc721-reentrancy origin: community patterns: - pattern: _checkOnERC721Received(...) languages: - solidity severity: WARNING - id: solidity.security.erc777-reentrancy.erc777-reentrancy message: ERC777 tokensReceived() reentrancy metadata: category: security technology: - solidity cwe: 'CWE-841: Improper Enforcement of Behavioral Workflow' confidence: HIGH likelihood: LOW impact: HIGH subcategory: - vuln references: - https://mirror.xyz/baconcoin.eth/LHaPiX38mnx8eJ2RVKNXHttHfweQMKNGmEnX4KUksk0 - https://etherscan.io/address/0xf53f00f844b381963a47fde3325011566870b31f license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.erc777-reentrancy.erc777-reentrancy shortlink: https://sg.run/0Jpw semgrep.dev: rule: r_id: 67654 rv_id: 946616 rule_id: QrUrJj version_id: JdTDyg1 url: https://semgrep.dev/playground/r/JdTDyg1/solidity.security.erc777-reentrancy.erc777-reentrancy origin: community patterns: - pattern: $X.tokensReceived(...); languages: - solidity severity: WARNING - id: solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash message: blockhash(block.number) and blockhash(block.number + N) always returns 0. metadata: category: security technology: - solidity cwe: 'CWE-341: Predictable from Observable State' confidence: HIGH likelihood: LOW impact: MEDIUM subcategory: - vuln references: - https://blog.positive.com/predicting-random-numbers-in-ethereum-smart-contracts-e5358c6b8620 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash shortlink: https://sg.run/qvPO semgrep.dev: rule: r_id: 67656 rv_id: 946618 rule_id: 4bUPoB version_id: GxTP7wj url: https://semgrep.dev/playground/r/GxTP7wj/solidity.security.incorrect-use-of-blockhash.incorrect-use-of-blockhash origin: community patterns: - pattern-either: - pattern: blockhash(block.number) - pattern: blockhash(block.number + $N) - pattern: blockhash(block.number * $N) - pattern: block.blockhash(block.number) - pattern: block.blockhash(block.number + $N) - pattern: block.blockhash(block.number * $N) severity: ERROR languages: - solidity - id: solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation message: Keep3rV2.current() call has high data freshness, but it has low security, an exploiter simply needs to manipulate 2 data points to be able to impact the feed. metadata: category: security technology: - solidity cwe: 'CWE-682: Incorrect Calculation' confidence: HIGH likelihood: LOW impact: HIGH subcategory: - vuln references: - https://twitter.com/peckshield/status/1510232640338608131 - https://twitter.com/FrankResearcher/status/1510239094777032713 - https://twitter.com/larry0x/status/1510263618180464644 - https://andrecronje.medium.com/keep3r-network-on-chain-oracle-price-feeds-3c67ed002a9 - https://etherscan.io/address/0x210ac53b27f16e20a9aa7d16260f84693390258f license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation shortlink: https://sg.run/lkEo semgrep.dev: rule: r_id: 67657 rv_id: 946619 rule_id: PeUrYv version_id: RGTAgvQ url: https://semgrep.dev/playground/r/RGTAgvQ/solidity.security.keeper-network-oracle-manipulation.keeper-network-oracle-manipulation origin: community patterns: - pattern: $KEEPER.current($TOKENIN, $AMOUNTIN, $TOKENOUT); languages: - solidity severity: WARNING - id: solidity.security.no-bidi-characters.no-bidi-characters message: The code must not contain any of Unicode Direction Control Characters metadata: category: security technology: - solidity cwe: 'CWE-837: Improper Enforcement of a Single, Unique Action' confidence: HIGH likelihood: LOW impact: LOW subcategory: - audit references: - https://entethalliance.org/specs/ethtrust-sl/v1/#req-1-unicode-bdo license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.no-bidi-characters.no-bidi-characters shortlink: https://sg.run/6DyK semgrep.dev: rule: r_id: 67659 rv_id: 946622 rule_id: 5rUD6Z version_id: DkTNp8K url: https://semgrep.dev/playground/r/DkTNp8K/solidity.security.no-bidi-characters.no-bidi-characters origin: community patterns: - pattern-either: - pattern-regex: "\u202A" - pattern-regex: "\u202B" - pattern-regex: "\u202D" - pattern-regex: "\u202E" - pattern-regex: "\u2066" - pattern-regex: "\u2067" - pattern-regex: "\u2068" - pattern-regex: "\u202C" - pattern-regex: "\u2069" languages: - solidity severity: WARNING - id: solidity.security.no-slippage-check.no-slippage-check message: No slippage check in a Uniswap v2/v3 trade metadata: category: security technology: - solidity cwe: 'CWE-682: Incorrect Calculation' confidence: MEDIUM likelihood: HIGH impact: MEDIUM subcategory: - vuln references: - https://uniswapv3book.com/docs/milestone_3/slippage-protection/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.no-slippage-check.no-slippage-check shortlink: https://sg.run/oO8X semgrep.dev: rule: r_id: 67660 rv_id: 946623 rule_id: GdUE2p version_id: WrTEoxy url: https://semgrep.dev/playground/r/WrTEoxy/solidity.security.no-slippage-check.no-slippage-check origin: community patterns: - pattern-either: - pattern: $X.swapExactTokensForTokens($A, $LIMIT, $B, $C, $D) - pattern: $X.swapExactTokensForTokensSupportingFeeOnTransferTokens($A, $LIMIT, $B, $C, $D) - pattern: $X.swapExactTokensForETH($A, $LIMIT, $B, $C, $D) - pattern: $X.swapExactTokensForETHSupportingFeeOnTransferTokens($A, $LIMIT, $B, $C, $D) - pattern: $X.swapExactETHForTokens{$VALUE:...}($LIMIT, $A, $B, $C) - pattern: $X.swapExactETHForTokensSupportingFeeOnTransferTokens{$VALUE:...}($LIMIT, $A, $B, $C) - pattern: $X.swapTokensForExactTokens($A, $LIMIT, $B, $C, $D) - pattern: $X.swapTokensForExactETH($A, $LIMIT, $B, $C, $D) - pattern: "function $FUNC(...) {\n ...\n $Y = $SWAPROUTER.ExactInputSingleParams({\n \ tokenIn: $A, \n tokenOut: $B, \n fee: $C, \n recipient: $D, \n \ deadline: $E, \n amountIn: $F, \n amountOutMinimum: $LIMIT, \n sqrtPriceLimitX96: 0\n });\n ...\n $X.exactInputSingle($Y);\n ...\n}\n" - pattern: | $X.exactInputSingle($SWAPROUTER.ExactInputSingleParams({ tokenIn: $A, tokenOut: $B, fee: $C, recipient: $D, deadline: $E, amountIn: $F, amountOutMinimum: $LIMIT, sqrtPriceLimitX96: 0 })); - pattern: | function $FUNC(...) { ... $Y = $SWAPROUTER.ExactOutputSingleParams({ tokenIn: $A, tokenOut: $B, fee: $C, recipient: $D, deadline: $E, amountOut: $F, amountInMaximum: $LIMIT, sqrtPriceLimitX96: 0 }); ... $X.exactOutputSingle($Y); ... } - pattern: | $X.exactOutputSingle($SWAPROUTER.ExactOutputSingleParams({ tokenIn: $A, tokenOut: $B, fee: $C, recipient: $D, deadline: $E, amountOut: $F, amountInMaximum: $LIMIT, sqrtPriceLimitX96: 0 })); - pattern: $X.swap($RECIPIENT, $ZEROFORONE, $AMOUNTIN, $LIMIT, $DATA) - metavariable-regex: metavariable: $LIMIT regex: ^(0)|(0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff)|(type\(uint(256)?\)\.max)|(uint(256)?\(-1)|(115792089237316195423570985008687907853269984665640564039457584007913129639935)|(2\s?\*\*\s?256\s?-\s?1)$ languages: - solidity severity: ERROR - id: solidity.security.proxy-storage-collision.proxy-storage-collision message: Proxy declares a state var that may override a storage slot of the implementation metadata: category: security technology: - solidity cwe: 'CWE-787: Out-of-bounds Write' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://blog.audius.co/article/audius-governance-takeover-post-mortem-7-23-22 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.proxy-storage-collision.proxy-storage-collision shortlink: https://sg.run/2GXr semgrep.dev: rule: r_id: 67663 rv_id: 946626 rule_id: BYU0EL version_id: qkT4jqp url: https://semgrep.dev/playground/r/qkT4jqp/solidity.security.proxy-storage-collision.proxy-storage-collision origin: community patterns: - pattern-either: - pattern: | contract $CONTRACT is ..., $PROXY, ... { ... $TYPE $VAR; ... constructor(...) { ... } ... } - pattern: | contract $CONTRACT is ..., $PROXY, ... { ... $TYPE $VAR = ...; ... constructor(...) { ... } ... } - pattern-not: | contract $CONTRACT is ..., $PROXY, ... { $TYPE immutable $VAR; ... constructor(...) { ... } ... } - pattern-not: | contract $CONTRACT is ..., $PROXY, ... { $TYPE immutable $VAR = ...; ... constructor(...) { ... } ... } - pattern-not: | contract $CONTRACT is ..., $PROXY, ... { $TYPE constant $VAR = ...; ... constructor(...) { ... } ... } - metavariable-regex: metavariable: $CONTRACT regex: ^(?!AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy).*$ - metavariable-regex: metavariable: $PROXY regex: (UpgradeabilityProxy|AdminUpgradeabilityProxy|OwnedUpgrade*abilityProxy|TransparentUpgradeableProxy|ERC1967Proxy) - focus-metavariable: $PROXY languages: - solidity severity: WARNING - id: solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug message: transferFrom() can steal allowance of other accounts metadata: category: security technology: - solidity cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' confidence: HIGH likelihood: HIGH impact: HIGH subcategory: - vuln references: - https://medium.com/immunefi/redacted-cartel-custom-approval-logic-bugfix-review-9b2d039ca2c5 - https://etherscan.io/address/0x186E55C0BebD2f69348d94C4A27556d93C5Bd36C license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug shortlink: https://sg.run/XDzj semgrep.dev: rule: r_id: 67664 rv_id: 946627 rule_id: DbU0Qb version_id: l4Tx9Px url: https://semgrep.dev/playground/r/l4Tx9Px/solidity.security.redacted-cartel-custom-approval-bug.redacted-cartel-custom-approval-bug origin: community patterns: - pattern-inside: | function transferFrom(...) { ... } - pattern: _approve(..., allowance(sender, recipient).sub(amount, ...), ...); languages: - solidity severity: ERROR - id: solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control message: setMultipleAllowances() is missing onlyOwner modifier metadata: category: security technology: - solidity cwe: 'CWE-284: Improper Access Control' confidence: HIGH likelihood: HIGH impact: HIGH subcategory: - vuln references: - https://twitter.com/danielvf/status/1494317265835147272 - https://etherscan.io/address/0x876b9ebd725d1fa0b879fcee12560a6453b51dc8 - https://play.secdim.com/game/dapp/challenge/rigoownsol license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control shortlink: https://sg.run/jbZP semgrep.dev: rule: r_id: 67665 rv_id: 946628 rule_id: WAUpbw version_id: YDTvRP2 url: https://semgrep.dev/playground/r/YDTvRP2/solidity.security.rigoblock-missing-access-control.rigoblock-missing-access-control origin: community patterns: - pattern: function setMultipleAllowances(...) {...} - pattern-not: function setMultipleAllowances(...) onlyOwner {...} languages: - solidity severity: ERROR - id: solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control message: Oracle update is not restricted in $F() metadata: category: security technology: - solidity cwe: 'CWE-284: Improper Access Control' confidence: MEDIUM likelihood: HIGH impact: HIGH subcategory: - vuln author: https://twitter.com/ArbazKiraak references: - https://medium.com/immunefi/sense-finance-access-control-issue-bugfix-review-32e0c806b1a0 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control shortlink: https://sg.run/1521 semgrep.dev: rule: r_id: 67666 rv_id: 946629 rule_id: 0oUbvd version_id: 6xTxjKQ url: https://semgrep.dev/playground/r/6xTxjKQ/solidity.security.sense-missing-oracle-access-control.sense-missing-oracle-access-control origin: community patterns: - pattern-either: - pattern-inside: | function $F(...,$D $REQUEST,...) external { ... } - pattern-inside: | function $F(...,$D $REQUEST,...) public { ... } - pattern-not-inside: | function $F(...,$D $REQUEST,...) external onlyVault(...) { ... } - patterns: - pattern: _updateOracle($LASTBLOCK,...,...) - pattern-not-inside: | ... if (msg.sender == $BALANCER) { ... } ... - pattern-not-inside: | ... require(msg.sender == address($BALANCER),...); ... - pattern-not-inside: | ... if (_msgSender() == $BALANCER) { ... } ... - pattern-not-inside: | ... require(_msgSender() == address($BALANCER),...); ... languages: - solidity severity: ERROR - id: solidity.security.superfluid-ctx-injection.superfluid-ctx-injection message: A specially crafted calldata may be used to impersonate other accounts metadata: category: security technology: - solidity cwe: 'CWE-20: Improper Input Validation' confidence: HIGH likelihood: HIGH impact: HIGH subcategory: - vuln references: - https://rekt.news/superfluid-rekt/ - https://medium.com/superfluid-blog/08-02-22-exploit-post-mortem-15ff9c97cdd - https://polygonscan.com/address/0x07711bb6dfbc99a1df1f2d7f57545a67519941e7 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection shortlink: https://sg.run/9KNy semgrep.dev: rule: r_id: 67667 rv_id: 946630 rule_id: KxUqld version_id: o5TZexb url: https://semgrep.dev/playground/r/o5TZexb/solidity.security.superfluid-ctx-injection.superfluid-ctx-injection origin: community patterns: - pattern: $T.decodeCtx(ctx); - pattern-not-inside: | require($T.isCtxValid(...), "..."); ... languages: - solidity severity: ERROR - id: solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug message: Parameter "from" is checked at incorrect position in "_allowances" mapping metadata: category: security technology: - solidity cwe: 'CWE-688: Function Call With Incorrect Variable or Reference as Argument' confidence: MEDIUM likelihood: HIGH impact: HIGH subcategory: - vuln references: - https://twitter.com/Mauricio_0218/status/1490082073096462340 - https://etherscan.io/address/0xe38b72d6595fd3885d1d2f770aa23e94757f91a1 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug shortlink: https://sg.run/yBWA semgrep.dev: rule: r_id: 67668 rv_id: 946631 rule_id: qNUnN0 version_id: zyTlkRL url: https://semgrep.dev/playground/r/zyTlkRL/solidity.security.tecra-coin-burnfrom-bug.tecra-coin-burnfrom-bug origin: community patterns: - pattern-inside: | function $BURN(..., address $FROM, ...) { ... _burn($FROM, ...); ... } - pattern-either: - pattern: require(_allowances[$S][$FROM] >= $X, ...) - pattern: require(allowance($S, $FROM) >= $X, ...) languages: - solidity severity: ERROR - id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request message: Detected input from a HTTPServletRequest going into the environment variables of an 'exec' command. Instead, call the command with user-supplied arguments by using the overloaded method with one String array as the argument. `exec({"command", "arg1", "arg2"})`. languages: - java severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) pattern-sinks: - patterns: - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); - focus-metavariable: $ENV_ARGS metadata: category: security technology: - java cwe: - 'CWE-454: External Initialization of Trusted Variables or Data Stores' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: false cwe2021-top25: false subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request shortlink: https://sg.run/EJAB semgrep.dev: rule: r_id: 70981 rv_id: 1409391 rule_id: nJULjy version_id: LjTRL6W url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request origin: community - patterns: - pattern-either: - pattern: | provisioner "remote-exec" { ... } - pattern: | provisioner "local-exec" { ... } - pattern-inside: | resource "aws_instance" "..." { ... } id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec message: Provisioners are a tool of last resort and should be avoided where possible. Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute arbitrary shell commands by design. languages: - terraform severity: WARNING metadata: category: security owasp: - A03:2021 - Injection - A01:2017 - Injection - A05:2025 - Injection cwe: - 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command Injection'')' - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' subcategory: - audit confidence: HIGH likelihood: HIGH impact: MEDIUM technology: - terraform references: - https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec - https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection - Other source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec shortlink: https://sg.run/7EjQ semgrep.dev: rule: r_id: 70982 rv_id: 1263736 rule_id: EwUxO1 version_id: bZT53j1 url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec origin: community - id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy metadata: category: security subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM technology: - terraform - aws owasp: - A05:2017 - Sensitive Data Exposure - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy - https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy shortlink: https://sg.run/LWlY semgrep.dev: rule: r_id: 70983 rv_id: 1263748 rule_id: 7KU3dr version_id: 7ZTE346 url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy origin: community message: '`$POLICY` is missing a `condition` block which scopes users of this policy to specific GitHub repositories. Without this, `$POLICY` is open to all users on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub` which scopes it to prevent this.' languages: - hcl severity: WARNING match: where: - metavariable: $IDENTIFIER regex: .*oidc-provider/token\.actions\.githubusercontent\.com all: - inside: | data "aws_iam_policy_document" $POLICY { ... } - | statement { ... principals { ... type = "Federated" identifiers = [..., $IDENTIFIER, ...] } } - not: | statement { ... condition { ... variable = "token.actions.githubusercontent.com:sub" } } - id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe languages: - clojure severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://xerces.apache.org/xerces2-j/features.html source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml category: security technology: - clojure - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe shortlink: https://sg.run/v7An semgrep.dev: rule: r_id: 71533 rv_id: 1262608 rule_id: bwU3Gj version_id: WrTqKyD url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe origin: community message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. Without prohibiting external entity declarations, this is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. patterns: - pattern-inside: | (ns ... (:require [clojure.xml :as ...])) ... - pattern-either: - pattern-inside: | (def ... ... ( ... )) - pattern-inside: | (defn ... ... ( ... )) - pattern-either: - pattern: (clojure.xml/parse $INPUT) - patterns: - pattern-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" false) - pattern-not-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ... (.setFeature "http://xml.org/sax/features/external-general-entities" false) ... (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) ...) - pattern-not-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ... (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) ... (.setFeature "http://xml.org/sax/features/external-general-entities" false) ...) - id: clojure.lang.security.use-of-sha1.use-of-sha1 languages: - clojure severity: WARNING message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function applications. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html technology: - clojure owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' - 'CWE-328: Use of Weak Hash' category: security subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Insecure Hashing Algorithm source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 shortlink: https://sg.run/dvwX semgrep.dev: rule: r_id: 71534 rv_id: 1262610 rule_id: NbUy12 version_id: K3TKk7E url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 origin: community patterns: - pattern-either: - pattern: (MessageDigest/getInstance $ALGO) - pattern: (java.security.MessageDigest/getInstance $ALGO) - metavariable-regex: metavariable: $ALGO regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) - id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs languages: - generic severity: WARNING message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose your application and its users to compromised code. SRIs allow you to consume specific versions of content where if even a single byte is compromised, the resource will not be loaded. Add an integrity attribute to your - pattern-not: paths: include: - '*.component' - '*.page' - id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute languages: - generic severity: INFO message: Visualforce Pages must have the cspHeader attribute set to true. This attribute is available in API version 55 or higher. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 category: security subcategory: - vuln technology: - salesforce - visualforce cwe2022-top25: true cwe2021-top25: true likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute shortlink: https://sg.run/yoj8 semgrep.dev: rule: r_id: 72424 rv_id: 1262907 rule_id: DbUj7d version_id: RGT0L0r url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute origin: community patterns: - pattern: ... - pattern-not: ... - pattern-not: ...... - pattern-not: ...... paths: include: - '*.page' - id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version languages: - generic severity: WARNING message: Visualforce Pages must use API version 55 or higher for required use of the cspHeader attribute set to true. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm category: security subcategory: - vuln technology: - salesforce - visualforce cwe2022-top25: true cwe2021-top25: true likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version shortlink: https://sg.run/rWr6 semgrep.dev: rule: r_id: 72425 rv_id: 1262908 rule_id: WAUwJW version_id: A8Tgdgn url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version origin: community patterns: - pattern-inside: - pattern-either: - pattern-regex: '[>][0-9].[0-9][<]' - pattern-regex: '[>][1-4][0-9].[0-9][<]' - pattern-regex: '[>][5][0-4].[0-9][<]' paths: include: - '*.page-meta.xml' - id: python.django.security.hashids-with-django-secret.hashids-with-django-secret languages: - python message: The Django secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient HashIDs, the salt used to construct them can be recovered. This means the Django secret key can be obtained by attackers, through the HashIDs. metadata: category: security subcategory: - vuln cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - "A02:2021 \u2013 Cryptographic Failures" references: - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY - http://carnage.github.io/2015/08/cryptanalysis-of-hashids technology: - django likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret shortlink: https://sg.run/bxeZ semgrep.dev: rule: r_id: 72426 rv_id: 946163 rule_id: 0oUXqy version_id: 0bT15nn url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret origin: community pattern-either: - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) severity: ERROR - id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret languages: - python message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient HashIDs, the salt used to construct them can be recovered. This means the Flask secret key can be obtained by attackers, through the HashIDs. metadata: category: security subcategory: - vuln cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - "A02:2021 \u2013 Cryptographic Failures" references: - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY - http://carnage.github.io/2015/08/cryptanalysis-of-hashids technology: - flask likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret shortlink: https://sg.run/N0Rx semgrep.dev: rule: r_id: 72427 rv_id: 946220 rule_id: KxUX3z version_id: 0bT15Px url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret origin: community pattern-either: - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) - patterns: - pattern-inside: | $APP = flask.Flask(...) ... - pattern-either: - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) severity: ERROR - id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' references: - https://docs.python.org/3/library/xml.html - https://github.com/tiran/defusedxml - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse shortlink: https://sg.run/n3jG semgrep.dev: rule: r_id: 72436 rv_id: 1263541 rule_id: X5Uqnx version_id: vdT06ER url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse origin: community message: The native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and "XML bombs" can cause denial of service. Do not use this library to parse untrusted input. Instead the Python documentation recommends using `defusedxml`. languages: - python severity: ERROR patterns: - pattern: xml.etree.ElementTree.parse($...ARGS) - pattern-not: xml.etree.ElementTree.parse("...") fix: defusedxml.etree.ElementTree.parse($...ARGS) - id: php.lang.security.tainted-exec.tainted-exec mode: taint pattern-sources: - pattern: $_REQUEST - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE pattern-sinks: - pattern: exec(...) - pattern: system(...) - pattern: popen(...) - pattern: passthru(...) - pattern: shell_exec(...) - pattern: pcntl_exec(...) - pattern: proc_open(...) pattern-sanitizers: - pattern: escapeshellarg(...) message: Executing non-constant commands. This can lead to command injection. You should use `escapeshellarg()` when using command. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' references: - https://www.stackhawk.com/blog/php-command-injection/ - https://brightsec.com/blog/code-injection-php/ - https://www.acunetix.com/websitesecurity/php-security-2/ category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec shortlink: https://sg.run/JAkP semgrep.dev: rule: r_id: 73146 rv_id: 1263300 rule_id: 9AUw06 version_id: BjTkZ4y url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec origin: community languages: - php severity: ERROR - id: php.lang.security.injection.tainted-session.tainted-session severity: WARNING message: Session key based on user input risks session poisoning. The user can determine the key used for the session, and thus write any session variable. Session variables are typically trusted to be set only by the application, and manipulating the session can result in access control issues. metadata: technology: - php category: security cwe: - 'CWE-284: Improper Access Control' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://en.wikipedia.org/wiki/Session_poisoning cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session shortlink: https://sg.run/bxNp semgrep.dev: rule: r_id: 73470 rv_id: 1263289 rule_id: 4bUdoP version_id: 8KT5rPE url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sanitizers: - patterns: - pattern-either: - pattern: $A . $B - pattern: bin2hex(...) - pattern: crc32(...) - pattern: crypt(...) - pattern: filter_input(...) - pattern: filter_var(...) - pattern: hash(...) - pattern: md5(...) - pattern: preg_filter(...) - pattern: preg_grep(...) - pattern: preg_match_all(...) - pattern: sha1(...) - pattern: sprintf(...) - pattern: str_contains(...) - pattern: str_ends_with(...) - pattern: str_starts_with(...) - pattern: strcasecmp(...) - pattern: strchr(...) - pattern: stripos(...) - pattern: stristr(...) - pattern: strnatcasecmp(...) - pattern: strnatcmp(...) - pattern: strncmp(...) - pattern: strpbrk(...) - pattern: strpos(...) - pattern: strripos(...) - pattern: strrpos(...) - pattern: strspn(...) - pattern: strstr(...) - pattern: strtok(...) - pattern: substr_compare(...) - pattern: substr_count(...) - pattern: vsprintf(...) pattern-sinks: - patterns: - pattern-inside: $_SESSION[$KEY] = $VAL; - pattern: $KEY - id: python.django.security.django-no-csrf-token.django-no-csrf-token patterns: - pattern: ... - pattern-either: - pattern: |
...
- pattern: |
...
- pattern: |
...
- metavariable-regex: metavariable: $METHOD regex: (?i)(post|put|delete|patch) - pattern-not-inside: ...{% csrf_token %}... - pattern-not-inside: ...{{ $VAR.csrf_token }}... message: Manually-created forms in django templates should specify a csrf_token to prevent CSRF attacks. languages: - generic severity: WARNING metadata: category: security cwe: 'CWE-352: Cross-Site Request Forgery (CSRF)' references: - https://docs.djangoproject.com/en/4.2/howto/csrf/ confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM subcategory: - audit technology: - django license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/python.django.security.django-no-csrf-token.django-no-csrf-token shortlink: https://sg.run/N0Bp semgrep.dev: rule: r_id: 73471 rv_id: 946160 rule_id: PeUyYG version_id: BjT1NRl url: https://semgrep.dev/playground/r/BjT1NRl/python.django.security.django-no-csrf-token.django-no-csrf-token origin: community paths: include: - '*.html' - id: python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-inside: | if $FORM.is_valid(): ... - pattern-either: - pattern: request.POST[...] - pattern: request.POST.get(...) message: Use $FORM.cleaned_data[] instead of request.POST[] after form.is_valid() has been executed to only access sanitized data languages: - python severity: WARNING metadata: category: security cwe: 'CWE-20: Improper Input Validation' references: - https://docs.djangoproject.com/en/4.2/ref/forms/api/#accessing-clean-data confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM subcategory: - audit technology: - django license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid shortlink: https://sg.run/kJn7 semgrep.dev: rule: r_id: 73472 rv_id: 946161 rule_id: JDUjqx version_id: DkTNpEJ url: https://semgrep.dev/playground/r/DkTNpEJ/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid origin: community - id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions patterns: - pattern: | "*" - pattern-inside: | resources: $A ... - pattern-inside: | verbs: $A ... - pattern-inside: | - apiGroups: [""] ... - pattern-inside: | apiVersion: rbac.authorization.k8s.io/v1 ... - pattern-inside: | kind: ClusterRole ... message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. Attaching excessive permissions to a ClusterRole associated with the core namespace allows the V1 API to perform arbitrary actions on arbitrary resources attached to the cluster. Prefer explicit allowlists of verbs/resources when configuring the core API namespace. ' languages: - yaml severity: WARNING metadata: cwe: - 'CWE-269: Improper Privilege Management' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups category: security technology: - kubernetes cwe2021-top25: false subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions shortlink: https://sg.run/x6Dz semgrep.dev: rule: r_id: 73474 rv_id: 1263935 rule_id: GdUR2A version_id: 9lT4bw7 url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions origin: community - id: ocaml.lang.security.unsafe.ocamllint-unsafe pattern-either: - pattern: $X.unsafe_get - pattern: $X.unsafe_set - pattern: $X.unsafe_to_string - pattern: $X.unsafe_of_string - pattern: $X.unsafe_blit - pattern: $X.unsafe_blit_string - pattern: $X.unsafe_fill - pattern: $X.unsafe_to_string - pattern: $X.unsafe_getenv - pattern: $X.unsafe_environment - pattern: $X.unsafe_chr - pattern: $X.unsafe_of_int - pattern: $X.unsafe_output - pattern: $X.unsafe_output_string - pattern: $X.unsafe_read - pattern: $X.unsafe_recv - pattern: $X.unsafe_recvfrom - pattern: $X.unsafe_send - pattern: $X.unsafe_sendto - pattern: $X.unsafe_set - pattern: $X.unsafe_set_int16 - pattern: $X.unsafe_set_int32 - pattern: $X.unsafe_set_int64 - pattern: $X.unsafe_set_int8 - pattern: $X.unsafe_set_uint16_ne - pattern: $X.unsafe_set_uint8 - pattern: $X.unsafe_single_write - pattern: $X.unsafe_string - pattern: $X.unsafe_sub - pattern: $X.unsafe_write message: Unsafe functions do not perform boundary checks or have other side effects, use with care. languages: - ocaml severity: WARNING metadata: category: security references: - https://v2.ocaml.org/api/Bigarray.Array1.html#VALunsafe_get - https://v2.ocaml.org/api/Bytes.html#VALunsafe_to_string technology: - ocaml cwe: 'CWE-242: Use of Inherently Dangerous Function (4.12)' confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM subcategory: - audit license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/ocaml.lang.security.unsafe.ocamllint-unsafe shortlink: https://sg.run/d8K80 semgrep.dev: rule: r_id: 92978 rv_id: 945981 rule_id: 6JUvjv6 version_id: zyTlkwv url: https://semgrep.dev/playground/r/zyTlkwv/ocaml.lang.security.unsafe.ocamllint-unsafe origin: community - id: python.fastapi.security.wildcard-cors.wildcard-cors languages: - python message: CORS policy allows any origin (using wildcard '*'). This is insecure and should be avoided. mode: taint pattern-sources: - pattern: '[..., "*", ...]' pattern-sinks: - patterns: - pattern: | $APP.add_middleware( CORSMiddleware, allow_origins=$ORIGIN, ...); - focus-metavariable: $ORIGIN severity: WARNING metadata: cwe: - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - python - fastapi references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration - https://cwe.mitre.org/data/definitions/942.html likelihood: HIGH impact: LOW confidence: MEDIUM vulnerability_class: - Configuration subcategory: - vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors shortlink: https://sg.run/KxApY semgrep.dev: rule: r_id: 112311 rv_id: 1263413 rule_id: lBU4JQ3 version_id: A8Tgd1R url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors origin: community - id: go.lang.security.injection.open-redirect.open-redirect languages: - go severity: WARNING message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This can lead to open redirect vulnerabilities, potentially allowing attackers to redirect users to malicious web sites. It is recommend where possible to not allow user-input to craft the redirect URL. When user-input is necessary to craft the request, it is recommended to follow OWASP best practices to restrict the URL to domains in an allowlist. options: interfile: true metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' references: - https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html category: security technology: - go confidence: HIGH description: An HTTP redirect was found to be crafted from user-input leading to an open redirect vulnerability subcategory: - vuln impact: MEDIUM likelihood: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect shortlink: https://sg.run/2ZW45 semgrep.dev: rule: r_id: 113619 rv_id: 945608 rule_id: DbU6RlN version_id: GxTP7J7 url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect origin: community mode: taint pattern-sources: - label: INPUT patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ - label: CLEAN requires: INPUT patterns: - pattern-either: - pattern: | "$URLSTR" + $INPUT - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) - pattern: fmt.Printf("$URLSTR", $INPUT, ...) - metavariable-regex: metavariable: $URLSTR regex: .*//[a-zA-Z0-10]+\..* pattern-sinks: - requires: INPUT and not CLEAN patterns: - pattern: http.Redirect($W, $REQ, $URL, ...) - focus-metavariable: $URL - id: php.lang.security.base-convert-loses-precision.base-convert-loses-precision message: The function base_convert uses 64-bit numbers internally, and does not correctly convert large numbers. It is not suitable for random tokens such as those used for session tokens or CSRF tokens. metadata: references: - https://www.php.net/base_convert - https://www.sjoerdlangkemper.nl/2017/03/15/dont-use-base-convert-on-random-tokens/ category: security technology: - php cwe: - 'CWE-190: Integer Overflow or Wraparound' subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/php.lang.security.base-convert-loses-precision.base-convert-loses-precision shortlink: https://sg.run/kxpGo semgrep.dev: rule: r_id: 115928 rv_id: 945988 rule_id: 7KUgBAk version_id: yeT0n4K url: https://semgrep.dev/playground/r/yeT0n4K/php.lang.security.base-convert-loses-precision.base-convert-loses-precision origin: community languages: - php severity: WARNING mode: taint pattern-sources: - pattern: hash(...) - pattern: hash_hmac(...) - pattern: sha1(...) - pattern: md5(...) - patterns: - pattern: random_bytes($N) - metavariable-comparison: metavariable: $N comparison: $N > 7 - patterns: - pattern: openssl_random_pseudo_bytes($N) - metavariable-comparison: metavariable: $N comparison: $N > 7 - patterns: - pattern: $OBJ->get_random_bytes($N) - metavariable-comparison: metavariable: $N comparison: $N > 7 pattern-sinks: - pattern: base_convert(...) pattern-sanitizers: - patterns: - pattern: substr(..., $LENGTH) - metavariable-comparison: metavariable: $LENGTH comparison: $LENGTH <= 7 - id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Set 'verify' to `true` before using the token. severity: ERROR metadata: owasp: - A05:2021 - Security Misconfiguration - A07:2021 - Identification and Authentication Failures - A02:2025 - Security Misconfiguration - A07:2025 - Authentication Failures cwe: - 'CWE-287: Improper Authentication' - 'CWE-345: Insufficient Verification of Data Authenticity' - 'CWE-347: Improper Verification of Cryptographic Signature' category: security subcategory: - vuln technology: - jwt-simple - jwt confidence: HIGH likelihood: MEDIUM impact: HIGH references: - https://www.npmjs.com/package/jwt-simple - https://cwe.mitre.org/data/definitions/287 - https://cwe.mitre.org/data/definitions/345 - https://cwe.mitre.org/data/definitions/347 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Improper Authentication source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify shortlink: https://sg.run/zdjod semgrep.dev: rule: r_id: 120561 rv_id: 1263191 rule_id: r6UyNLy version_id: 3ZT4Xxv url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify origin: community languages: - javascript - typescript patterns: - pattern-inside: | $JWT = require('jwt-simple'); ... - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) - metavariable-pattern: metavariable: $NOVERIFY patterns: - pattern-either: - pattern: | true - pattern: | "..." - id: php.lang.security.injection.printed-request.printed-request mode: taint message: '`Printing user input risks cross-site scripting vulnerability. You should use `htmlentities()` when showing data to users.' languages: - php severity: ERROR pattern-sources: - pattern: $_REQUEST - pattern: $_GET - pattern: $_POST pattern-sinks: - pattern: print($...VARS); pattern-sanitizers: - pattern: htmlentities(...) - pattern: htmlspecialchars(...) - pattern: strip_tags(...) - pattern: isset(...) - pattern: empty(...) - pattern: esc_html(...) - pattern: esc_attr(...) - pattern: wp_kses(...) - pattern: e(...) - pattern: twig_escape_filter(...) - pattern: xss_clean(...) - pattern: html_escape(...) - pattern: Html::escape(...) - pattern: Xss::filter(...) - pattern: escapeHtml(...) - pattern: escapeHtml(...) - pattern: escapeHtmlAttr(...) fix: print(htmlentities($...VARS)); metadata: technology: - php cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security references: - https://www.php.net/manual/en/function.htmlentities.php - https://www.php.net/manual/en/reserved.variables.request.php - https://www.php.net/manual/en/reserved.variables.post.php - https://www.php.net/manual/en/reserved.variables.get.php - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request shortlink: https://sg.run/QrxEJ semgrep.dev: rule: r_id: 128886 rv_id: 1263284 rule_id: KxUvRBw version_id: ZRTKAk4 url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request origin: community - id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone patterns: - pattern-inside: | &sessions.Options{ ..., SameSite: http.SameSiteNoneMode, ..., } - pattern: | &sessions.Options{ ..., } message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting SameSite to Lax, Strict or Default for enhanced security. metadata: cwe: - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://pkg.go.dev/github.com/gorilla/sessions#Options category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone shortlink: https://sg.run/x8Nwj semgrep.dev: rule: r_id: 133074 rv_id: 1262913 rule_id: YGUpGd4 version_id: K3TKkKB url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone origin: community fix-regex: regex: (SameSite\s*:\s+)http.SameSiteNoneMode replacement: \1http.SameSiteDefaultMode severity: WARNING languages: - go - id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx languages: - solidity message: Missing check for 'from' and 'to' being the same before updating balances could lead to incorrect balance manipulation on self-transfers. Include a check to ensure 'from' and 'to' are not the same before updating balances to prevent balance manipulation during self-transfers. severity: ERROR metadata: category: security technology: - blockchain - solidity cwe: 'CWE-682: Incorrect Calculation' subcategory: - vuln confidence: HIGH likelihood: HIGH impact: HIGH owasp: - A7:2021 Identification and Authentication Failures references: - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities - https://x.com/shoucccc/status/1757777764646859121 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx shortlink: https://sg.run/Or6X7 semgrep.dev: rule: r_id: 133075 rv_id: 946620 rule_id: 6JUv7Nz version_id: A8TJzYz url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx origin: community patterns: - pattern-either: - pattern: | _balances[$FROM] = $FROM_BALANCE - value; - pattern: | _balances[$TO] = $TO_BALANCE + value; - pattern-not-inside: | if ($FROM != $TO) { ... _balances[$FROM] = $FROM_BALANCE - value; ... _balances[$TO] = $TO_BALANCE + value; ... } - pattern-inside: | function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual { ... } - id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication languages: - yaml message: Basic authentication is considered weak and should be avoided. Use a different authentication scheme, such of OAuth2, OpenID Connect, or mTLS. severity: ERROR patterns: - pattern-inside: | openapi: $VERSION ... components: ... securitySchemes: ... $SCHEME: ... - metavariable-regex: metavariable: $VERSION regex: 3.* - pattern: | type: http ... scheme: basic metadata: category: security subcategory: - vuln technology: - openapi likelihood: MEDIUM impact: HIGH confidence: HIGH cwe: 'CWE-287: Improper Authentication' owasp: - A04:2021 Insecure Design - A07:2021 Identification and Authentication Failures references: - https://cwe.mitre.org/data/definitions/287.html - https://owasp.org/Top10/A04_2021-Insecure_Design/ - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication shortlink: https://sg.run/v8wNW semgrep.dev: rule: r_id: 133077 rv_id: 947072 rule_id: zdUKgEX version_id: 0bT1ErG url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication origin: community - id: python.twilio.security.twiml-injection.twiml-injection languages: - python severity: WARNING message: Using non-constant TwiML (Twilio Markup Language) argument when creating a Twilio conversation could allow the injection of additional TwiML commands metadata: cwe: - 'CWE-91: XML Injection' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - python - twilio - twiml confidence: MEDIUM likelihood: HIGH impact: MEDIUM subcategory: - vuln references: - https://codeberg.org/fennix/funjection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection shortlink: https://sg.run/GdEEy semgrep.dev: rule: r_id: 134692 rv_id: 1263580 rule_id: oqUgjj2 version_id: kbTzGp1 url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection origin: community mode: taint pattern-sources: - pattern: | f"..." - pattern: | "..." % ... - pattern: | "...".format(...) - patterns: - pattern: $ARG - pattern-inside: | def $F(..., $ARG, ...): ... pattern-sanitizers: - pattern: xml.sax.saxutils.escape(...) - pattern: html.escape(...) pattern-sinks: - patterns: - pattern: | $CLIENT.calls.create(..., twiml=$SINK, ...) - focus-metavariable: $SINK - id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded message: A secret is hard-coded in the application. Secrets stored in source code, such as credentials, identifiers, and other types of sensitive data, can be leaked and used by internal or external malicious actors. It is recommended to rotate the secret and retrieve them from a secure secret vault or Hardware Security Module (HSM), alternatively environment variables can be used if allowed by your company policy. severity: WARNING metadata: likelihood: LOW impact: HIGH confidence: MEDIUM category: security subcategory: - vuln cwe: - 'CWE-798: Use of Hard-coded Credentials' cwe2020-top25: true cwe2021-top25: true cwe2022-top25: true owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures technology: - secrets vulnerability_class: - Hard-coded Secrets source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded shortlink: https://sg.run/qN29x semgrep.dev: rule: r_id: 137856 rv_id: 1263257 rule_id: ReUD6Kg version_id: DkTRbLX url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded origin: community languages: - kotlin options: symbolic_propagation: true patterns: - pattern-either: - pattern: '$PASS = env[...] ?: $VALUE' - metavariable-regex: metavariable: $PASS regex: (password|pass|passwd|loginPassword) - metavariable-pattern: language: generic metavariable: $VALUE patterns: - pattern-either: - pattern-regex: ^[A-Za-z0-9/+=]+$ paths: include: - '*build.gradle.kts' - id: generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token pattern-regex: (?:api_live(?:_[a-zA-Z]{2})?\.[a-zA-Z0-9-_]{11}\.[-_a-zA-Z0-9]{32}) languages: - regex message: Onfido live API Token detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - secrets - onfido confidence: HIGH references: - https://documentation.onfido.com/api/latest/#api-tokens subcategory: - audit likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token shortlink: https://sg.run/lBoKD semgrep.dev: rule: r_id: 141957 rv_id: 945509 rule_id: WAUW9q3 version_id: A8TJzE2 url: https://semgrep.dev/playground/r/A8TJzE2/generic.secrets.security.detected-onfido-live-api-token.detected-onfido-live-api-token origin: community - id: php.lang.security.injection.tainted-callable.tainted-callable severity: WARNING message: Callable based on user input risks remote code execution. metadata: technology: - php category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://www.php.net/manual/en/language.types.callable.php subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable shortlink: https://sg.run/YGb33 semgrep.dev: rule: r_id: 141958 rv_id: 1263285 rule_id: 0oULBKK version_id: nWT2L5x url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: file_get_contents('php://input') pattern-sinks: - patterns: - pattern: $CALLABLE - pattern-either: - pattern-inside: $ARRAYITERATOR->uasort($CALLABLE) - pattern-inside: $ARRAYITERATOR->uksort($CALLABLE) - pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...) - pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...) - pattern-inside: $EVLOOP->fork($CALLABLE, ...) - pattern-inside: $EVLOOP->idle($CALLABLE, ...) - pattern-inside: $EVLOOP->prepare($CALLABLE, ...) - pattern-inside: $EVWATCHER->setCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE) - pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE) - pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE) - pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE) - pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE) - pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE) - pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE) - pattern-inside: $SQLITE3->setAuthorizer($CALLABLE) - pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE) - pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE) - pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...) - pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...) - pattern-inside: apcu_entry($KEY, $CALLABLE, ...) - pattern-inside: array_filter($ARRAY, $CALLABLE, ...) - pattern-inside: array_map($CALLABLE, ...) - pattern-inside: array_reduce($ARRAY, $CALLABLE, ...) - pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...) - pattern-inside: array_walk($ARRAY, $CALLABLE, ...) - pattern-inside: call_user_func_array($CALLABLE, ...) - pattern-inside: call_user_func($CALLABLE, ...) - pattern-inside: Closure::fromCallable($CALLABLE) - pattern-inside: createCollation($NAME, $CALLABLE) - pattern-inside: eio_grp($CALLABLE, ...) - pattern-inside: eio_nop($PRI, $CALLABLE, ...) - pattern-inside: eio_sync($PRI, $CALLABLE, ...) - pattern-inside: EvPrepare::createStopped($CALLABLE, ...) - pattern-inside: fann_set_callback($ANN, $CALLABLE) - pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...) - pattern-inside: forward_static_call_array($CALLABLE, ...) - pattern-inside: forward_static_call($CALLABLE, ...) - pattern-inside: header_register_callback($CALLABLE) - pattern-inside: ibase_set_event_handler($CALLABLE, ...) - pattern-inside: IntlChar::enumCharTypes($CALLABLE) - pattern-inside: iterator_apply($ITERATOR, $CALLABLE) - pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE) - pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...) - pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE) - pattern-inside: new EvCheck($CALLABLE, ...) - pattern-inside: new EventHttpRequest($CALLABLE, ...) - pattern-inside: new EvFork($CALLABLE, ...) - pattern-inside: new EvIdle($CALLABLE, ...) - pattern-inside: new Fiber($CALLABLE) - pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...) - pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE) - pattern-inside: new Zookeeper($HOST, $CALLABLE, ...) - pattern-inside: ob_start($CALLABLE, ...) - pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE) - pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE) - pattern-inside: readline_completion_function($CALLABLE) - pattern-inside: register_shutdown_function($CALLABLE, ...) - pattern-inside: register_tick_function($CALLABLE, ...) - pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE) - pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...) - pattern-inside: set_error_handler($CALLABLE, ...) - pattern-inside: set_exception_handler($CALLABLE) - pattern-inside: setAuthorizer($CALLABLE) - pattern-inside: spl_autoload_register($CALLABLE, ...) - pattern-inside: uasort($ARRAY, $CALLABLE) - pattern-inside: uksort($ARRAY, $CALLABLE) - pattern-inside: usort($ARRAY, $CALLABLE) - pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE) - pattern-inside: xml_set_default_handler($PARSER, $CALLABLE) - pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE) - pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE) - pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...) - id: dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount message: The Dockerfile(image) mounts docker.sock to the container which may allow an attacker already inside of the container to escape container and execute arbitrary commands on the host machine. languages: - dockerfile - yaml severity: ERROR metadata: cwe: - 'CWE-862: Missing Authorization' - 'CWE-269: Improper Privilege Management' confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - audit technology: - dockerfile category: security references: - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html - https://redfoxsec.com/blog/insecure-volume-mounts-in-docker/ - https://blog.quarkslab.com/why-is-exposing-the-docker-socket-a-really-bad-idea.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount shortlink: https://sg.run/10AAQ semgrep.dev: rule: r_id: 146566 rv_id: 945266 rule_id: oqUgAAk version_id: WrTEoEq url: https://semgrep.dev/playground/r/WrTEoEq/dockerfile.security.dockerd-socket-mount.dockerfile-dockerd-socket-mount origin: community pattern-either: - patterns: - pattern: VOLUME $X - metavariable-regex: metavariable: $X regex: /var/run/docker.sock - patterns: - pattern-regex: '- "/var/run/docker.sock:.*"' - pattern-inside: | volumes: ... - id: go.lang.security.reverseproxy-director.reverseproxy-director message: ReverseProxy can remove headers added by Director. Consider using ReverseProxy.Rewrite instead of ReverseProxy.Director. languages: - go severity: WARNING patterns: - pattern-inside: | import "net/http/httputil" ... - pattern-either: - pattern: $PROXY.Director = $FUNC - patterns: - pattern-inside: | httputil.ReverseProxy{ ... } - pattern: | Director: $FUNC metadata: cwe: - 'CWE-115: Misinterpretation of Input' category: security subcategory: - audit technology: - go confidence: MEDIUM likelihood: LOW impact: LOW references: - https://github.com/golang/go/issues/50580 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.lang.security.reverseproxy-director.reverseproxy-director shortlink: https://sg.run/9AYYR semgrep.dev: rule: r_id: 146567 rv_id: 945612 rule_id: zdUKzzA version_id: DkTNpvx url: https://semgrep.dev/playground/r/DkTNpvx/go.lang.security.reverseproxy-director.reverseproxy-director origin: community - id: javascript.node-crypto.security.aead-no-final.aead-no-final message: The 'final' call of a Decipher object checks the authentication tag in a mode for authenticated encryption. Failing to call 'final' will invalidate all integrity guarantees of the released ciphertext. metadata: cwe: - 'CWE-310: CWE CATEGORY: Cryptographic Issues' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security subcategory: - vuln technology: - node-crypto likelihood: HIGH impact: MEDIUM confidence: HIGH references: - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final shortlink: https://sg.run/r6EEA semgrep.dev: rule: r_id: 146569 rv_id: 1263222 rule_id: 2ZUz884 version_id: zyTb2X0 url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern: | $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) ... $DECIPHER.update(...) - pattern-not-inside: | $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) ... $DECIPHER.final(...) - metavariable-regex: metavariable: $ALGO regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ - id: javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv message: The deprecated functions 'createCipher' and 'createDecipher' generate the same initialization vector every time. For counter modes such as CTR, GCM, or CCM this leads to break of both confidentiality and integrity, if the key is used more than once. Other modes are still affected in their strength, though they're not completely broken. Use 'createCipheriv' or 'createDecipheriv' instead. metadata: cwe: - 'CWE-1204: Generation of Weak Initialization Vector (IV)' category: security subcategory: - vuln technology: - node-crypto likelihood: HIGH impact: MEDIUM confidence: HIGH references: - https://nodejs.org/api/crypto.html#cryptocreatecipheralgorithm-password-options - https://nodejs.org/api/crypto.html#cryptocreatedecipheralgorithm-password-options license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv shortlink: https://sg.run/bw33r semgrep.dev: rule: r_id: 146570 rv_id: 945898 rule_id: X5UQRR7 version_id: ZRT3510 url: https://semgrep.dev/playground/r/ZRT3510/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern-either: - pattern: | $CRYPTO.createCipher(...) - pattern: | $CRYPTO.createDecipher(...) - id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode of operation is missing an expected authentication tag length. If the expected authentication tag length is not specified or otherwise checked, the application might be tricked into verifying a shorter-than-expected authentication tag. This can be abused by an attacker to spoof ciphertexts or recover the implicit authentication key of GCM, allowing arbitrary forgeries. metadata: cwe: - 'CWE-310: CWE CATEGORY: Cryptographic Issues' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security subcategory: - vuln technology: - node-crypto likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length shortlink: https://sg.run/NbGG1 semgrep.dev: rule: r_id: 146571 rv_id: 1263223 rule_id: j2UgPP3 version_id: pZT03qd url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern: | $CRYPTO.createDecipheriv('$ALGO', $KEY, $IV) - metavariable-regex: metavariable: $ALGO regex: .*(-gcm)$ - id: php.lang.security.injection.tainted-exec.tainted-exec languages: - php severity: WARNING message: User input is passed to a function that executes a shell command. This can lead to remote code execution. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec shortlink: https://sg.run/kxEEz semgrep.dev: rule: r_id: 146572 rv_id: 1263286 rule_id: 10UOGG5 version_id: ExTExyR url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: file_get_contents('php://input') pattern-sanitizers: - patterns: - pattern-either: - pattern: escapeshellcmd(...) - pattern: escapeshellarg(...) pattern-sinks: - patterns: - pattern-either: - pattern: exec(...) - pattern: system(...) - pattern: passthru(...) - patterns: - pattern: proc_open(...) - pattern-not: proc_open([...], ...) - pattern: popen(...) - pattern: expect_popen(...) - pattern: shell_exec(...) - pattern: | `...` - id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false languages: - yaml message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method: $METHOD $PATH. This Action configuration will enable the ''Always Allow'' option for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk of a user selecting the ''Always Allow'' button is that the agent could perform unintended actions on behalf of the user. When working with sensitive functionality, it is always best to include a Human In The Loop (HITL) type of control. Consider the trade-off between security and user friction and then make a risk-based decision about this function.' severity: WARNING pattern-either: - pattern-inside: | post: ... x-openai-isConsequential: false - pattern-inside: | put: ... x-openai-isConsequential: false - pattern-inside: | patch: ... x-openai-isConsequential: false - pattern-inside: | delete: ... x-openai-isConsequential: false metadata: category: security subcategory: - audit technology: - openapi - openai likelihood: HIGH impact: HIGH confidence: HIGH cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' owasp: - A04:2021 Insecure Design - LLM08:2023 - Excessive Agency references: - https://platform.openai.com/docs/actions/consequential-flag - https://owasp.org/Top10/A04_2021-Insecure_Design/ - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false shortlink: https://sg.run/x8EEP semgrep.dev: rule: r_id: 146574 rv_id: 947071 rule_id: yyURooD version_id: WrTEZN8 url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false origin: community - id: python.lang.security.insecure-uuid-version.insecure-uuid-version patterns: - pattern: uuid.uuid1(...) message: Using UUID version 1 for UUID generation can lead to predictable UUIDs based on system information (e.g., MAC address, timestamp). This may lead to security risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better randomness and security. metadata: references: - https://www.landh.tech/blog/20230811-sandwich-attack/ cwe: - 'CWE-330: Use of Insufficiently Random Values' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.3.2 Insecure UUID Generation control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values version: '4' category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version shortlink: https://sg.run/BYBgW semgrep.dev: rule: r_id: 148295 rv_id: 1263539 rule_id: kxUd1yD version_id: O9Tpx97 url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version origin: community languages: - python severity: WARNING fix-regex: regex: uuid1 replacement: uuid4 - id: go.lang.security.audit.crypto.sha224-hash.sha224-hash pattern-either: - patterns: - pattern-inside: | import "crypto/sha256" ... - pattern-either: - pattern: | sha256.New224() - pattern: | sha256.Sum224(...) - patterns: - pattern-inside: | import "golang.org/x/crypto/sha3" ... - pattern-either: - pattern: | sha3.New224() - pattern: | sha3.Sum224(...) message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' category: security technology: - go references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash shortlink: https://sg.run/ReJwY semgrep.dev: rule: r_id: 151749 rv_id: 1262925 rule_id: GdUvElR version_id: 9lT4b4w url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash origin: community - id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::javax.crypto owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 shortlink: https://sg.run/Ab2KQ semgrep.dev: rule: r_id: 151750 rv_id: 1263017 rule_id: ReUDGEz version_id: YDTZewo url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 origin: community pattern-either: - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) - patterns: - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); - metavariable-regex: metavariable: $ALGO regex: .*224 - id: php.lang.security.audit.sha224-hash.sha224-hash pattern-either: - pattern: hash('sha224', ...); - pattern: hash('sha512/224', ...); - pattern: hash('sha3-224', ...); - pattern: hash_hmac('sha224', ...); - pattern: hash_hmac('sha512/224', ...); - pattern: hash_hmac('sha3-224', ...); message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - php owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/BYXqv semgrep.dev: rule: r_id: 151751 rv_id: 1263275 rule_id: AbU97EA version_id: bZT53Jo url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash origin: community languages: - php severity: WARNING - id: python.lang.security.audit.sha224-hash.sha224-hash message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - python subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/Db1Yv semgrep.dev: rule: r_id: 151752 rv_id: 1263511 rule_id: BYUX0y9 version_id: 5PTo1QL url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash origin: community severity: WARNING languages: - python pattern-either: - pattern: hashlib.sha224(...) - pattern: hashlib.sha3_224(...) - id: ruby.lang.security.audit.sha224-hash.sha224-hash message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/WABbo semgrep.dev: rule: r_id: 151753 rv_id: 1263592 rule_id: DbU60wQ version_id: 8KT5rRY url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash origin: community languages: - ruby severity: WARNING pattern-either: - pattern: Digest::SHA224.$FUNC - pattern: OpenSSL::Digest::SHA224.$FUNC - pattern: SHA3::Digest::SHA224(...) - patterns: - pattern-either: - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) - pattern: OpenSSL::HMAC.digest("$ALGO", ...) - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") - pattern: OpenSSL::Digest.digest("$ALGO", ...) - pattern: OpenSSL::Digest.new("$ALGO", ...) - metavariable-regex: metavariable: $ALGO regex: .*224 - id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql patterns: - pattern-inside: | resource "google_sql_database_instance" "..." { ... database_version = "$DB" ... } - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = $VALUE ... } ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" ... } ... } - metavariable-regex: metavariable: $DB regex: .*(MYSQL|POSTGRES).* - focus-metavariable: $VALUE fix: | "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" message: Ensure all Cloud SQL database instance require incoming connections to use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql shortlink: https://sg.run/WANR2 semgrep.dev: rule: r_id: 153509 rv_id: 1263874 rule_id: 5rUdGAz version_id: 2KTv22E url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql origin: community languages: - hcl severity: WARNING - id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver patterns: - pattern-inside: | resource "google_sql_database_instance" "..." { ... database_version = "$DB" ... } - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = $VALUE ... } ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = "ENCRYPTED_ONLY" ... } ... } - metavariable-regex: metavariable: $DB regex: .*(SQLSERVER).* - focus-metavariable: $VALUE fix: | "ENCRYPTED_ONLY" message: Ensure all Cloud SQL database instance require incoming connections to use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value that is supported. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver shortlink: https://sg.run/0o92j semgrep.dev: rule: r_id: 153510 rv_id: 1263875 rule_id: GdUvX6A version_id: X0Tzyyl url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver origin: community languages: - hcl severity: WARNING - id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true message: Function `flask.url_for` with `_external=True` argument will generate URLs using the `Host` header of the HTTP request, which may lead to security risks such as Host header injection metadata: cwe: - 'CWE-673: External Influence of Sphere Definition' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - flask references: - https://flask.palletsprojects.com/en/latest/api/#flask.url_for - https://portswigger.net/kb/issues/00500300_host-header-injection subcategory: - audit likelihood: MEDIUM impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true shortlink: https://sg.run/gEGeR semgrep.dev: rule: r_id: 191541 rv_id: 1263418 rule_id: JDU5oql version_id: K3TKk6n url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true origin: community languages: - python severity: WARNING patterns: - pattern-not: flask.url_for(..., _external=False, ...) - pattern-not: url_for(..., _external=False, ...) - pattern-either: - pattern: flask.url_for(..., _external=$VAR, ...) - pattern: url_for(..., _external=$VAR, ...) - id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit languages: - php severity: WARNING message: Detected usage of vulnerable functions with user input, which could lead to SSRF vulnerabilities. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET[...] - pattern: $_POST[...] - pattern: $_REQUEST[...] - pattern: get_option(...) - pattern: get_user_meta(...) - pattern: get_query_var(...) pattern-sinks: - patterns: - focus-metavariable: $URL - pattern-either: - pattern: wp_remote_get($URL, ...) - pattern: wp_safe_remote_get($URL, ...) - pattern: wp_safe_remote_request($URL, ...) - pattern: wp_safe_remote_head($URL, ...) - pattern: wp_oembed_get($URL, ...) - pattern: vip_safe_wp_remote_get($URL, ...) - pattern: wp_safe_remote_post($URL, ...) paths: include: - '**/wp-content/plugins/**/*.php' metadata: cwe: 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: A10:2021 - Server-Side Request Forgery (SSRF) category: security confidence: MEDIUM likelihood: MEDIUM impact: HIGH subcategory: - audit technology: - Wordpress Plugins references: - https://developer.wordpress.org/reference/functions/wp_safe_remote_get/ - https://developer.wordpress.org/reference/functions/wp_remote_get/ - https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/ vulnerability_class: - Server-Side Request Forgery (SSRF) license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit shortlink: https://sg.run/K3y06 semgrep.dev: rule: r_id: 191611 rv_id: 1039233 rule_id: 6JUZyKX version_id: JdTp6rq url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit origin: community - id: dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url patterns: - pattern: | RUN ... $PIP install ... --extra-index-url ... - metavariable-regex: metavariable: $PIP regex: pip|pip3 message: 'When `--extra-index-url` is used in a `pip install` command, this is usually meant to install a package from a package index other than the public one. However, if a package is added with the same name to the public PyPi repository, and if the version number is high enough, this package will be installed when building this docker image. This package may be a malicious dependency. Such an attack is called a dependency confusion attack. If using a private package index, prefer to use `--index-url` if possible. ' languages: - dockerfile severity: INFO metadata: references: - https://pip.pypa.io/en/stable/cli/pip_install/#cmdoption-extra-index-url - https://github.com/semgrep/semgrep-rules/issues/3032 category: security subcategory: - audit confidence: MEDIUM impact: HIGH likelihood: LOW technology: - docker cwe: - 'CWE-427: Uncontrolled Search Path Element' license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url shortlink: https://sg.run/qk4p8 semgrep.dev: rule: r_id: 197112 rv_id: 1039209 rule_id: pKUkLD3 version_id: 1QTY5L3 url: https://semgrep.dev/playground/r/1QTY5L3/dockerfile.audit.dockerfile-pip-extra-index-url.dockerfile-pip-extra-index-url origin: community - id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor languages: - yaml message: The Shai-hulud backdoor creates a purposefully vulnerable github action with the name `discussion.yaml`. paths: include: - '**/.github/workflows/discussion.yaml' metadata: category: security cwe: - 'CWE-509: Replicating Malicious Code (Virus or Worm)' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - github-actions cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack references: - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor shortlink: https://sg.run/JdYPZ semgrep.dev: rule: r_id: 238946 rv_id: 1263927 rule_id: 7KUDRPj version_id: 6xT29ol url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ github.event.issue.title }} - pattern: ${{ github.event.issue.body }} - pattern: ${{ github.event.pull_request.title }} - pattern: ${{ github.event.pull_request.body }} - pattern: ${{ github.event.comment.body }} - pattern: ${{ github.event.review.body }} - pattern: ${{ github.event.review_comment.body }} - pattern: ${{ github.event.pages. ... .page_name}} - pattern: ${{ github.event.head_commit.message }} - pattern: ${{ github.event.head_commit.author.email }} - pattern: ${{ github.event.head_commit.author.name }} - pattern: ${{ github.event.commits ... .author.email }} - pattern: ${{ github.event.commits ... .author.name }} - pattern: ${{ github.event.pull_request.head.ref }} - pattern: ${{ github.event.pull_request.head.label }} - pattern: ${{ github.event.pull_request.head.repo.default_branch }} - pattern: ${{ github.head_ref }} - pattern: ${{ github.event.inputs ... }} - pattern: ${{ github.event.discussion.title }} - pattern: ${{ github.event.discussion.body }} - pattern: ${{ inputs ... }} severity: ERROR - id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface languages: - go message: Deserializing into `interface{}` allows arbitrary data structures and types, which can lead to security vulnerabilities (CWE-502). Use a concrete struct type instead. severity: WARNING metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures category: security technology: - go confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://cwe.mitre.org/data/definitions/502.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface shortlink: https://sg.run/6WbKL semgrep.dev: rule: r_id: 274359 rv_id: 1409387 rule_id: 4bUAQDG version_id: ZRTDkjk url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface origin: community patterns: - pattern-either: - pattern: | var $VAR interface{} ... json.Unmarshal($DATA, &$VAR) - pattern: | var $VAR interface{} ... yaml.Unmarshal($DATA, &$VAR) - pattern: | var $VAR interface{} ... xml.Unmarshal($DATA, &$VAR) - id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by the action owner, enabling supply-chain attacks \u2014 as seen in the trivy-action and kics-github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`." severity: WARNING languages: - yaml metadata: category: security cwe: - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' - 'CWE-353: Missing Support for Integrity Check' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software and Data Integrity Failures references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Other source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag shortlink: https://sg.run/2LgAL semgrep.dev: rule: r_id: 288863 rv_id: 1413422 rule_id: GdUxYDx version_id: xyTRDAd url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag origin: community patterns: - pattern-inside: '{steps: ...}' - pattern: | uses: "$ACTION" - metavariable-pattern: metavariable: $ACTION language: generic patterns: - pattern-not-regex: ^\./ - pattern-not-regex: ^docker:// - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' - id: yaml.github-actions.security.secrets-inherit.secrets-inherit languages: - yaml severity: ERROR message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s secrets to a reusable workflow. This violates the principle of least privilege because the called workflow receives access to every secret in the repository, not just the ones it needs. If the called workflow is compromised or sourced from a third party, an attacker gains access to all repository secrets. Instead, explicitly pass only the secrets that the called workflow requires using the `secrets:` map, e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.' metadata: category: security cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit shortlink: https://sg.run/X2PZB semgrep.dev: rule: r_id: 288864 rv_id: 1413424 rule_id: ReUQnKg version_id: e1T42L1 url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit origin: community patterns: - pattern-inside: | jobs: ... - pattern: 'secrets: inherit' - id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age pattern-either: - patterns: - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) - metavariable-regex: metavariable: $TARGET regex: ^(?![\s\S]*minimumReleaseAge) - focus-metavariable: $TARGET - patterns: - pattern-regex: minimumReleaseAge\s*=\s*\d+ - pattern-regex: =\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 604800 - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ message: 'This bunfig.toml does not set a minimum release age or sets it too low. Newly published packages can be malicious or unstable. Add `minimumReleaseAge = 604800` under the `[install]` section to wait 7 days before resolving newly published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' languages: - generic severity: MEDIUM paths: include: - '**/bunfig.toml' - '**/.bunfig.toml' metadata: category: security technology: - bun - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://bun.sh/docs/runtime/bunfig license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age shortlink: https://sg.run/JqPrR semgrep.dev: rule: r_id: 291646 rv_id: 1423385 rule_id: oqUyJOb version_id: BjTyRe5 url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age origin: community - id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown pattern-either: - patterns: - pattern-inside: | updates: ... - pattern: | - package-ecosystem: $ECOSYSTEM ... - pattern-not: | - package-ecosystem: $ECOSYSTEM ... cooldown: ... ... - patterns: - pattern-inside: | updates: ... - pattern-regex: default-days\s*:\s*(?P\d+) - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-inside: | updates: ... - pattern: | cooldown: default-days: $DAYS - metavariable-regex: metavariable: $DAYS regex: ^\D - focus-metavariable: $DAYS message: 'This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' languages: - yaml severity: MEDIUM paths: include: - '**/.github/dependabot.yml' - '**/.github/dependabot.yaml' metadata: category: security technology: - dependabot cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown shortlink: https://sg.run/5WvGK semgrep.dev: rule: r_id: 291647 rv_id: 1423386 rule_id: zdUArOL version_id: DkTwEGl url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown origin: community - id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age pattern-either: - patterns: - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) - pattern-not-regex: min-release-age - focus-metavariable: $TARGET - patterns: - pattern-regex: min-release-age\s*=\s*\d+ - pattern-regex: =\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 7 - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)min-release-age\s*=\s*$ message: 'This .npmrc does not set a minimum release age or sets it too low. Newly published packages can be malicious or unstable. Add `min-release-age = 7` to wait 7 days before resolving newly published package versions. Added in: v11.10 Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' languages: - generic severity: MEDIUM paths: include: - '**/.npmrc' metadata: category: security technology: - npm - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ - https://github.com/npm/cli/pull/8965 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age shortlink: https://sg.run/GRo1z semgrep.dev: rule: r_id: 291648 rv_id: 1423387 rule_id: pKU6A82 version_id: WrT7LdL url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age origin: community - id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` to transitive dependencies from being installed from untrusted sources. Added in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern: | blockExoticSubdeps: $VAL - metavariable-regex: metavariable: $VAL regex: ^(?!true$).+ - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#blockexoticsubdeps license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies shortlink: https://sg.run/RrWRv semgrep.dev: rule: r_id: 291649 rv_id: 1423388 rule_id: 2ZUQEZ5 version_id: 0bTGnwj url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies origin: community - id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age message: 'This pnpm workspace configuration does not set a minimum release age. Newly published packages can be malicious or unstable. Add `minimumReleaseAge: 10080` (minutes) to wait at least seven days before installing newly published package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 10080 - focus-metavariable: $AGE - patterns: - pattern: | minimumReleaseAge: $AGE - metavariable-regex: metavariable: $AGE regex: ^\D - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age shortlink: https://sg.run/Aj0o0 semgrep.dev: rule: r_id: 291650 rv_id: 1423389 rule_id: X5Uwn1n version_id: K3TgxrW url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age origin: community - id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent malicious package updates from downgrading security settings. Added in: v10.21.0 Reference: https://pnpm.io/settings#trustpolicy' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern: | trustPolicy: $VAL - metavariable-regex: metavariable: $VAL regex: ^(?!no-downgrade$).+ - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy shortlink: https://sg.run/B2Kz7 semgrep.dev: rule: r_id: 291651 rv_id: 1423390 rule_id: j2U6J8N version_id: qkTvDQn url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy origin: community - id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age pattern-either: - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern-either: - pattern: | { ..., "matchPackageNames": [...], ... } - pattern: | { ..., "matchPackagePatterns": [...], ... } - pattern: | { ..., "matchDepTypes": [...], ... } - pattern-not: | { ..., "minimumReleaseAge": $AGE, ... } - pattern-not: | { ..., "minimumReleaseAge": false, ... } - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 7 - focus-metavariable: $AGE - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern: | "minimumReleaseAge": "$AGE" - metavariable-regex: metavariable: $AGE regex: ^(?!\d+ days?$) - focus-metavariable: $AGE message: 'This Renovate configuration does not set a minimum release age. Newly published packages can be malicious or unstable. Add `"minimumReleaseAge": "7 days"` within a `packageRules` entry to wait 7 days before proposing updates to newly published package versions. Set `"minimumReleaseAge": false` to set an exception for minimal release age for the package rule. Added in: v42' languages: - json severity: MEDIUM paths: include: - '**/renovate.json' - '**/renovate.json5' - '**/.renovaterc' - '**/.renovaterc.json' - '**/.renovaterc.json5' metadata: category: security technology: - renovate cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.renovatebot.com/configuration-options/#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age shortlink: https://sg.run/D8l2q semgrep.dev: rule: r_id: 291652 rv_id: 1443454 rule_id: 10UbQrX version_id: jQT1KAX url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age origin: community - id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown pattern-either: - patterns: - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) - metavariable-regex: metavariable: $TARGET regex: ^(?![\s\S]*exclude-newer) - focus-metavariable: $TARGET - patterns: - pattern-regex: exclude-newer\s*=\s*"(?P\d+) days?" - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" - metavariable-regex: metavariable: $VAL regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T) - focus-metavariable: $VAL message: 'This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' languages: - generic severity: MEDIUM paths: include: - '**/pyproject.toml' - '**/uv.toml' metadata: category: security technology: - uv - python cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown shortlink: https://sg.run/WeY0Z semgrep.dev: rule: r_id: 291653 rv_id: 1423392 rule_id: 9AUo6vE version_id: YDTwLle url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown origin: community - id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) - metavariable-regex: metavariable: $VAL regex: ^(?!['"]?\d+d['"]?$) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"` to wait 7 days before resolving newly published package versions. Added in: 4.10 Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' languages: - yaml severity: MEDIUM paths: include: - '**/.yarnrc.yml' metadata: category: security technology: - yarn - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate shortlink: https://sg.run/0gvNq semgrep.dev: rule: r_id: 291654 rv_id: 1423393 rule_id: yyUBeEz version_id: JdTnXlj url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate origin: community - id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`. Without a cooldown, Poetry may resolve newly published package versions that have not yet been vetted by the community. Supply chain attacks frequently involve publishing a malicious version of a popular package and waiting for it to be pulled in \u2014 most are detected and removed within days. Set `min-release-age = 7` under `[solver]` to require that package versions are at least 7 days old before they are considered during dependency resolution. Added in: v2.4.0" languages: - generic severity: MEDIUM paths: include: - '**/poetry.toml' - '**/config.toml' pattern-either: - pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z) - pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P"[^"]*"|[0-6](?:\s|#|$)|false) metadata: category: security technology: - poetry - python cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: MEDIUM likelihood: LOW impact: MEDIUM subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://python-poetry.org/docs/configuration/#solvermin-release-age license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age shortlink: https://sg.run/JqnYZ semgrep.dev: rule: r_id: 309390 rv_id: 1443453 rule_id: kxUjBPy version_id: X0TYPX6 url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age origin: community - id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown below 7 days) allows Bundler to resolve newly published gem versions immediately, before the community has had time to detect malicious releases. The May 2026 RubyGems supply-chain attack demonstrated that threat actors can push compromised gem versions and have them automatically pulled into builds within minutes. Add `cooldown: 7` to each public source declaration so Bundler ignores gem versions published within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org", cooldown: 7`). If you operate an internal or private registry where the supply-chain risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`; `bundle install` with an existing lockfile is unaffected.' languages: - ruby severity: MEDIUM paths: include: - '**/Gemfile' - '**/gems.rb' exclude: - '**/vendor/**' - '**/.bundle/**' pattern-either: - patterns: - pattern: source "...", ... - pattern-not: 'source "...", ..., cooldown: $N, ...' - patterns: - pattern: 'source "...", ..., cooldown: $N, ...' - metavariable-comparison: metavariable: $N comparison: $N > 0 and $N < 7 - focus-metavariable: $N metadata: category: security technology: - bundler - ruby cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: MEDIUM likelihood: LOW impact: MEDIUM subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown shortlink: https://sg.run/5Wlkl semgrep.dev: rule: r_id: 309391 rv_id: 1443455 rule_id: wdUzPbP version_id: 1QTEjAN url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown origin: community - id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell languages: - yaml message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote server is compromised or the URL is hijacked, an attacker can execute arbitrary code in your CI runner. Consider downloading the file first, verifying its checksum or signature, and then executing it." metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A03:2021 - Injection - A03:2025 - Injection references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ technology: - github-actions - bash - curl cwe2021-top25: true cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell shortlink: https://sg.run/GR8K1 semgrep.dev: rule: r_id: 309392 rv_id: 1443456 rule_id: x8UAgrE version_id: 9lT3zYb url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: bash metavariable: $SHELL patterns: - pattern-either: - pattern: curl ... | $CMD ... - pattern: wget ... | $CMD ... - metavariable-regex: metavariable: $CMD regex: ^(bash|sh|python3?|ruby|perl)$ severity: ERROR - id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret languages: - yaml message: "A secret is exposed in the workflow-level `env:` block, making it available to every job and step in this workflow \u2014 including any untrusted code run in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level `env:` so the secret is only available where it is actually needed." metadata: category: security cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow technology: - github-actions subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret shortlink: https://sg.run/Rrn12 semgrep.dev: rule: r_id: 309393 rv_id: 1443457 rule_id: OrUnq7z version_id: yeTqX9r url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret origin: community patterns: - pattern-inside: | env: ... - pattern-regex: \$\{\{\s*secrets\. - pattern-not-inside: 'jobs: ...' severity: WARNING - id: javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html message: Dynamically rendering arbitrary HTML on your website can be very dangerous because it can easily lead to XSS vulnerabilities. Only use HTML interpolation on trusted content and never on user-provided content. metadata: references: - https://vuejs.org/v2/guide/syntax.html#Raw-HTML category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' technology: - vue owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html shortlink: https://sg.run/0QEw semgrep.dev: rule: r_id: 9354 rv_id: 1263250 rule_id: 2ZUb2o version_id: PkTR3Kj url: https://semgrep.dev/playground/r/PkTR3Kj/javascript.vue.security.audit.xss.templates.avoid-v-html.avoid-v-html origin: community languages: - regex severity: WARNING paths: include: - '*.vue' pattern-regex: <[^<>]*v-html= - id: javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection message: If unverified user data can reach the `wkhtmltoimage` it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - wkhtmltoimage cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection shortlink: https://sg.run/KlDn semgrep.dev: rule: r_id: 9355 rv_id: 1263251 rule_id: X5U8yj version_id: JdTzx4D url: https://semgrep.dev/playground/r/JdTzx4D/javascript.wkhtmltoimage.security.audit.wkhtmltoimage-injection.wkhtmltoimage-injection origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | $WK = require('wkhtmltoimage'); ... - pattern-not-inside: | var $INPUT = "..."; ... - pattern: $WK.generate($INPUT,...) - pattern-not: $WK.generate("...",...) - id: javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection message: If unverified user data can reach the `wkhtmltopdf` it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - wkhtmltopdf cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection shortlink: https://sg.run/qx8O semgrep.dev: rule: r_id: 9356 rv_id: 1263252 rule_id: j2Uv58 version_id: 5PTo1xA url: https://semgrep.dev/playground/r/5PTo1xA/javascript.wkhtmltopdf.security.audit.wkhtmltopdf-injection.wkhtmltopdf-injection origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | $WK = require('wkhtmltopdf'); ... - pattern-not-inside: | var $INPUT = "..."; ... - pattern: $WK($INPUT,...) - pattern-not: $WK("...",...) - id: javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe message: If unverified user data can reach the XML Parser it can result in XML External or Internal Entity (XXE) Processing vulnerabilities metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' category: security technology: - xml2json cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW confidence: LOW references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe shortlink: https://sg.run/l27o semgrep.dev: rule: r_id: 9357 rv_id: 1263253 rule_id: 10UKpB version_id: GxTkeg8 url: https://semgrep.dev/playground/r/GxTkeg8/javascript.xml2json.security.audit.xml2json-xxe.xml2json-xxe origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern: | var $XML = require('xml2json'); ... $XML.toJson(...); - pattern-not: | var $XML = require('xml2json'); ... $XML.toJson("...",...); - pattern-not: |- var $XML = require('xml2json'); ... var $S = "..."; ... $XML.toJson($S,...); - id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement pattern: | { "Effect": "Allow", "Principal": "*", "Resource": [ ..., "=~/arn:aws:s3.*/", ... ], ... } message: Detected public S3 bucket policy. This policy allows anyone to access certain properties of or items in the bucket. Do not do this unless you will never have sensitive data inside the bucket. metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' references: - https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html category: security technology: - aws subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement shortlink: https://sg.run/Yv1d semgrep.dev: rule: r_id: 9358 rv_id: 1263255 rule_id: 9AU1br version_id: A8Tgdxq url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement origin: community severity: WARNING languages: - json - id: kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call message: A formatted or concatenated string was detected as input to a java.lang.Runtime call. This is dangerous if a variable is controlled by user input and could result in a command injection. Ensure your variables are not controlled by users or sufficiently sanitized. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#COMMAND_INJECTION. category: security technology: - kt references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call shortlink: https://sg.run/6nEK semgrep.dev: rule: r_id: 9359 rv_id: 1263259 rule_id: yyUnpo version_id: 0bTKzZ9 url: https://semgrep.dev/playground/r/0bTKzZ9/kotlin.lang.security.command-injection-formatted-runtime-call.command-injection-formatted-runtime-call origin: community severity: ERROR languages: - kt pattern-either: - pattern: $RUNTIME.exec($X + $Y) - pattern: $RUNTIME.exec(String.format(...)) - pattern: $RUNTIME.loadLibrary($X + $Y) - pattern: $RUNTIME.loadLibrary(String.format(...)) - id: kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTPONLY_COOKIE category: security technology: - kt references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly shortlink: https://sg.run/ox7X semgrep.dev: rule: r_id: 9360 rv_id: 1263260 rule_id: r6UrKQ version_id: K3TKkRO url: https://semgrep.dev/playground/r/K3TKkRO/kotlin.lang.security.cookie-missing-httponly.cookie-missing-httponly origin: community message: A cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie. Set the 'HttpOnly' flag by calling 'cookie.setHttpOnly(true);' severity: WARNING languages: - kt patterns: - pattern-not-inside: | $COOKIE.setValue("") ... - pattern-either: - pattern: $COOKIE.setHttpOnly(false) - patterns: - pattern-not-inside: | $COOKIE.setHttpOnly(...) ... - pattern: $RESPONSE.addCookie($COOKIE) - id: kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_COOKIE category: security technology: - kt references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - audit likelihood: LOW impact: LOW confidence: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag shortlink: https://sg.run/zv7n semgrep.dev: rule: r_id: 9361 rv_id: 1263261 rule_id: bwUw3j version_id: qkTR7r9 url: https://semgrep.dev/playground/r/qkTR7r9/kotlin.lang.security.cookie-missing-secure-flag.cookie-missing-secure-flag origin: community message: A cookie was detected without setting the 'secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'secure' flag by calling '$COOKIE.setSecure(true);' severity: WARNING languages: - kt patterns: - pattern-not-inside: | $COOKIE.setValue("") ... - pattern-either: - pattern: $COOKIE.setSecure(false) - patterns: - pattern-not-inside: | $COOKIE.setSecure(...) ... - pattern: $RESPONSE.addCookie($COOKIE) - id: ocaml.lang.compatibility.deprecated.deprecated-pervasives pattern: Pervasives.$X message: Pervasives is deprecated and will not be available after 4.10. Use Stdlib. languages: - ocaml severity: ERROR metadata: category: compatibility technology: - ocaml license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ocaml.lang.compatibility.deprecated.deprecated-pervasives shortlink: https://sg.run/dKe0 semgrep.dev: rule: r_id: 9378 rv_id: 945962 rule_id: 3qUP1E version_id: K3TJbDY url: https://semgrep.dev/playground/r/K3TJbDY/ocaml.lang.compatibility.deprecated.deprecated-pervasives origin: community