rules: - id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: The host for this proxy URL is dynamically determined. This can be dangerous if the host can be injected by an attacker because it may forcibly alter destination of the proxy. Consider hardcoding acceptable destinations and retrieving them with 'map' or something similar. metadata: source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md references: - https://nginx.org/en/docs/http/ngx_http_map_module.html category: security technology: - nginx confidence: MEDIUM cwe: - 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host shortlink: https://sg.run/ndpb semgrep.dev: rule: r_id: 9036 rv_id: 1262671 rule_id: GdU7yl version_id: kbTzG2j url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host origin: community pattern-either: - pattern: proxy_pass $SCHEME://$$HOST ...; - pattern: proxy_pass $$SCHEME://$$HOST ...; - id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: The protocol scheme for this proxy is dynamically determined. This can be dangerous if the scheme can be injected by an attacker because it may forcibly alter the connection scheme. Consider hardcoding a scheme for this proxy. metadata: cwe: - 'CWE-16: CWE CATEGORY: Configuration' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md category: security technology: - nginx confidence: MEDIUM owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme shortlink: https://sg.run/EkAo semgrep.dev: rule: r_id: 9037 rv_id: 1262672 rule_id: ReUg7n version_id: w8TRoAJ url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme origin: community pattern: proxy_pass $$SCHEME:// ...; - id: generic.nginx.security.header-injection.header-injection pattern: | location ... <$VARIABLE> ... { ... add_header ... $$VARIABLE ... } paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: ERROR message: 'The $$VARIABLE path parameter is added as a header in the response. This could allow an attacker to inject a newline and add a new header into the response. This is called HTTP response splitting. To fix, do not allow whitespace in the path parameter: ''[^\s]+''.' metadata: cwe: - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP Request/Response Splitting'')' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md - https://owasp.org/www-community/attacks/HTTP_Response_Splitting category: security technology: - nginx confidence: MEDIUM owasp: - A03:2021 - Injection - A05:2025 - Injection subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection shortlink: https://sg.run/7oj4 semgrep.dev: rule: r_id: 9038 rv_id: 1262673 rule_id: AbUz8p version_id: xyTjzNW url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection origin: community - id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version patterns: - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; - pattern-not: ssl_protocols TLSv1.2; - pattern-not: ssl_protocols TLSv1.3; - pattern: ssl_protocols ...; paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 and TLS1.3; older versions are known to be broken and are susceptible to attacks. Prefer use of TLSv1.2 or later. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ category: security technology: - nginx confidence: HIGH owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version shortlink: https://sg.run/gLKy semgrep.dev: rule: r_id: 9041 rv_id: 1262676 rule_id: WAUo9k version_id: vdT06O4 url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version origin: community - id: generic.nginx.security.missing-ssl-version.missing-ssl-version patterns: - pattern: server { ... listen $PORT ssl; ... } - pattern-not-inside: server { ... ssl_protocols ... } paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: This server configuration is missing the 'ssl_protocols' directive. By default, this server will use 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions older than TLSv1.2 are known to be broken. Explicitly specify 'ssl_protocols TLSv1.2 TLSv1.3' to use secure TLS versions. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ - https://nginx.org/en/docs/http/configuring_https_servers.html category: security technology: - nginx confidence: MEDIUM owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version shortlink: https://sg.run/3xzl semgrep.dev: rule: r_id: 9043 rv_id: 1262678 rule_id: KxUbeA version_id: ZRTKAle url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version origin: community - id: generic.nginx.security.request-host-used.request-host-used pattern-either: - pattern: $http_host - pattern: $host paths: include: - '*conf*' - '*nginx*' - '*vhost*' - '**/sites-available/*' - '**/sites-enabled/*' languages: - generic severity: WARNING message: '''$http_host'' and ''$host'' variables may contain a malicious value from attacker controlled ''Host'' request header. Use an explicitly configured host value or a allow list for validation.' metadata: cwe: - 'CWE-290: Authentication Bypass by Spoofing' references: - https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md - https://portswigger.net/web-security/host-header category: security technology: - nginx confidence: MEDIUM owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/generic.nginx.security.request-host-used.request-host-used shortlink: https://sg.run/4x3Z semgrep.dev: rule: r_id: 9044 rv_id: 1262680 rule_id: qNUjGg version_id: ExTExrN url: https://semgrep.dev/playground/r/ExTExrN/generic.nginx.security.request-host-used.request-host-used origin: community - id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key pattern-regex: rk_live_[0-9a-zA-Z]{24} languages: - regex message: Stripe Restricted API Key detected severity: ERROR metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json category: security technology: - secrets - stripe confidence: MEDIUM owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key shortlink: https://sg.run/ZvdL semgrep.dev: rule: r_id: 9079 rv_id: 1262900 rule_id: 5rUOWq version_id: K3TKkKj url: https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key origin: community - id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri patterns: - pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END - metavariable-regex: metavariable: $...USERNAME regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z - metavariable-regex: metavariable: $...PASSWORD regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32} - metavariable-regex: metavariable: $PROTOCOL regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*) languages: - generic message: Username and password in URI detected severity: ERROR metadata: owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go category: security technology: - secrets confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri shortlink: https://sg.run/8yA4 semgrep.dev: rule: r_id: 9084 rv_id: 1262903 rule_id: DbUple version_id: YDTZeZE url: https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri origin: community - id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly patterns: - pattern-not-inside: | &sessions.Options{ ..., HttpOnly: true, ..., } - pattern: | &sessions.Options{ ..., } message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by setting 'HttpOnly' to 'true' in the Options struct. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly shortlink: https://sg.run/4xJZ semgrep.dev: rule: r_id: 9088 rv_id: 1262911 rule_id: qNUj6g version_id: WrTqKqe url: https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly origin: community fix-regex: regex: (HttpOnly\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure patterns: - pattern-not-inside: | &sessions.Options{ ..., Secure: true, ..., } - pattern: | &sessions.Options{ ..., } message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in the Options struct. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure shortlink: https://sg.run/PJdE semgrep.dev: rule: r_id: 9089 rv_id: 1262912 rule_id: lBU9kw version_id: 0bTKzKk url: https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure origin: community fix-regex: regex: (Secure\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection metadata: cwe: - 'CWE-300: Channel Accessible by Non-Endpoint' references: - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption category: security technology: - grpc confidence: HIGH owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection shortlink: https://sg.run/J9yZ semgrep.dev: rule: r_id: 9090 rv_id: 1262916 rule_id: PeUZ4X version_id: YDTZeZB url: https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection origin: community message: 'Found an insecure gRPC connection using ''grpc.WithInsecure()''. This creates a connection without encryption to a gRPC server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Instead, establish a secure connection with an SSL certificate using the ''grpc.WithTransportCredentials()'' function. You can create a create credentials using a ''tls.Config{}'' struct with ''credentials.NewTLS()''. The final fix looks like this: ''grpc.WithTransportCredentials(credentials.NewTLS())''.' languages: - go severity: ERROR pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) fix-regex: regex: (.*)WithInsecure\(.*?\) replacement: \1WithTransportCredentials(credentials.NewTLS()) - id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection metadata: cwe: - 'CWE-300: Channel Accessible by Non-Endpoint' references: - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption category: security technology: - grpc confidence: HIGH owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection shortlink: https://sg.run/5Q5l semgrep.dev: rule: r_id: 9091 rv_id: 1262917 rule_id: JDUy0B version_id: 6xT2923 url: https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection origin: community message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. This allows for a connection without encryption to this server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Include credentials derived from an SSL certificate in order to create a secure gRPC connection. You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", "cert.key")'. languages: - go severity: ERROR mode: taint pattern-sinks: - requires: OPTIONS and not CREDS pattern: grpc.NewServer($OPT, ...) - requires: EMPTY_CONSTRUCTOR pattern: grpc.NewServer() pattern-sources: - label: OPTIONS pattern: grpc.ServerOption{ ... } - label: CREDS pattern: grpc.Creds(...) - label: EMPTY_CONSTRUCTOR pattern: grpc.NewServer() - id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm shortlink: https://sg.run/Gej1 semgrep.dev: rule: r_id: 9092 rv_id: 1262919 rule_id: 5rUOWQ version_id: zyTb2bz url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm origin: community languages: - go severity: ERROR patterns: - pattern-either: - pattern-inside: | import "github.com/golang-jwt/jwt" ... - pattern-inside: | import "github.com/dgrijalva/jwt-go" ... - pattern-either: - pattern: | jwt.SigningMethodNone - pattern: jwt.UnsafeAllowNoneSignatureType - id: go.jwt-go.security.jwt.hardcoded-jwt-key message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - jwt - secrets confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key shortlink: https://sg.run/Rod2 semgrep.dev: rule: r_id: 9093 rv_id: 1262920 rule_id: GdU7Ny version_id: pZT0305 url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key origin: community severity: WARNING languages: - go mode: taint pattern-sources: - patterns: - pattern-inside: | []byte("$F") pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $TOKEN.SignedString($F) - focus-metavariable: $F - id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` unless you know what you're doing This method parses the token but doesn't validate the signature. It's only ever useful in cases where you know the signature is valid (because it has been checked previously in the stack) and you want to extract values from it. metadata: cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: MEDIUM references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified shortlink: https://sg.run/Av66 semgrep.dev: rule: r_id: 9094 rv_id: 1262918 rule_id: ReUgJJ version_id: o5TbDbq url: https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified origin: community languages: - go severity: WARNING patterns: - pattern-inside: | import "github.com/dgrijalva/jwt-go" ... - pattern: | $JWT.ParseUnverified(...) - id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd patterns: - pattern-either: - patterns: - pattern: | exec.Cmd {...,Path: $CMD,...} - pattern-not: | exec.Cmd {...,Path: "...",...} - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $CMD = "..."; ... - patterns: - pattern: | exec.Cmd {...,Args: $ARGS,...} - pattern-not: | exec.Cmd {...,Args: []string{...},...} - pattern-not-inside: | $ARGS = []string{"...",...}; ... - pattern-not-inside: | $CMD = "..."; ... $ARGS = []string{$CMD,...}; ... - pattern-not-inside: | $CMD = exec.LookPath("..."); ... $ARGS = []string{$CMD,...}; ... - patterns: - pattern: | exec.Cmd {...,Args: []string{$CMD,...},...} - pattern-not: | exec.Cmd {...,Args: []string{"...",...},...} - pattern-not-inside: | $CMD,$ERR := exec.LookPath("..."); ... - pattern-not-inside: | $CMD = "..."; ... - patterns: - pattern-either: - pattern: | exec.Cmd {...,Args: []string{"=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$EXE,...},...} - patterns: - pattern: | exec.Cmd {...,Args: []string{$CMD,"-c",$EXE,...},...} - pattern-inside: | $CMD,$ERR := exec.LookPath("=~/(sh|bash|ksh|csh|tcsh|zsh)/"); ... - pattern-not: | exec.Cmd {...,Args: []string{"...","...","...",...},...} - pattern-not-inside: | $EXE = "..."; ... - pattern-inside: | import "os/exec" ... message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd shortlink: https://sg.run/Dorj semgrep.dev: rule: r_id: 9108 rv_id: 1262934 rule_id: 2ZUb8l version_id: e1Tyjeg url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd origin: community severity: ERROR languages: - go - id: go.lang.security.audit.crypto.bad_imports.insecure-module-used message: The package `net/http/cgi` is on the import blocklist. The package is vulnerable to httpoxy attacks (CVE-2015-5386). It is recommended to use `net/http` or a web framework to build a web application instead. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec references: - https://godoc.org/golang.org/x/crypto/sha3 category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used shortlink: https://sg.run/l2gj semgrep.dev: rule: r_id: 9113 rv_id: 1262921 rule_id: yyUnov version_id: 2KTv2vJ url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used origin: community languages: - go severity: WARNING pattern-either: - patterns: - pattern-inside: | import "net/http/cgi" ... - pattern: | cgi.$FUNC(...) - id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key message: Disabled host key verification detected. This allows man-in-the-middle attacks. Use the 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. See https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to learn more about the problem and how to fix it. metadata: cwe: - 'CWE-322: Key Exchange without Entity Authentication' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec references: - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key shortlink: https://sg.run/Yv6X semgrep.dev: rule: r_id: 9114 rv_id: 1262922 rule_id: r6UrW9 version_id: X0TzyzN url: https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key origin: community languages: - go severity: WARNING pattern: ssh.InsecureIgnoreHostKey() - id: go.lang.security.audit.crypto.math_random.math-random-used metadata: cwe: - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used shortlink: https://sg.run/6nK6 semgrep.dev: rule: r_id: 9115 rv_id: 1262923 rule_id: bwUwy8 version_id: jQTn5nj url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used origin: community message: Do not use `math/rand`. Use `crypto/rand` instead. languages: - go severity: WARNING patterns: - pattern-either: - pattern: | import $RAND "$MATH" - pattern: | import "$MATH" - metavariable-regex: metavariable: $MATH regex: ^(math/rand(\/v[0-9]+)*)$ - pattern-either: - pattern-inside: | ... rand.$FUNC(...) - pattern-inside: | ... $RAND.$FUNC(...) - focus-metavariable: - $MATH fix: | crypto/rand - id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion message: '`MinVersion` is missing from this TLS configuration. By default, as of Go 1.22, TLS 1.2 is currently used as the minimum. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer 10), it may be necessary to enable TLS 1.0 to provide support. Add `MinVersion: tls.VersionTLS13'' to the TLS configuration to bump the minimum version to TLS 1.3.' metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go references: - https://go.dev/doc/go1.22#minor_library_changes - https://pkg.go.dev/crypto/tls#:~:text=MinVersion - https://www.us-cert.gov/ncas/alerts/TA14-290A category: security technology: - go confidence: HIGH subcategory: - audit likelihood: MEDIUM impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion shortlink: https://sg.run/oxEN semgrep.dev: rule: r_id: 9116 rv_id: 1262924 rule_id: NbUk4X version_id: 1QTypyp url: https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion origin: community languages: - go severity: WARNING patterns: - pattern: | tls.Config{ $...CONF } - pattern-not: | tls.Config{..., MinVersion: ..., ...} fix: | tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 } - id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, SSLv3 will be removed. Instead, use 'tls.VersionTLS13'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go references: - https://golang.org/doc/go1.14#crypto/tls - https://www.us-cert.gov/ncas/alerts/TA14-290A category: security technology: - go confidence: HIGH subcategory: - vuln likelihood: MEDIUM impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure shortlink: https://sg.run/zvE1 semgrep.dev: rule: r_id: 9117 rv_id: 1262926 rule_id: kxUkJ2 version_id: yeTxpxj url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure origin: community languages: - go severity: WARNING fix-regex: regex: VersionSSL30 replacement: VersionTLS13 pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' - id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered weak. Use the function 'tls.CipherSuites()' to get a list of good cipher suites. See https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other cipher suites to use. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go references: - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites category: security technology: - go confidence: HIGH subcategory: - vuln likelihood: HIGH impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher shortlink: https://sg.run/px8N semgrep.dev: rule: r_id: 9118 rv_id: 1262927 rule_id: wdUJYk version_id: rxTAKAZ url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher origin: community languages: - go severity: WARNING pattern-either: - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...} - pattern: | tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...} - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 shortlink: https://sg.run/2xB5 semgrep.dev: rule: r_id: 9119 rv_id: 1262928 rule_id: x8Un6q version_id: bZT535Y url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 origin: community patterns: - pattern-inside: | import "crypto/md5" ... - pattern-either: - pattern: | md5.New() - pattern: | md5.Sum(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 shortlink: https://sg.run/XBYA semgrep.dev: rule: r_id: 9120 rv_id: 1262929 rule_id: OrU31O version_id: NdTzyz1 url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 origin: community patterns: - pattern-inside: | import "crypto/sha1" ... - pattern-either: - pattern: | sha1.New() - pattern: | sha1.Sum(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES message: Detected DES cipher algorithm which is insecure. The algorithm is considered weak and has been deprecated. Use AES instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES shortlink: https://sg.run/jREA semgrep.dev: rule: r_id: 9121 rv_id: 1262930 rule_id: eqU8B3 version_id: kbTzGzA url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES origin: community patterns: - pattern-inside: | import "crypto/des" ... - pattern-either: - pattern: | des.NewTripleDESCipher(...) - pattern: | des.NewCipher(...) - id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 message: Detected RC4 cipher algorithm which is insecure. The algorithm has many known vulnerabilities. Use AES instead. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://github.com/securego/gosec#available-rules category: security technology: - go references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 shortlink: https://sg.run/1ZAD semgrep.dev: rule: r_id: 9122 rv_id: 1262931 rule_id: v8Unl0 version_id: w8TRoRQ url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 origin: community patterns: - pattern-inside: | import "crypto/rc4" ... - pattern: rc4.NewCipher(...) - id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits languages: - go severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - go confidence: HIGH subcategory: - audit likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key shortlink: https://sg.run/9oY4 semgrep.dev: rule: r_id: 9123 rv_id: 1262932 rule_id: d8UjY3 version_id: xyTjz8L url: https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key origin: community patterns: - pattern-either: - pattern: | rsa.GenerateKey(..., $BITS) - pattern: | rsa.GenerateMultiPrimeKey(..., $BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048 - focus-metavariable: - $BITS fix: | 2048 - id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces message: Detected a network listener listening on 0.0.0.0 or an empty string. This could unexpectedly expose the server publicly as it binds to all available interfaces. Instead, specify another IP address that is not 0.0.0.0 nor the empty string. languages: - go severity: WARNING metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/securego/gosec category: security technology: - go confidence: HIGH references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces shortlink: https://sg.run/rdE0 semgrep.dev: rule: r_id: 9125 rv_id: 1262939 rule_id: nJUz3J version_id: ExTExoK url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces origin: community pattern-either: - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) - id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly patterns: - pattern-not-inside: | http.Cookie{ ..., HttpOnly: true, ..., } - pattern: | http.Cookie{ ..., } message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' flag by setting 'HttpOnly' to 'true' in the Cookie. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go - https://golang.org/src/net/http/cookie.go category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly shortlink: https://sg.run/b73e semgrep.dev: rule: r_id: 9126 rv_id: 1262940 rule_id: EwU2Z6 version_id: 7ZTE3BW url: https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly origin: community fix-regex: regex: (HttpOnly\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure patterns: - pattern-not-inside: | http.Cookie{ ..., Secure: true, ..., } - pattern: | http.Cookie{ ..., } message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' to 'true' in the Options struct. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go - https://golang.org/src/net/http/cookie.go category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure shortlink: https://sg.run/N4G7 semgrep.dev: rule: r_id: 9127 rv_id: 1262941 rule_id: 7KUQ8X version_id: LjTkgGE url: https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure origin: community fix-regex: regex: (Secure\s*:\s+)false replacement: \1true severity: WARNING languages: - go - id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace message: Detected a potentially dynamic ClientTrace. This occurred because semgrep could not find a static definition for '$TRACE'. Dynamic ClientTraces are dangerous because they deserialize function code to run when certain Request events occur, which could lead to code being run without your knowledge. Ensure that your ClientTrace is statically defined. metadata: cwe: - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://github.com/returntocorp/semgrep-rules/issues/518 category: security technology: - go confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace shortlink: https://sg.run/kXEK semgrep.dev: rule: r_id: 9128 rv_id: 1262942 rule_id: L1Uyjp version_id: 8KT5rNv url: https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace origin: community patterns: - pattern-not-inside: | package $PACKAGE ... &httptrace.ClientTrace { ... } ... - pattern: httptrace.WithClientTrace($ANY, $TRACE) severity: WARNING languages: - go - id: go.lang.security.audit.net.formatted-template-string.formatted-template-string message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' does not escape contents. Be absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may have a XSS vulnerability. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/pkg/html/template/#HTML category: security technology: - go confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string shortlink: https://sg.run/weE0 semgrep.dev: rule: r_id: 9129 rv_id: 1262943 rule_id: 8GUjDW version_id: gETB7Pe url: https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string origin: community languages: - go severity: WARNING patterns: - pattern-not: template.HTML("..." + "...") - pattern-either: - pattern: template.HTML($T + $X, ...) - pattern: template.HTML(fmt.$P("...", ...), ...) - pattern: | $T = "..." ... $T = $FXN(..., $T, ...) ... template.HTML($T, ...) - pattern: | $T = fmt.$P("...", ...) ... template.HTML($T, ...) - pattern: | $T, $ERR = fmt.$P("...", ...) ... template.HTML($T, ...) - pattern: | $T = $X + $Y ... template.HTML($T, ...) - pattern: |- $T = "..." ... $OTHER, $ERR = fmt.$P(..., $T, ...) ... template.HTML($OTHER, ...) - id: go.lang.security.audit.net.use-tls.use-tls pattern: http.ListenAndServe($ADDR, $HANDLER) fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://golang.org/pkg/net/http/#ListenAndServeTLS category: security technology: - go confidence: MEDIUM subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls shortlink: https://sg.run/dKbY semgrep.dev: rule: r_id: 9134 rv_id: 1262948 rule_id: PeUZ8X version_id: JdTzxkn url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls origin: community message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. languages: - go severity: WARNING - id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf patterns: - pattern-inside: | func $FUNC(..., $W http.ResponseWriter, ...) { ... var $TEMPLATE = "..." ... $W.Write([]byte(fmt.$PRINTF($TEMPLATE, ...)), ...) ... } - pattern-either: - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $INTERM = $ANYTHING(..., $DATA, ...) ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $INTERM = $DATA[...] ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $DATA, $ERR := r.URL.Query()[...] ... $INTERM = $DATA[...] ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $DATA, $ERR := r.URL.Query()[...] ... $INTERM = $ANYTHING(..., $DATA, ...) ... $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...))) - pattern: | $PARAMS = r.URL.Query() ... $DATA, $ERR := $PARAMS[...] ... $W.Write([]byte(fmt.$PRINTF(..., $DATA, ...))) message: Found data going from url query parameters into formatted data written to ResponseWriter. This could be XSS and should not be done. If you must do this, ensure your data is sanitized or escaped. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf shortlink: https://sg.run/Zvon semgrep.dev: rule: r_id: 9135 rv_id: 1262949 rule_id: JDUyXB version_id: 5PTo1qr url: https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf origin: community severity: WARNING languages: - go - id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures technology: - java - secrets - jwt category: security cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret shortlink: https://sg.run/RoDK semgrep.dev: rule: r_id: 9149 rv_id: 1262980 rule_id: oqUeAn version_id: d6Tyx8j url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret origin: community languages: - java severity: WARNING patterns: - pattern-either: - pattern: | (Algorithm $ALG) = $ALGO.$HMAC("$Y"); - pattern: | $SECRET = "$Y"; ... (Algorithm $ALG) = $ALGO.$HMAC($SECRET); - pattern: | class $CLASS { ... $TYPE $SECRET = "$Y"; ... $RETURNTYPE $FUNC (...) { ... (Algorithm $ALG) = $ALGO.$HMAC($SECRET); ... } ... } - focus-metavariable: $Y - metavariable-regex: metavariable: $HMAC regex: (HMAC384|HMAC256|HMAC512) - id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg shortlink: https://sg.run/Av14 semgrep.dev: rule: r_id: 9150 rv_id: 1262981 rule_id: zdUkzR version_id: ZRTKADq url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg origin: community languages: - java severity: ERROR pattern-either: - pattern: | $JWT.sign(com.auth0.jwt.algorithms.Algorithm.none()); - pattern: | $NONE = com.auth0.jwt.algorithms.Algorithm.none(); ... $JWT.sign($NONE); - pattern: |- class $CLASS { ... $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none(); ... $RETURNTYPE $FUNC (...) { ... $JWT.sign($NONE); ... } ... } - id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Call '.verify()' before using the token. metadata: cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt confidence: MEDIUM references: - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify shortlink: https://sg.run/Bk95 semgrep.dev: rule: r_id: 9151 rv_id: 1262979 rule_id: pKUOE9 version_id: vdT06Lp url: https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify origin: community languages: - java severity: WARNING patterns: - pattern: | com.auth0.jwt.JWT.decode(...); - pattern-not-inside: |- class $CLASS { ... $RETURNTYPE $FUNC (...) { ... $VERIFIER.verify(...); ... } } - id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN references: - https://www.owasp.org/index.php/Path_Traversal category: security technology: - jax-rs cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal shortlink: https://sg.run/DoWj semgrep.dev: rule: r_id: 9152 rv_id: 1262984 rule_id: 2ZUb9l version_id: 7ZTE3KW url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal origin: community message: Detected a potential path traversal. A malicious actor could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. severity: WARNING languages: - java pattern-either: - pattern: | $RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) { ... new File(..., $VAR, ...); ... } - pattern: |- $RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) { ... new File(..., $VAR, ...); ... } - id: java.jboss.security.session_sqli.find-sql-string-concatenation message: In $METHOD, $X is used to construct a SQL query via string concatenation. languages: - java severity: ERROR pattern-either: - pattern: | $RETURN $METHOD(...,String $X,...){ ... Session $SESSION = ...; ... String $QUERY = ... + $X + ...; ... PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); ... ResultSet $RESULT = $PS.executeQuery(); ... } - pattern: | $RETURN $METHOD(...,String $X,...){ ... String $QUERY = ... + $X + ...; ... Session $SESSION = ...; ... PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY); ... ResultSet $RESULT = $PS.executeQuery(); ... } metadata: category: security technology: - jboss confidence: MEDIUM cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation shortlink: https://sg.run/W8kA semgrep.dev: rule: r_id: 9153 rv_id: 1262986 rule_id: X5U8rQ version_id: 8KT5r3v url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation origin: community - id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN references: - https://www.owasp.org/index.php/Path_Traversal category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal shortlink: https://sg.run/oxXN semgrep.dev: rule: r_id: 9160 rv_id: 1263064 rule_id: NbUk7X version_id: zyTb2rq url: https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal origin: community message: Detected a potential path traversal. A malicious actor could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) - patterns: - pattern-inside: | $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...); ... - pattern: | $PARAM = $VALS[$INDEX]; pattern-sanitizers: - pattern: org.apache.commons.io.FilenameUtils.getName(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (java.io.File $FILE) = ... - pattern: | (java.io.FileOutputStream $FOS) = ... - pattern: | new java.io.FileInputStream(...) severity: ERROR languages: - java - id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization severity: WARNING languages: - java metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.3 Insecue Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization shortlink: https://sg.run/zvO1 semgrep.dev: rule: r_id: 9161 rv_id: 1263065 rule_id: kxUk12 version_id: pZT03A1 url: https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization origin: community message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling of the message payload when ObjectMessage.getObject() is called. Deserialization of untrusted data can lead to security flaws; a remote attacker could via a crafted JMS ObjectMessage to execute arbitrary code with the permissions of the application listening/consuming JMS Messages. In this case, the JMS MessageListener consume an ObjectMessage type received inside the onMessage method, which may lead to arbitrary code execution when calling the $Y.getObject method. patterns: - pattern-inside: | public class $JMS_LISTENER implements MessageListener { ... public void onMessage(Message $JMS_MSG) { ... } } - pattern-either: - pattern-inside: $X = $Y.getObject(...); - pattern-inside: $X = ($Z) $Y.getObject(...); - id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss message: 'Cross-site scripting detected in HttpServletResponse writer with variable ''$VAR''. User input was detected going directly from the HttpServletRequest into output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: ''Encode.forHtml($VAR)''.' metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss shortlink: https://sg.run/pxjN semgrep.dev: rule: r_id: 9162 rv_id: 1263066 rule_id: wdUJOk version_id: 2KTv2EG url: https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss origin: community severity: ERROR patterns: - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } - pattern-inside: $VAR = $REQ.getParameter(...); ... - pattern-either: - pattern: $RESP.getWriter(...).write(..., $VAR, ...); - pattern: | $WRITER = $RESP.getWriter(...); ... $WRITER.write(..., $VAR, ...); languages: - java - id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe shortlink: https://sg.run/XBwA semgrep.dev: rule: r_id: 9164 rv_id: 1263069 rule_id: OrU35O version_id: 1QTypQZ url: https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe origin: community message: XML external entities are not explicitly disabled for this XMLInputFactory. This could be vulnerable to XML external entity vulnerabilities. Explicitly disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" to false. patterns: - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, false); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.FALSE); ... } - pattern-not-inside: | $METHOD(...) { ... $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); ... } - pattern-either: - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) - pattern: new XMLInputFactory(...) languages: - java - id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size shortlink: https://sg.run/9o74 semgrep.dev: rule: r_id: 9167 rv_id: 1262989 rule_id: d8UjJ3 version_id: 3ZT4X2r url: https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size origin: community message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits or more, or switch to use AES instead. severity: WARNING languages: - java patterns: - pattern: | $KEYGEN = KeyGenerator.getInstance("Blowfish"); ... $KEYGEN.init($SIZE); - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 128 - id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A malicious actor could discern the difference between plaintext with valid or invalid padding. Further, CBC mode does not include any integrity checks. Use 'AES/GCM/NoPadding' instead. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE references: - https://capec.mitre.org/data/definitions/463.html - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY category: security technology: - java subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle shortlink: https://sg.run/ydxr semgrep.dev: rule: r_id: 9168 rv_id: 1262990 rule_id: ZqU5oD version_id: 44TEjbE url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle origin: community severity: WARNING fix: | "AES/GCM/NoPadding" languages: - java patterns: - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") - pattern: | "=~/.*\/CBC\/PKCS5Padding/" - id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs message: When data from an untrusted source is put into a logger and not neutralized correctly, an attacker could forge log entries or include malicious content. metadata: cwe: - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS category: security technology: - java references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs shortlink: https://sg.run/wek0 semgrep.dev: rule: r_id: 9173 rv_id: 1262995 rule_id: 8GUjwW version_id: RGT0LEr url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs origin: community severity: WARNING languages: - java patterns: - pattern-either: - patterns: - pattern-inside: | class $CLASS { ... Logger $LOG = ...; ... } - pattern-either: - pattern-inside: | $X $METHOD(...,HttpServletRequest $REQ,...) { ... } - pattern-inside: | $X $METHOD(...,ServletRequest $REQ,...) { ... } - pattern-inside: | $X $METHOD(...) { ... HttpServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... ServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... Logger $LOG = ...; ... HttpServletRequest $REQ = ...; ... } - pattern-inside: | $X $METHOD(...) { ... Logger $LOG = ...; ... ServletRequest $REQ = ...; ... } - pattern-either: - pattern: | String $VAL = $REQ.getParameter(...); ... $LOG.$LEVEL(<... $VAL ...>); - pattern: | String $VAL = $REQ.getParameter(...); ... $LOG.log($LEVEL,<... $VAL ...>); - pattern: | $LOG.$LEVEL(<... $REQ.getParameter(...) ...>); - pattern: | $LOG.log($LEVEL,<... $REQ.getParameter(...) ...>); - id: java.lang.security.audit.formatted-sql-string.formatted-sql-string metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.5 Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement category: security technology: - java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string shortlink: https://sg.run/OPXp semgrep.dev: rule: r_id: 9175 rv_id: 1409389 rule_id: QrUzxR version_id: ExTeyBP url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string origin: community options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | $ANNOT $FUNC (..., $INPUT, ...) { ... } - pattern: (String $INPUT) - focus-metavariable: $INPUT label: INPUT - patterns: - pattern-either: - pattern: $X + $INPUT - pattern: $X += $INPUT - pattern: String.format(..., $INPUT, ...) - pattern: String.join(..., $INPUT, ...) - pattern: (String $STR).concat($INPUT) - pattern: $INPUT.concat(...) - patterns: - pattern-either: - pattern: $STRB.append($INPUT) - pattern: new $STRB(..., $INPUT, ...) - metavariable-type: metavariable: $STRB type: StringBuilder label: CONCAT requires: INPUT pattern-propagators: - pattern: (StringBuffer $S).append($X) from: $X to: $S - pattern: (StringBuilder $S).append($X) from: $X to: $S pattern-sinks: - patterns: - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) - pattern-either: - pattern: (Statement $S).$SQLFUNC(...) - pattern: (PreparedStatement $P).$SQLFUNC(...) - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) - pattern: (EntityManager $EM).$SQLFUNC(...) - metavariable-regex: metavariable: $SQLFUNC regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare requires: CONCAT pattern-sanitizers: - patterns: - pattern: (CriteriaBuilder $CB).$ANY(...) severity: ERROR languages: - java - id: java.lang.security.audit.http-response-splitting.http-response-splitting metadata: cwe: - 'CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers (''HTTP Request/Response Splitting'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING references: - https://www.owasp.org/index.php/HTTP_Response_Splitting category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting shortlink: https://sg.run/eL0l semgrep.dev: rule: r_id: 9176 rv_id: 1263023 rule_id: 3qUPyK version_id: X0Tzykw url: https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting origin: community message: Older Java application servers are vulnerable to HTTP response splitting, which may occur if an HTTP request can be injected with CRLF characters. This finding is reported for completeness; it is recommended to ensure your environment is not affected by testing this yourself. severity: INFO languages: - java pattern-either: - pattern: | $VAR = $REQ.getParameter(...); ... $COOKIE = new Cookie(..., $VAR, ...); ... $RESP.addCookie($COOKIE, ...); - patterns: - pattern-inside: | $RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) { ... } - pattern: | $COOKIE = new Cookie(..., $VAR, ...); ... $RESP.addCookie($COOKIE, ...); - id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection metadata: cwe: - 'CWE-297: Improper Validation of Certificate with Host Mismatch' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL category: security technology: - java references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection shortlink: https://sg.run/vzN4 semgrep.dev: rule: r_id: 9177 rv_id: 1263024 rule_id: 4bUkrW version_id: jQTn5Dv url: https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection origin: community message: Insecure SMTP connection detected. This connection will trust any SSL certificate. Enable certificate verification by setting 'email.setSSLCheckServerIdentity(true)'. severity: WARNING patterns: - pattern-not-inside: | $EMAIL.setSSLCheckServerIdentity(true); ... - pattern-inside: | $EMAIL = new SimpleEmail(...); ... - pattern: $EMAIL.send(...); languages: - java - id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect message: Application redirects to a destination URL specified by a user-supplied parameter that is not validated. This could direct users to malicious locations. Consider using an allowlist to validate URLs. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.1.5 Open Redirect control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements version: '4' category: security technology: - java references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln impact: LOW likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect shortlink: https://sg.run/Q51P semgrep.dev: rule: r_id: 9186 rv_id: 1263048 rule_id: WAUo0p version_id: PkTR329 url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect origin: community severity: WARNING languages: - java pattern-either: - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... String $URL = $REQ.getParameter(...); ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... String $URL = $REQ.getParameter(...); ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,String $URL,...) { ... HttpServletResponse $RES = ...; ... $RES.sendRedirect($URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... $RES.sendRedirect($REQ.getParameter(...)); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... $RES.sendRedirect($REQ.getParameter(...)); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) { ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) { ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... String $URL = $REQ.getParameter(...); ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... String $URL = $REQ.getParameter(...); ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,String $URL,...) { ... HttpServletResponse $RES = ...; ... $RES.addHeader("Location",$URL); ... } - pattern: | $X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) { ... $RES.addHeader("Location",$REQ.getParameter(...)); ... } - pattern: |- $X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) { ... $RES.addHeader("Location",$REQ.getParameter(...)); ... } - id: java.lang.security.audit.weak-ssl-context.weak-ssl-context metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT references: - https://tools.ietf.org/html/rfc7568 - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html category: security technology: - java subcategory: - audit likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context shortlink: https://sg.run/4x7E semgrep.dev: rule: r_id: 9188 rv_id: 1263050 rule_id: KxUb1k version_id: 5PTo1rW url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context origin: community message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") for the best security. severity: WARNING languages: - java patterns: - pattern-not: SSLContext.getInstance("TLSv1.3") - pattern-not: SSLContext.getInstance("TLSv1.2") - pattern: SSLContext.getInstance("...") fix-regex: regex: (.*?)\.getInstance\(.*?\) replacement: \1.getInstance("TLSv1.2") - id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated message: DES is considered deprecated. AES is the recommended cipher. Upgrade to use AES. See https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard for more information. metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated shortlink: https://sg.run/5Q73 semgrep.dev: rule: r_id: 9191 rv_id: 1262996 rule_id: PeUZNg version_id: A8TgdEn url: https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated origin: community severity: WARNING patterns: - pattern-either: - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") - pattern-inside: $CIPHER.getInstance("DES") - pattern-either: - pattern: | "=~/DES/.*/" - pattern: | "DES" fix: | "AES/GCM/NoPadding" languages: - java - kt - id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended cipher. Upgrade to use AES. metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE references: - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated shortlink: https://sg.run/Geqn semgrep.dev: rule: r_id: 9192 rv_id: 1262997 rule_id: JDUy8J version_id: BjTkZyQ url: https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated origin: community severity: WARNING patterns: - pattern-either: - pattern: | $CIPHER.getInstance("=~/DESede.*/") - pattern: | $CRYPTO.KeyGenerator.getInstance("DES") languages: - java - kt - id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher shortlink: https://sg.run/Ro9K semgrep.dev: rule: r_id: 9193 rv_id: 1262998 rule_id: 5rUOb6 version_id: DkTRbwL url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher origin: community message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. severity: WARNING languages: - java patterns: - pattern: | Cipher $VAR = $CIPHER.getInstance($MODE); - metavariable-regex: metavariable: $MODE regex: .*ECB.* - id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher patterns: - pattern-either: - pattern: new NullCipher(...); - pattern: new javax.crypto.NullCipher(...); metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher shortlink: https://sg.run/AvA4 semgrep.dev: rule: r_id: 9194 rv_id: 1263001 rule_id: GdU7pw version_id: K3TKkgB url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher origin: community message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector message: Initialization Vectors (IVs) for block ciphers should be randomly generated each time they are used. Using a static IV means the same plaintext encrypts to the same ciphertext every time, weakening the strength of the encryption. metadata: cwe: - 'CWE-329: Generation of Predictable IV with CBC Mode' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cwe.mitre.org/data/definitions/329.html category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector shortlink: https://sg.run/BkB5 semgrep.dev: rule: r_id: 9195 rv_id: 1263002 rule_id: ReUgj1 version_id: qkTR7vP url: https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector origin: community severity: WARNING languages: - java pattern-either: - pattern: | byte[] $IV = { ... }; ... new IvParameterSpec($IV, ...); - pattern: | class $CLASS { byte[] $IV = { ... }; ... $METHOD(...) { ... new IvParameterSpec($IV, ...); ... } } - id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING references: - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java - kotlin subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding shortlink: https://sg.run/DoOj semgrep.dev: rule: r_id: 9196 rv_id: 1263003 rule_id: AbUzoj version_id: l4TJRpK url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding origin: community message: Using RSA without OAEP mode weakens the encryption. severity: WARNING languages: - java - kt pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") - id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket metadata: functional-categories: - net::search::crypto-config::java.net cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket shortlink: https://sg.run/W8zA semgrep.dev: rule: r_id: 9197 rv_id: 1263008 rule_id: BYUN3X version_id: RGT0LEj url: https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket origin: community message: Detected use of a Java socket that is not encrypted. As a result, the traffic could be read by an attacker intercepting the network traffic. Use an SSLSocket created by 'SSLSocketFactory' or 'SSLServerSocketFactory' instead. severity: WARNING languages: - java pattern-either: - pattern: new ServerSocket(...) - pattern: new Socket(...) - id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits based on NIST recommendation. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::key-length::java.security cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - java subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key shortlink: https://sg.run/4x6x semgrep.dev: rule: r_id: 9200 rv_id: 1263019 rule_id: 0oU5P5 version_id: o5TbDLY url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key origin: community patterns: - pattern: | KeyPairGenerator $KEY = $G.getInstance("RSA"); ... $KEY.initialize($BITS); - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048 - id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer message: Detected a request with potential user-input going into a OutputStream or Writer object. This bypasses any view or template environments, including HTML escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. Consider using a view technology such as JavaServer Faces (JSFs) which automatically escapes HTML views. severity: WARNING options: interfile: true metadata: likelihood: HIGH impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' cwe2021-top25: true cwe2022-top25: true owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html subcategory: - vuln technology: - java - servlets interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer shortlink: https://sg.run/KlRL semgrep.dev: rule: r_id: 9211 rv_id: 1263055 rule_id: j2Uv7B version_id: DkTRbXy url: https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer origin: community languages: - java mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ).$REQFUNC(...) - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" - metavariable-regex: metavariable: $REQFUNC regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) pattern-sinks: - patterns: - pattern-either: - pattern: | (HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...) - pattern: | (HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...) - pattern: | (java.io.PrintWriter $WRITER).$WRITE(...) - pattern: | (PrintWriter $WRITER).$WRITE(...) - pattern: | (javax.servlet.ServletOutputStream $WRITER).$WRITE(...) - pattern: | (ServletOutputStream $WRITER).$WRITE(...) - pattern: | (java.io.OutputStream $WRITER).$WRITE(...) - pattern: | (OutputStream $WRITER).$WRITE(...) pattern-sanitizers: - pattern-either: - pattern: Encode.forHtml(...) - pattern: (PolicyFactory $POLICY).sanitize(...) - pattern: (AntiSamy $AS).scan(...) - pattern: JSoup.clean(...) - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) - id: java.spring.security.audit.spring-sqli.spring-sqli mode: taint pattern-sources: - patterns: - pattern: $ARG - pattern-inside: | public $T $M (..., String $ARG,...){...} pattern-sanitizers: - not_conflicting: true pattern-either: - patterns: - focus-metavariable: $A - pattern-inside: | new $TYPE(...,$A,...); pattern-sinks: - patterns: - pattern-either: - patterns: - focus-metavariable: $A - pattern: | new PreparedStatementCreatorFactory($A,...); - patterns: - focus-metavariable: $A - pattern: | (JdbcTemplate $T).$M($A,...) - patterns: - pattern: (String $A) - pattern-inside: | (JdbcTemplate $T).batchUpdate(...) - patterns: - focus-metavariable: $A - pattern: | NamedParameterBatchUpdateUtils.$M($A,...) - patterns: - focus-metavariable: $A - pattern: | BatchUpdateUtils.$M($A,...) message: Detected a string argument from a public method contract in a raw SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. languages: - java severity: WARNING options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - spring owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli shortlink: https://sg.run/1Z3x semgrep.dev: rule: r_id: 9222 rv_id: 1263082 rule_id: eqU8N2 version_id: ZRTKAWW url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli origin: community - id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect message: Application redirects a user to a destination URL specified by a user supplied parameter that is not validated. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT category: security technology: - spring references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect shortlink: https://sg.run/9oXz semgrep.dev: rule: r_id: 9223 rv_id: 1263083 rule_id: v8Un7w version_id: nWT2Lk0 url: https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect origin: community severity: WARNING languages: - java pattern-either: - pattern: | $X $METHOD(...,String $URL,...) { return "redirect:" + $URL; } - pattern: | $X $METHOD(...,String $URL,...) { ... String $REDIR = "redirect:" + $URL; ... return $REDIR; ... } - pattern: | $X $METHOD(...,String $URL,...) { ... new ModelAndView("redirect:" + $URL); ... } - pattern: |- $X $METHOD(...,String $URL,...) { ... String $REDIR = "redirect:" + $URL; ... new ModelAndView($REDIR); ... } - id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) in an AngularJS application could provide additional attack surface for XSS vulnerabilities. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://docs.angularjs.org/api/ng/service/$sce - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angular owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled shortlink: https://sg.run/N4DG semgrep.dev: rule: r_id: 9227 rv_id: 1263094 rule_id: EwU20Z version_id: 5PTo1EW url: https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled origin: community languages: - javascript - typescript severity: ERROR pattern: | $sceProvider.enabled(false); - id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method message: The use of $sce.trustAs can be dangerous if unsanitized user input flows through this API. metadata: references: - https://docs.angularjs.org/api/ng/service/$sce - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' technology: - angular owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method shortlink: https://sg.run/OPW2 semgrep.dev: rule: r_id: 9231 rv_id: 1263098 rule_id: gxU1QX version_id: BjTkZv0 url: https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | app.controller(..., function($scope,$sce) { ... }); - pattern: $scope.$X pattern-sinks: - pattern: $sce.trustAs(...) - pattern: $sce.trustAsHtml(...) - id: javascript.browser.security.open-redirect.js-open-redirect message: The application accepts potentially user-controlled input `$PROP` which can control the location of the current window context. This can lead two types of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) with JavaScript URIs. It is recommended to validate user-controllable input before allowing it to control the redirection. options: interfile: true metadata: interfile: true cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.1 Insecue Redirect control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation version: '4' category: security confidence: HIGH references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html technology: - browser subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect shortlink: https://sg.run/3xRe semgrep.dev: rule: r_id: 9243 rv_id: 1263122 rule_id: WAUopl version_id: pZT03x0 url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | new URLSearchParams($WINDOW. ... .location.search).get('...') - pattern: | new URLSearchParams(location.search).get('...') - pattern: | new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') - pattern: | new URLSearchParams(location.hash.substring(1)).get('...') - patterns: - pattern-either: - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.search) ... - pattern-inside: | $PROPS = new URLSearchParams(location.search) ... - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) ... - pattern-inside: | $PROPS = new URLSearchParams(location.hash.substring(1)) ... - pattern: $PROPS.get('...') - patterns: - pattern-either: - pattern-inside: | $PROPS = new URL($WINDOW. ... .location.href) ... - pattern-inside: | $PROPS = new URL(location.href) ... - pattern: $PROPS.searchParams.get('...') - patterns: - pattern-either: - pattern: | new URL($WINDOW. ... .location.href).searchParams.get('...') - pattern: | new URL(location.href).searchParams.get('...') pattern-sinks: - patterns: - pattern-either: - pattern: location.href = $SINK - pattern: $THIS. ... .location.href = $SINK - pattern: location.replace($SINK) - pattern: $THIS. ... .location.replace($SINK) - pattern: location = $SINK - pattern: $WINDOW. ... .location = $SINK - focus-metavariable: $SINK - metavariable-pattern: patterns: - pattern-not: | "..." + $VALUE - pattern-not: | `...${$VALUE}` metavariable: $SINK - id: javascript.browser.security.raw-html-concat.raw-html-concat message: User controlled data in a HTML string may result in XSS metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/xss/ category: security technology: - browser cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat shortlink: https://sg.run/4xAx semgrep.dev: rule: r_id: 9244 rv_id: 1263123 rule_id: 0oU5b5 version_id: 2KTv2wp url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: location.href - pattern: location.hash - pattern: location.search - pattern: $WINDOW. ... .location.href - pattern: $WINDOW. ... .location.hash - pattern: $WINDOW. ... .location.search pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $STRING + $EXPR - pattern-not: $STRING + "..." - metavariable-pattern: patterns: - pattern: <$TAG ... - pattern-not: <$TAG ...>...... metavariable: $STRING language: generic - patterns: - pattern: $EXPR + $STRING - pattern-not: '"..." + $STRING' - metavariable-pattern: patterns: - pattern: '... {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $XML = require('node-expat') ... - pattern-inside: | import $XML from 'node-expat' ... - pattern-inside: | import * as $XML from 'node-expat' ... - pattern-either: - pattern-inside: | $PARSER = new $XML.Parser(...); ... - pattern-either: - pattern: $PARSER.parse($QUERY) - pattern: $PARSER.write($QUERY) - focus-metavariable: $QUERY - id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: interfile: true cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - express - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret shortlink: https://sg.run/Do1d semgrep.dev: rule: r_id: 9252 rv_id: 1263166 rule_id: pKUOjy version_id: pZT03Q0 url: https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern-inside: | $JWT = require('express-jwt'); ... - pattern-inside: | import $JWT from 'express-jwt'; ... - pattern-inside: | import * as $JWT from 'express-jwt'; ... - pattern-inside: | import { ..., $JWT, ... } from 'express-jwt'; ... - pattern-either: - pattern: | $JWT({...,secret: "$Y",...},...) - pattern: | $OPTS = "$Y"; ... $JWT({...,secret: $OPTS},...); - focus-metavariable: $Y - id: javascript.express.security.express-phantom-injection.express-phantom-injection message: If unverified user data can reach the `phantom` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://phantomjs.org/page-automation.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection shortlink: https://sg.run/W8BL semgrep.dev: rule: r_id: 9253 rv_id: 1263167 rule_id: 2ZUbx3 version_id: 2KTv26p url: https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('phantom'); ... - pattern-inside: | import 'phantom'; ... - pattern-either: - pattern: $PAGE.open($SINK,...) - pattern: $PAGE.setContent($SINK,...) - pattern: $PAGE.openUrl($SINK,...) - pattern: $PAGE.evaluateJavaScript($SINK,...) - pattern: $PAGE.property("content",$SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection message: If unverified user data can reach the `puppeteer` methods it can result in Server-Side Request Forgery vulnerabilities metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' category: security technology: - express references: - https://pptr.dev/api/puppeteer.page cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection shortlink: https://sg.run/0QJB semgrep.dev: rule: r_id: 9254 rv_id: 1263168 rule_id: X5U8Nz version_id: X0TzyJY url: https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('puppeteer'); ... - pattern-inside: | import 'puppeteer'; ... - pattern-either: - pattern: $PAGE.goto($SINK,...) - pattern: $PAGE.setContent($SINK,...) - pattern: $PAGE.evaluate($SINK,...) - pattern: $PAGE.evaluate($CODE,$SINK,...) - pattern: $PAGE.evaluateHandle($SINK,...) - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) - pattern: $PAGE.evaluateOnNewDocument($SINK,...) - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection message: Make sure that unverified user data can not reach `sandbox`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection shortlink: https://sg.run/KlwL semgrep.dev: rule: r_id: 9255 rv_id: 1263169 rule_id: j2UvXB version_id: jQTn59D url: https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | $SANDBOX = require('sandbox'); ... - pattern-either: - patterns: - pattern-inside: | $S = new $SANDBOX(...); ... - pattern: | $S.run(...) - pattern: | new $SANDBOX($OPTS).run(...) - pattern: new $SANDBOX().run(...) - id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or Internal Entity (XXE) Processing vulnerabilities metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' category: security technology: - express references: - https://www.npmjs.com/package/xml2json cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe shortlink: https://sg.run/XBD4 semgrep.dev: rule: r_id: 9264 rv_id: 1263174 rule_id: x8Uneb version_id: bZT534J url: https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('xml2json'); ... - pattern-inside: | import 'xml2json'; ... - pattern: $EXPAT.toJson($SINK,...) - focus-metavariable: $SINK - id: javascript.express.security.require-request.require-request message: If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on the server. options: interfile: true metadata: interfile: true owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html category: security technology: - express references: - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/javascript.express.security.require-request.require-request shortlink: https://sg.run/jRbl semgrep.dev: rule: r_id: 9265 rv_id: 1263177 rule_id: OrU3WK version_id: w8TRo0d url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern: require($SINK) - focus-metavariable: $SINK - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name message: "Don\u2019t use the default session cookie name Using the default session cookie name can open your app to attacks. The security issue posed is similar to X-Powered-By: a potential attacker can use it to fingerprint the server and target attacks accordingly." severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name shortlink: https://sg.run/1Z5x semgrep.dev: rule: r_id: 9266 rv_id: 1263130 rule_id: eqU8k2 version_id: bZT536J url: https://semgrep.dev/playground/r/bZT536J/javascript.express.security.audit.express-cookie-settings.express-cookie-session-default-name origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {name:...} ...>,...) - pattern-not-inside: | $OPTS = <... {name:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.name = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure message: 'Default session middleware settings: `secure` not set. It ensures the browser only sends the cookie over HTTPS.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure shortlink: https://sg.run/9oKz semgrep.dev: rule: r_id: 9267 rv_id: 1263131 rule_id: v8Unzw version_id: NdTzyrv url: https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{secure:true}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {secure:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {secure:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.secure = true; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.secure = true; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly message: 'Default session middleware settings: `httpOnly` not set. It ensures the cookie is sent only over HTTP(S), not client JavaScript, helping to protect against cross-site scripting attacks.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly shortlink: https://sg.run/ydBO semgrep.dev: rule: r_id: 9268 rv_id: 1263132 rule_id: d8UjGo version_id: kbTzGev url: https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{httpOnly:true}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {httpOnly:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {httpOnly:true} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.httpOnly = true; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.httpOnly = true; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain message: 'Default session middleware settings: `domain` not set. It indicates the domain of the cookie; use it to compare against the domain of the server in which the URL is being requested. If they match, then check the path attribute next.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain shortlink: https://sg.run/rd41 semgrep.dev: rule: r_id: 9269 rv_id: 1263133 rule_id: ZqU5Pn version_id: w8TRoyd url: https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{domain:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {domain:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {domain:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.domain = ...; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.domain = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path message: 'Default session middleware settings: `path` not set. It indicates the path of the cookie; use it to compare against the request path. If this and domain match, then send the cookie in the request.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path shortlink: https://sg.run/b7pd semgrep.dev: rule: r_id: 9270 rv_id: 1263134 rule_id: nJUz4X version_id: xyTjzQD url: https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{path:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {path:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {path:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.path = ...; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie.path = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires message: 'Default session middleware settings: `expires` not set. Use it to set expiration date for persistent cookies.' severity: WARNING languages: - javascript - typescript metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires shortlink: https://sg.run/N4eG semgrep.dev: rule: r_id: 9271 rv_id: 1263135 rule_id: EwU2DZ version_id: O9TpxRq url: https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires origin: community patterns: - pattern-either: - pattern-inside: | $SESSION = require('cookie-session'); ... - pattern-inside: | $SESSION = require('express-session'); ... - pattern: $SESSION(...) - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) - pattern-not-inside: | $OPTS = <... {cookie:{expires:...}} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE = <... {expires:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $OPTS.cookie = <... {expires:...} ...>; ... $SESSION($OPTS,...); - pattern-not-inside: | $OPTS = ...; ... $COOKIE.expires = ...; ... $SESSION($OPTS,...); - pattern-not-inside: |- $OPTS = ...; ... $OPTS.cookie.expires = ...; ... $SESSION($OPTS,...); - id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked message: No token revoking configured for `express-jwt`. A leaked token could still be used and unable to be revoked. Consider using function as the `isRevoked` option. metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.3 Insecure Stateless Session Tokens control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - express cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A04_2021-Insecure_Design license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked shortlink: https://sg.run/kXNo semgrep.dev: rule: r_id: 9272 rv_id: 1263137 rule_id: 7KUQ9k version_id: vdT06Bg url: https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | $JWT = require('express-jwt'); ... - pattern: $JWT(...) - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) - pattern-not-inside: |- $OPTS = <... {isRevoked:...} ...>; ... $JWT($OPTS,...); - id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal message: Possible writing outside of the destination, make sure that the target path is nested in the intended destination metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' category: security references: - https://owasp.org/www-community/attacks/Path_Traversal technology: - express - node.js cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal shortlink: https://sg.run/weRn semgrep.dev: rule: r_id: 9273 rv_id: 1263141 rule_id: L1Uyb8 version_id: ExTExX0 url: https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern-inside: | $PATH = require('path'); ... - pattern-inside: | import $PATH from 'path'; ... - pattern-either: - pattern: $PATH.join(...,$SINK,...) - pattern: $PATH.resolve(...,$SINK,...) - patterns: - focus-metavariable: $SINK - pattern-inside: | import 'path'; ... - pattern-either: - pattern: path.join(...,$SINK,...) - pattern: path.resolve(...,$SINK,...) pattern-sanitizers: - pattern: $Y.replace(...) - pattern: $Y.indexOf(...) - pattern: | function ... (...) { ... <... $Y.indexOf(...) ...> ... } - patterns: - pattern: $FUNC(...) - metavariable-regex: metavariable: $FUNC regex: sanitize - id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event message: Xml Parser is used inside Request Event. Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or Internal Entity (XXE) Processing vulnerabilities metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' category: security technology: - express references: - https://www.npmjs.com/package/xml2json cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event shortlink: https://sg.run/x1AA semgrep.dev: rule: r_id: 9274 rv_id: 1263146 rule_id: 8GUjkk version_id: QkTGqgo url: https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('xml2json'); ... - pattern-inside: | import 'xml2json'; ... - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) - focus-metavariable: $INPUT - id: javascript.express.security.audit.res-render-injection.res-render-injection message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to the loading of other HTML/templating pages that they may not be authorized to render. An attacker may attempt to use directory traversal techniques e.g. `../folder/index` to access other HTML pages on the file system. Where possible, do not allow users to define what should be loaded in $RES.render or use an allow list for the existing application. options: interfile: true metadata: interfile: true owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' category: security technology: - express references: - http://expressjs.com/en/4x/api.html#res.render subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection shortlink: https://sg.run/eLjd semgrep.dev: rule: r_id: 9276 rv_id: 1263149 rule_id: QrUzrq version_id: PkTR3OY url: https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.render($SINK, ...) - focus-metavariable: $SINK - id: javascript.express.security.audit.xss.direct-response-write.direct-response-write message: Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML. options: interfile: true metadata: interfile: true references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM vulnerability_class: - Cross-Site-Scripting (XSS) license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write shortlink: https://sg.run/vzGl semgrep.dev: rule: r_id: 9277 rv_id: 1263150 rule_id: 3qUPA1 version_id: JdTzxeg url: https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options) - pattern-not-inside: | function ... ($REQ, $RES) { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | $APP.$METHOD(..., function $FUNC($REQ, $RES) { ... $RES.$SET('Content-Type', '$TYPE') }) - pattern-not-inside: | function ... ($REQ, $RES, $NEXT) { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | function ... ($REQ, $RES) { ... $RES.set('$TYPE') } - pattern-not-inside: | $APP.$METHOD(..., function $FUNC($REQ, $RES) { ... $RES.set('$TYPE') }) - pattern-not-inside: | function ... ($REQ, $RES, $NEXT) { ... $RES.set('$TYPE') } - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - pattern-not-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | ({ $REQ }: Request,$RES: Response) => { ... $RES.$SET('Content-Type', '$TYPE') } - pattern-not-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => { ... $RES.set('$TYPE') } - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: body pattern-sinks: - patterns: - pattern-inside: function ... (..., $RES,...) {...} - pattern-either: - pattern: $RES.write($ARG) - pattern: $RES.send($ARG) - pattern-not: $RES. ... .set('...'). ... .send($ARG) - pattern-not: $RES. ... .type('...'). ... .send($ARG) - pattern-not-inside: $RES.$METHOD({ ... }) - focus-metavariable: $ARG pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'express-xss-sanitizer'; ... - pattern-inside: | import * as $S from "express-xss-sanitizer"; ... - pattern-inside: | const { ..., $S, ... } = require('express-xss-sanitizer'); ... - pattern-inside: | var { ..., $S, ... } = require('express-xss-sanitizer'); ... - pattern-inside: | let { ...,$S,... } = require('express-xss-sanitizer'); ... - pattern-inside: | $S = require("express-xss-sanitizer") ... - pattern: $S(...) - patterns: - pattern: $RES. ... .type('$F'). ... .send(...) - metavariable-regex: metavariable: $F regex: (?!.*text/html) - patterns: - pattern-inside: | $X = [...]; ... - pattern: | if(<... !$X.includes($SOURCE)...>) { ... return ... } ... - pattern: $SOURCE - id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: interfile: true cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.2 Static API keys or secret control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jose - jwt - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret shortlink: https://sg.run/Ro1g semgrep.dev: rule: r_id: 9293 rv_id: 1263182 rule_id: JDUyRl version_id: d6TyxbX url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-inside: | $JOSE = require("jose"); ... - pattern-either: - pattern-inside: | var {JWT} = $JOSE; ... - pattern-inside: | var {JWK, JWT} = $JOSE; ... - pattern-inside: | const {JWT} = $JOSE; ... - pattern-inside: | const {JWK, JWT} = $JOSE; ... - pattern-inside: | let {JWT} = $JOSE; ... - pattern-inside: | let {JWK, JWT} = $JOSE; ... - pattern-either: - pattern: | JWT.verify($P, "...", ...); - pattern: | JWT.sign($P, "...", ...); - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" - pattern: | $JWT.sign($P, JWK.asKey("..."), ...); options: symbolic_propagation: true interfile: true - id: javascript.jose.security.jwt-none-alg.jwt-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.3 Insecue Stateless Session Tokens control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jose - jwt subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg shortlink: https://sg.run/AvRL semgrep.dev: rule: r_id: 9294 rv_id: 1263183 rule_id: 5rUOGN version_id: ZRTKAyb url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg origin: community languages: - javascript - typescript severity: ERROR pattern-either: - pattern: | var $JOSE = require("jose"); ... var { JWK, JWT } = $JOSE; ... var $T = JWT.verify($P, JWK.None,...); - pattern: | var $JOSE = require("jose"); ... var { JWK, JWT } = $JOSE; ... $T = JWT.verify($P, JWK.None,...); - pattern: | var $JOSE = require("jose"); ... var { JWK, JWT } = $JOSE; ... JWT.verify($P, JWK.None,...); - id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.2 Static API keys or secret control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jwt - javascript - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret shortlink: https://sg.run/4xN9 semgrep.dev: rule: r_id: 9300 rv_id: 1263189 rule_id: WAUon7 version_id: gETB75D url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern: "$X = '...' \n" - pattern: "$X = '$Y' \n" - patterns: - pattern-either: - pattern-inside: | $JWT.sign($DATA,"...",...); - pattern-inside: | $JWT.verify($DATA,"...",...); pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $JWT = require("jsonwebtoken") ... - pattern-inside: | import $JWT from "jsonwebtoken" ... - pattern-inside: | import * as $JWT from "jsonwebtoken" ... - pattern-inside: | import {...,$JWT,...} from "jsonwebtoken" ... - pattern-either: - pattern-inside: | $JWT.sign($DATA,$VALUE,...); - pattern-inside: | $JWT.verify($DATA,$VALUE,...); - focus-metavariable: $VALUE - id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.3 Insecue Stateless Session Tokens control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jwt subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg shortlink: https://sg.run/PJXv semgrep.dev: rule: r_id: 9301 rv_id: 1263190 rule_id: 0oU53g version_id: QkTGqQo url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern-inside: | $JWT = require("jsonwebtoken"); ... - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) - id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression message: Detected use of dynamic execution of JavaScript which may come from user-input, which can lead to Cross-Site-Scripting (XSS). Where possible avoid including user-input in functions which dynamically execute user-input. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection source-rule-url: https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js references: - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval! category: security technology: - javascript subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression shortlink: https://sg.run/6nwK semgrep.dev: rule: r_id: 9315 rv_id: 1263214 rule_id: yyUngo version_id: WrTqKkJ url: https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $PROP = new URLSearchParams($WINDOW. ... .location.search).get('...') ... - pattern-inside: | $PROP = new URLSearchParams(location.search).get('...') ... - pattern-inside: | $PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...') ... - pattern-inside: | $PROP = new URLSearchParams(location.hash.substring(1)).get('...') ... - focus-metavariable: $PROP - patterns: - pattern-either: - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.search) ... - pattern-inside: | $PROPS = new URLSearchParams(location.search) ... - pattern-inside: | $PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1)) ... - pattern-inside: | $PROPS = new URLSearchParams(location.hash.substring(1)) ... - pattern: $PROPS.get('...') - focus-metavariable: $PROPS - patterns: - pattern-either: - pattern: location.href - pattern: location.hash - pattern: location.search - pattern: $WINDOW. ... .location.href - pattern: $WINDOW. ... .location.hash - pattern: $WINDOW. ... .location.search pattern-sinks: - patterns: - pattern-either: - pattern: eval(<... $SINK ...>) - pattern: window.eval(<... $SINK ...>) - pattern: new Function(<... $SINK ...>) - pattern: new Function(<... $SINK ...>)(...) - pattern: setTimeout(<... $SINK ...>,...) - pattern: setInterval(<... $SINK ...>,...) - focus-metavariable: $SINK pattern-sanitizers: - patterns: - pattern-either: - pattern: location.href = $FUNC(...) - pattern: location.hash = $FUNC(...) - pattern: location.search = $FUNC(...) - pattern: $WINDOW. ... .location.href = $FUNC(...) - pattern: $WINDOW. ... .location.hash = $FUNC(...) - pattern: $WINDOW. ... .location.search = $FUNC(...) - id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures asvs: section: 'V3: Session Management Verification Requirements' control_id: 3.5.2 Static API keys or secret control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management version: '4' category: security technology: - jwt - nodejs - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret shortlink: https://sg.run/vz70 semgrep.dev: rule: r_id: 9333 rv_id: 1263225 rule_id: QrUzq6 version_id: X0TzyoE url: https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | {..., clientSecret: "...", ...} - pattern: | {..., secretOrKey: "...", ...} - pattern: | {..., consumerSecret: "...", ...} - patterns: - pattern-inside: | $OBJ = {} ... - pattern-either: - pattern: | $OBJ.clientSecret = "..." - pattern: | $OBJ.secretOrKey = "..." - pattern: | $OBJ.consumerSecret = "..." - pattern: $OBJ - patterns: - pattern-inside: | $SECRET = '...' ... - pattern-either: - pattern: | {..., clientSecret: $SECRET, ...} - pattern: | {..., secretOrKey: $SECRET, ...} - pattern: | {..., consumerSecret: $SECRET, ...} - patterns: - pattern-inside: | $SECRET = '...' ... - pattern-either: - pattern-inside: | $VALUE = {..., clientSecret: $SECRET, ...} ... - pattern-inside: | $VALUE = {..., secretOrKey: $SECRET, ...} ... - pattern-inside: | $VALUE = {..., consumerSecret: $SECRET, ...} ... - pattern: $VALUE pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $F = require("$I").Strategy ... - pattern-inside: | $F = require("$I") ... - pattern-inside: | import { $STRAT as $F } from '$I' ... - pattern-inside: | import $F from '$I' ... - metavariable-regex: metavariable: $I regex: (passport-.*) - pattern-inside: | new $F($VALUE,...) - focus-metavariable: $VALUE - id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement pattern: | { "Effect": "Allow", "Principal": "*", "Resource": [ ..., "=~/arn:aws:s3.*/", ... ], ... } message: Detected public S3 bucket policy. This policy allows anyone to access certain properties of or items in the bucket. Do not do this unless you will never have sensitive data inside the bucket. metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' references: - https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html category: security technology: - aws subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement shortlink: https://sg.run/Yv1d semgrep.dev: rule: r_id: 9358 rv_id: 1263255 rule_id: 9AU1br version_id: A8Tgdxq url: https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement origin: community severity: WARNING languages: - json - id: php.lang.security.assert-use.assert-use mode: taint pattern-sources: - pattern-either: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER - patterns: - pattern: | Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... }) - focus-metavariable: $ARG pattern-sinks: - patterns: - pattern: assert($SINK, ...); - pattern-not: assert("...", ...); - pattern: $SINK message: Calling assert with user input is equivalent to eval'ing. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' references: - https://www.php.net/manual/en/function.assert - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php category: security technology: - php confidence: HIGH subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use shortlink: https://sg.run/3xXW semgrep.dev: rule: r_id: 9387 rv_id: 1263272 rule_id: DbUpjk version_id: 9lT4bLx url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use origin: community languages: - php severity: ERROR - id: php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off patterns: - pattern-either: - pattern: | $ARG = $IS_VERIFIED; ... curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $ARG); - pattern: curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $IS_VERIFIED) - metavariable-regex: metavariable: $IS_VERIFIED regex: 0|false|null message: SSL verification is disabled but should not be (currently CURLOPT_SSL_VERIFYPEER= $IS_VERIFIED) metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://www.saotn.org/dont-turn-off-curlopt_ssl_verifypeer-fix-php-configuration/ category: security technology: - php owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off shortlink: https://sg.run/PJqv semgrep.dev: rule: r_id: 9389 rv_id: 1263277 rule_id: 0oU5Xg version_id: kbTzG9b url: https://semgrep.dev/playground/r/kbTzG9b/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off origin: community languages: - php severity: ERROR - id: php.lang.security.phpinfo-use.phpinfo-use pattern: phpinfo(...); message: The 'phpinfo' function may reveal sensitive information about your environment. metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' references: - https://www.php.net/manual/en/function.phpinfo - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/PhpinfosSniff.php category: security technology: - php owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/php.lang.security.phpinfo-use.phpinfo-use shortlink: https://sg.run/W82E semgrep.dev: rule: r_id: 9397 rv_id: 1263298 rule_id: ReUglY version_id: RGT0LN0 url: https://semgrep.dev/playground/r/RGT0LN0/php.lang.security.phpinfo-use.phpinfo-use origin: community languages: - php severity: ERROR - id: python.boto3.security.hardcoded-token.hardcoded-token message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html - https://bento.dev/checks/boto3/hardcoded-access-token/ - https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/ owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - boto3 - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token shortlink: https://sg.run/LwQ6 semgrep.dev: rule: r_id: 9439 rv_id: 1263347 rule_id: 5rUOwK version_id: gETB78n url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token origin: community languages: - python severity: WARNING mode: taint pattern-sources: - pattern: | "..." pattern-sinks: - patterns: - pattern-either: - pattern: $W(...,$TOKEN="$VALUE",...) - pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...) - metavariable-regex: metavariable: $TOKEN regex: (aws_session_token|aws_access_key_id|aws_secret_access_key) - metavariable-pattern: language: generic metavariable: $VALUE patterns: - pattern-either: - pattern-regex: ^AKI - pattern-regex: ^[A-Za-z0-9/+=]+$ - metavariable-analysis: metavariable: $VALUE analyzer: entropy - id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea message: IDEA (International Data Encryption Algorithm) is a block cipher created in 1991. It is an optional component of the OpenPGP standard. This cipher is susceptible to attacks when using weak keys. It is recommended that you do not use this cipher for new applications. Use a strong symmetric cipher such as EAS instead. With the `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://tools.ietf.org/html/rfc5469 - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea shortlink: https://sg.run/3xyK semgrep.dev: rule: r_id: 9443 rv_id: 1263350 rule_id: BYUNPg version_id: 44TEjNJ url: https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY) - metavariable-regex: metavariable: $IDEA regex: ^(IDEA)$ - focus-metavariable: $IDEA fix: AES - id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb message: ECB (Electronic Code Book) is the simplest mode of operation for block ciphers. Each block of data is encrypted in the same way. This means identical plaintext blocks will always result in identical ciphertext blocks, which can leave significant patterns in the output. Use a different, cryptographically strong mode instead, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B305 references: - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes - https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption category: security technology: - cryptography subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM functional-categories: - crypto::search::mode::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb shortlink: https://sg.run/4xr5 semgrep.dev: rule: r_id: 9444 rv_id: 1263351 rule_id: DbUp5g version_id: PkTR3w7 url: https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb origin: community severity: WARNING languages: - python pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV) fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV) - id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 patterns: - pattern: cryptography.hazmat.primitives.hashes.$SHA(...) - metavariable-pattern: metavariable: $SHA pattern: | SHA1 - focus-metavariable: $SHA fix: | SHA256 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B303 references: - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1 - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - cryptography subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 shortlink: https://sg.run/J9Qy semgrep.dev: rule: r_id: 9446 rv_id: 1263353 rule_id: 0oU5dN version_id: 5PTo1l0 url: https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 origin: community severity: WARNING languages: - python - id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size patterns: - pattern-either: - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(..., key_size=$SIZE, ...) - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 2048 - focus-metavariable: $SIZE fix: | 2048 message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py references: - https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/ - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::key-length::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size shortlink: https://sg.run/5Qb0 semgrep.dev: rule: r_id: 9447 rv_id: 1263354 rule_id: KxUb0x version_id: GxTkeOK url: https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size origin: community languages: - python severity: WARNING - id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size patterns: - pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...) - pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE - metavariable-pattern: metavariable: $SIZE pattern-either: - pattern: SECP192R1 - pattern: SECT163K1 - pattern: SECT163R2 - focus-metavariable: $SIZE fix: | SECP256R1 message: Detected an insufficient curve size for EC. NIST recommends a key size of 224 or higher. For example, use 'ec.SECP256R1'. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves category: security technology: - cryptography subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::key-length::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size shortlink: https://sg.run/GeQq semgrep.dev: rule: r_id: 9448 rv_id: 1263355 rule_id: qNUjZ3 version_id: RGT0LW6 url: https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size origin: community languages: - python severity: WARNING - id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size patterns: - pattern-either: - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(..., key_size=$SIZE, ...) - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP, $SIZE, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 2048 - focus-metavariable: $SIZE fix: | 2048 message: Detected an insufficient key size for RSA. NIST recommends a key size of 2048 or higher. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py references: - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/ - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf category: security technology: - cryptography subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::key-length::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size shortlink: https://sg.run/RoQq semgrep.dev: rule: r_id: 9449 rv_id: 1263356 rule_id: lBU9jn version_id: A8TgdPK url: https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size origin: community languages: - python severity: WARNING - id: python.distributed.security.require-encryption patterns: - pattern: | distributed.security.Security(..., require_encryption=$VAL, ...) - metavariable-pattern: metavariable: $VAL pattern: | False - focus-metavariable: $VAL fix: | True message: Initializing a security context for Dask (`distributed`) without "require_encryption" keyword argument may silently fail to provide security. severity: WARNING metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters category: security technology: - distributed subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.distributed.security.require-encryption shortlink: https://sg.run/AvQ2 semgrep.dev: rule: r_id: 9450 rv_id: 1263358 rule_id: YGURy0 version_id: DkTRbol url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption origin: community languages: - python - id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://docs.python.org/3/library/pickle.html category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization shortlink: https://sg.run/9oyr semgrep.dev: rule: r_id: 9467 rv_id: 1409400 rule_id: OrU3e6 version_id: GxTlb9e url: https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization origin: community message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`, `cpickle`, `dill`, `shelve`, or `yaml`, which are known to lead to remote code execution vulnerabilities. languages: - python severity: ERROR mode: taint pattern-sources: - pattern-either: - patterns: - pattern-inside: | def $INSIDE(..., $PARAM, ...): ... - pattern-either: - pattern: request.$REQFUNC(...) - pattern: request.$REQFUNC.get(...) - pattern: request.$REQFUNC[...] pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern: | pickle.$PICKLEFUNC(...) - pattern: | _pickle.$PICKLEFUNC(...) - pattern: | cPickle.$PICKLEFUNC(...) - pattern: | shelve.$PICKLEFUNC(...) - metavariable-regex: metavariable: $PICKLEFUNC regex: dumps|dump|load|loads - patterns: - pattern: dill.$DILLFUNC(...) - metavariable-regex: metavariable: $DILLFUNC regex: dump|dump_session|dumps|load|load_session|loads - patterns: - pattern: yaml.$YAMLFUNC(...) - pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...) - pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...) - pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...) - pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...) - metavariable-regex: metavariable: $YAMLFUNC regex: dump|dump_all|load|load_all - id: python.django.security.injection.open-redirect.open-redirect message: Data from request ($DATA) is passed to redirect(). This is an open redirect and could be exploited. Ensure you are redirecting to safe URLs by using django.utils.http.is_safe_url(). See https://cwe.mitre.org/data/definitions/601.html for more information. metadata: cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/ - https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231 category: security technology: - django subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect shortlink: https://sg.run/Ave2 semgrep.dev: rule: r_id: 9494 rv_id: 1263393 rule_id: PeUZgr version_id: 3ZT4XD7 url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-not-inside: | def $FUNC(...): ... django.utils.http.is_safe_url(...) ... - pattern-not-inside: | def $FUNC(...): ... if <... django.utils.http.is_safe_url(...) ...>: ... - pattern-not-inside: | def $FUNC(...): ... django.utils.http.url_has_allowed_host_and_scheme(...) ... - pattern-not-inside: | def $FUNC(...): ... if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>: ... - pattern-either: - pattern: django.shortcuts.redirect(..., request.$W.get(...), ...) - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...) - pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) - pattern: | $DATA = request.$W.get(...) ... django.shortcuts.redirect(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.shortcuts.redirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.shortcuts.redirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.shortcuts.redirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...) - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...) - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) - pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...) - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...) - pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) - pattern: django.shortcuts.redirect(..., request.$W(...), ...) - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...) - pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) - pattern: | $DATA = request.$W(...) ... django.shortcuts.redirect(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.shortcuts.redirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.shortcuts.redirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.shortcuts.redirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...) - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...) - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) - pattern: return django.shortcuts.redirect(..., request.$W(...), ...) - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...) - pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) - pattern: django.shortcuts.redirect(..., request.$W[...], ...) - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...) - pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) - pattern: | $DATA = request.$W[...] ... django.shortcuts.redirect(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.shortcuts.redirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.shortcuts.redirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.shortcuts.redirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...) - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...) - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) - pattern: return django.shortcuts.redirect(..., request.$W[...], ...) - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...) - pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) - pattern: django.shortcuts.redirect(..., request.$W, ...) - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) - pattern: django.shortcuts.redirect(..., $S % request.$W, ...) - pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...) - pattern: | $DATA = request.$W ... django.shortcuts.redirect(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.shortcuts.redirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.shortcuts.redirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.shortcuts.redirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.shortcuts.redirect(..., $INTERM, ...) - pattern: $A = django.shortcuts.redirect(..., request.$W, ...) - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) - pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...) - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...) - pattern: return django.shortcuts.redirect(..., request.$W, ...) - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) - pattern: return django.shortcuts.redirect(..., $S % request.$W, ...) - pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...) - pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...) - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseRedirect(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseRedirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseRedirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) - pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) - pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...) - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseRedirect(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseRedirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseRedirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) - pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) - pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...) - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseRedirect(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseRedirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseRedirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) - pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...) - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) - pattern: django.http.HttpResponseRedirect(..., request.$W, ...) - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) - pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...) - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseRedirect(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseRedirect(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseRedirect(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseRedirect(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.http.HttpResponseRedirect(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...) - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) - pattern: return django.http.HttpResponseRedirect(..., request.$W, ...) - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...) - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) - metavariable-regex: metavariable: $W regex: (?!get_full_path) - id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse message: Found user-controlled request data passed into HttpResponse. This could be vulnerable to XSS, leading to attackers gaining access to user cookies and protected information. Ensure that the request data is properly escaped or sanitzed. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse shortlink: https://sg.run/BkvA semgrep.dev: rule: r_id: 9495 rv_id: 1263398 rule_id: JDUydR version_id: GxTke5K url: https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...) - pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...) - pattern: django.http.HttpResponse(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponse(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponse(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponse(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponse(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...) - pattern: return django.http.HttpResponse(..., request.$W.get(...), ...) - pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...), ...) - pattern: django.http.HttpResponse(..., $S % request.$W(...), ...) - pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...) - pattern: django.http.HttpResponse(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponse(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponse(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponse(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponse(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: $A = django.http.HttpResponse(..., request.$W(...), ...) - pattern: return django.http.HttpResponse(..., request.$W(...), ...) - pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...), ...) - pattern: django.http.HttpResponse(..., $S % request.$W[...], ...) - pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...) - pattern: django.http.HttpResponse(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponse(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponse(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponse(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponse(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: $A = django.http.HttpResponse(..., request.$W[...], ...) - pattern: return django.http.HttpResponse(..., request.$W[...], ...) - pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...) - pattern: django.http.HttpResponse(..., $S % request.$W, ...) - pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...) - pattern: django.http.HttpResponse(..., request.$W, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponse(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponse(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponse(..., f"...{$DATA}...", ...) - pattern: $A = django.http.HttpResponse(..., request.$W, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... $A = django.http.HttpResponse(..., $INTERM, ...) - pattern: return django.http.HttpResponse(..., request.$W, ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponse(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponse(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.http.HttpResponse(..., $INTERM, ...) - id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest message: Found user-controlled request data passed into a HttpResponseBadRequest. This could be vulnerable to XSS, leading to attackers gaining access to user cookies and protected information. Ensure that the request data is properly escaped or sanitzed. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest shortlink: https://sg.run/DoZP semgrep.dev: rule: r_id: 9496 rv_id: 1263399 rule_id: 5rUOX1 version_id: RGT0LY6 url: https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...) - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...", ...) - pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseBadRequest(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) - pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...), ...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...) - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...", ...) - pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseBadRequest(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...) - pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...], ...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...) - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...", ...) - pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseBadRequest(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...) - pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...) - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W, ...), ...) - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...) - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...) - pattern: django.http.HttpResponseBadRequest(..., request.$W, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseBadRequest(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseBadRequest(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseBadRequest(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.http.HttpResponseBadRequest(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.http.HttpResponseBadRequest(..., $INTERM, ...) - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...) - pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...) - id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse message: Found user-controlled request data being passed into a file open, which is them passed as an argument into the FileResponse. This is dangerous because an attacker could specify an arbitrary file to read, which could result in leaking important data. Be sure to validate or sanitize the user-inputted filename in the request data before using it in FileResponse. metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse shortlink: https://sg.run/W862 semgrep.dev: rule: r_id: 9497 rv_id: 1263400 rule_id: GdU7QR version_id: A8Tgd1K url: https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: django.http.FileResponse(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.http.FileResponse(..., open($DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = open($DATA, ...) ... django.http.FileResponse(..., $INTERM, ...) - pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...) - pattern: return django.http.FileResponse(..., request.$W.get(...), ...) - pattern: django.http.FileResponse(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.http.FileResponse(..., open($DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = open($DATA, ...) ... django.http.FileResponse(..., $INTERM, ...) - pattern: $A = django.http.FileResponse(..., request.$W(...), ...) - pattern: return django.http.FileResponse(..., request.$W(...), ...) - pattern: django.http.FileResponse(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.http.FileResponse(..., open($DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = open($DATA, ...) ... django.http.FileResponse(..., $INTERM, ...) - pattern: $A = django.http.FileResponse(..., request.$W[...], ...) - pattern: return django.http.FileResponse(..., request.$W[...], ...) - pattern: django.http.FileResponse(..., request.$W, ...) - pattern: | $DATA = request.$W ... django.http.FileResponse(..., open($DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = open($DATA, ...) ... django.http.FileResponse(..., $INTERM, ...) - pattern: $A = django.http.FileResponse(..., request.$W, ...) - pattern: return django.http.FileResponse(..., request.$W, ...) - id: python.django.security.injection.request-data-write.request-data-write message: Found user-controlled request data passed into '.write(...)'. This could be dangerous if a malicious actor is able to control data into sensitive files. For example, a malicious actor could force rolling of critical log files, or cause a denial-of-service by using up available disk space. Instead, ensure that request data is properly escaped or sanitized. metadata: cwe: - 'CWE-93: Improper Neutralization of CRLF Sequences (''CRLF Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - django references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write shortlink: https://sg.run/0Q6j semgrep.dev: rule: r_id: 9498 rv_id: 1263401 rule_id: ReUg5z version_id: BjTkZO5 url: https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write origin: community languages: - python severity: WARNING pattern-either: - pattern: $F.write(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... $F.write(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $F.write(..., $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $B.$C(..., $DATA, ...) ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $F.write(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $F.write(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... $F.write(..., $INTERM, ...) - pattern: $A = $F.write(..., request.$W.get(...), ...) - pattern: return $F.write(..., request.$W.get(...), ...) - pattern: $F.write(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... $F.write(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $F.write(..., $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $B.$C(..., $DATA, ...) ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $F.write(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $F.write(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... $F.write(..., $INTERM, ...) - pattern: $A = $F.write(..., request.$W(...), ...) - pattern: return $F.write(..., request.$W(...), ...) - pattern: $F.write(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... $F.write(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $F.write(..., $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $B.$C(..., $DATA, ...) ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $F.write(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $F.write(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... $F.write(..., $INTERM, ...) - pattern: $A = $F.write(..., request.$W[...], ...) - pattern: return $F.write(..., request.$W[...], ...) - pattern: $F.write(..., request.$W, ...) - pattern: | $DATA = request.$W ... $F.write(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $F.write(..., $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $B.$C(..., $DATA, ...) ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $F.write(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... $F.write(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $F.write(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... $F.write(..., $INTERM, ...) - pattern: $A = $F.write(..., request.$W, ...) - pattern: return $F.write(..., request.$W, ...) - id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute remote code. See https://owasp.org/www-community/attacks/Code_Injection for more information. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html category: security technology: - django subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string shortlink: https://sg.run/4x2z semgrep.dev: rule: r_id: 9500 rv_id: 1263383 rule_id: BYUNw9 version_id: vdT06xG url: https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string origin: community patterns: - pattern-inside: | def $F(...): ... - pattern-either: - pattern: eval(..., $STR % request.$W.get(...), ...) - pattern: | $V = request.$W.get(...) ... eval(..., $STR % $V, ...) - pattern: | $V = request.$W.get(...) ... $S = $STR % $V ... eval(..., $S, ...) - pattern: eval(..., "..." % request.$W(...), ...) - pattern: | $V = request.$W(...) ... eval(..., $STR % $V, ...) - pattern: | $V = request.$W(...) ... $S = $STR % $V ... eval(..., $S, ...) - pattern: eval(..., $STR % request.$W[...], ...) - pattern: | $V = request.$W[...] ... eval(..., $STR % $V, ...) - pattern: | $V = request.$W[...] ... $S = $STR % $V ... eval(..., $S, ...) - pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...) - pattern: | $V = request.$W.get(...) ... eval(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W.get(...) ... $S = $STR.format(..., $V, ...) ... eval(..., $S, ...) - pattern: eval(..., $STR.format(..., request.$W(...), ...), ...) - pattern: | $V = request.$W(...) ... eval(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W(...) ... $S = $STR.format(..., $V, ...) ... eval(..., $S, ...) - pattern: eval(..., $STR.format(..., request.$W[...], ...), ...) - pattern: | $V = request.$W[...] ... eval(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W[...] ... $S = $STR.format(..., $V, ...) ... eval(..., $S, ...) - pattern: | $V = request.$W.get(...) ... eval(..., f"...{$V}...", ...) - pattern: | $V = request.$W.get(...) ... $S = f"...{$V}..." ... eval(..., $S, ...) - pattern: | $V = request.$W(...) ... eval(..., f"...{$V}...", ...) - pattern: | $V = request.$W(...) ... $S = f"...{$V}..." ... eval(..., $S, ...) - pattern: | $V = request.$W[...] ... eval(..., f"...{$V}...", ...) - pattern: | $V = request.$W[...] ... $S = f"...{$V}..." ... eval(..., $S, ...) languages: - python severity: WARNING - id: python.django.security.injection.code.user-eval.user-eval message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library for the specific functionality you need. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html - https://owasp.org/www-community/attacks/Code_Injection category: security technology: - django subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval shortlink: https://sg.run/PJDW semgrep.dev: rule: r_id: 9501 rv_id: 1263384 rule_id: DbUpDQ version_id: d6Tyx2A url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval origin: community patterns: - pattern-inside: | def $F(...): ... - pattern-either: - pattern: eval(..., request.$W.get(...), ...) - pattern: | $V = request.$W.get(...) ... eval(..., $V, ...) - pattern: eval(..., request.$W(...), ...) - pattern: | $V = request.$W(...) ... eval(..., $V, ...) - pattern: eval(..., request.$W[...], ...) - pattern: | $V = request.$W[...] ... eval(..., $V, ...) languages: - python severity: WARNING - id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library for the specific functionality you need. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - django references: - https://owasp.org/www-community/attacks/Code_Injection subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string shortlink: https://sg.run/J9JW semgrep.dev: rule: r_id: 9502 rv_id: 1263385 rule_id: WAUovx version_id: ZRTKA1p url: https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string origin: community patterns: - pattern-inside: | def $F(...): ... - pattern-either: - pattern: exec(..., $STR % request.$W.get(...), ...) - pattern: | $V = request.$W.get(...) ... exec(..., $STR % $V, ...) - pattern: | $V = request.$W.get(...) ... $S = $STR % $V ... exec(..., $S, ...) - pattern: exec(..., "..." % request.$W(...), ...) - pattern: | $V = request.$W(...) ... exec(..., $STR % $V, ...) - pattern: | $V = request.$W(...) ... $S = $STR % $V ... exec(..., $S, ...) - pattern: exec(..., $STR % request.$W[...], ...) - pattern: | $V = request.$W[...] ... exec(..., $STR % $V, ...) - pattern: | $V = request.$W[...] ... $S = $STR % $V ... exec(..., $S, ...) - pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...) - pattern: | $V = request.$W.get(...) ... exec(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W.get(...) ... $S = $STR.format(..., $V, ...) ... exec(..., $S, ...) - pattern: exec(..., $STR.format(..., request.$W(...), ...), ...) - pattern: | $V = request.$W(...) ... exec(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W(...) ... $S = $STR.format(..., $V, ...) ... exec(..., $S, ...) - pattern: exec(..., $STR.format(..., request.$W[...], ...), ...) - pattern: | $V = request.$W[...] ... exec(..., $STR.format(..., $V, ...), ...) - pattern: | $V = request.$W[...] ... $S = $STR.format(..., $V, ...) ... exec(..., $S, ...) - pattern: | $V = request.$W.get(...) ... exec(..., f"...{$V}...", ...) - pattern: | $V = request.$W.get(...) ... $S = f"...{$V}..." ... exec(..., $S, ...) - pattern: | $V = request.$W(...) ... exec(..., f"...{$V}...", ...) - pattern: | $V = request.$W(...) ... $S = f"...{$V}..." ... exec(..., $S, ...) - pattern: | $V = request.$W[...] ... exec(..., f"...{$V}...", ...) - pattern: | $V = request.$W[...] ... $S = f"...{$V}..." ... exec(..., $S, ...) - pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...), ...), ...) - pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...) - pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...), ...) - pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...) - pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...), ...), ...), ...), ...) - pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...), ...), ...) - pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...", ...), ...), ...) - pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...), ...) - pattern: | $DATA = request.$W.get(...) ... exec(..., base64.decodestring($DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = base64.decodestring($DATA, ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = base64.decodestring(bytes($DATA, ...), ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... exec(..., base64.decodestring($DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = base64.decodestring($DATA, ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = base64.decodestring(bytes($DATA, ...), ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... exec(..., base64.decodestring($DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = base64.decodestring($DATA, ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = base64.decodestring(bytes($DATA, ...), ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W ... exec(..., base64.decodestring($DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = base64.decodestring($DATA, ...) ... exec(..., $INTERM, ...) - pattern: | $DATA = request.$W ... exec(..., base64.decodestring(bytes($DATA, ...), ...), ...) - pattern: | $DATA = request.$W ... $INTERM = base64.decodestring(bytes($DATA, ...), ...) ... exec(..., $INTERM, ...) languages: - python severity: WARNING - id: python.django.security.injection.code.user-exec.user-exec message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library for the specific functionality you need. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - django references: - https://owasp.org/www-community/attacks/Code_Injection subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec shortlink: https://sg.run/5Q3X semgrep.dev: rule: r_id: 9503 rv_id: 1263386 rule_id: 0oU5AW version_id: nWT2LA2 url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec origin: community patterns: - pattern-inside: | def $F(...): ... - pattern-either: - pattern: exec(..., request.$W.get(...), ...) - pattern: | $V = request.$W.get(...) ... exec(..., $V, ...) - pattern: exec(..., request.$W(...), ...) - pattern: | $V = request.$W(...) ... exec(..., $V, ...) - pattern: exec(..., request.$W[...], ...) - pattern: | $V = request.$W[...] ... exec(..., $V, ...) - pattern: | loop = asyncio.get_running_loop() ... await loop.run_in_executor(None, exec, request.$W[...]) - pattern: | $V = request.$W[...] ... loop = asyncio.get_running_loop() ... await loop.run_in_executor(None, exec, $V) - pattern: | loop = asyncio.get_running_loop() ... await loop.run_in_executor(None, exec, request.$W.get(...)) - pattern: | $V = request.$W.get(...) ... loop = asyncio.get_running_loop() ... await loop.run_in_executor(None, exec, $V) languages: - python severity: WARNING - id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system message: Request data detected in os.system. This could be vulnerable to a command injection and should be avoided. If this must be done, use the 'subprocess' module instead and pass the arguments as a list. See https://owasp.org/www-community/attacks/Command_Injection for more information. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/Command_Injection category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system shortlink: https://sg.run/Gen2 semgrep.dev: rule: r_id: 9504 rv_id: 1263387 rule_id: KxUbp2 version_id: ExTExPo url: https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system origin: community languages: - python severity: ERROR patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: os.system(..., request.$W.get(...), ...) - pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: os.system(..., $S % request.$W.get(...), ...) - pattern: os.system(..., f"...{request.$W.get(...)}...", ...) - pattern: | $DATA = request.$W.get(...) ... os.system(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... os.system(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... os.system(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... os.system(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... os.system(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... os.system(..., $INTERM, ...) - pattern: $A = os.system(..., request.$W.get(...), ...) - pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $A = os.system(..., $S % request.$W.get(...), ...) - pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...) - pattern: return os.system(..., request.$W.get(...), ...) - pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: return os.system(..., $S % request.$W.get(...), ...) - pattern: return os.system(..., f"...{request.$W.get(...)}...", ...) - pattern: os.system(..., request.$W(...), ...) - pattern: os.system(..., $S.format(..., request.$W(...), ...), ...) - pattern: os.system(..., $S % request.$W(...), ...) - pattern: os.system(..., f"...{request.$W(...)}...", ...) - pattern: | $DATA = request.$W(...) ... os.system(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... os.system(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... os.system(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... os.system(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... os.system(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... os.system(..., $INTERM, ...) - pattern: $A = os.system(..., request.$W(...), ...) - pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...) - pattern: $A = os.system(..., $S % request.$W(...), ...) - pattern: $A = os.system(..., f"...{request.$W(...)}...", ...) - pattern: return os.system(..., request.$W(...), ...) - pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...) - pattern: return os.system(..., $S % request.$W(...), ...) - pattern: return os.system(..., f"...{request.$W(...)}...", ...) - pattern: os.system(..., request.$W[...], ...) - pattern: os.system(..., $S.format(..., request.$W[...], ...), ...) - pattern: os.system(..., $S % request.$W[...], ...) - pattern: os.system(..., f"...{request.$W[...]}...", ...) - pattern: | $DATA = request.$W[...] ... os.system(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... os.system(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... os.system(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... os.system(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... os.system(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... os.system(..., $INTERM, ...) - pattern: $A = os.system(..., request.$W[...], ...) - pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...) - pattern: $A = os.system(..., $S % request.$W[...], ...) - pattern: $A = os.system(..., f"...{request.$W[...]}...", ...) - pattern: return os.system(..., request.$W[...], ...) - pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...) - pattern: return os.system(..., $S % request.$W[...], ...) - pattern: return os.system(..., f"...{request.$W[...]}...", ...) - pattern: os.system(..., request.$W, ...) - pattern: os.system(..., $S.format(..., request.$W, ...), ...) - pattern: os.system(..., $S % request.$W, ...) - pattern: os.system(..., f"...{request.$W}...", ...) - pattern: | $DATA = request.$W ... os.system(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W ... os.system(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W ... os.system(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W ... os.system(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... os.system(..., $INTERM, ...) - pattern: | $DATA = request.$W ... os.system(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... os.system(..., $INTERM, ...) - pattern: $A = os.system(..., request.$W, ...) - pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...) - pattern: $A = os.system(..., $S % request.$W, ...) - pattern: $A = os.system(..., f"...{request.$W}...", ...) - pattern: return os.system(..., request.$W, ...) - pattern: return os.system(..., $S.format(..., request.$W, ...), ...) - pattern: return os.system(..., $S % request.$W, ...) - pattern: return os.system(..., f"...{request.$W}...", ...) - id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body message: Found request data in an EmailMessage that is set to use HTML. This is dangerous because HTML emails are susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. metadata: cwe: - 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (''Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://www.damonkohler.com/2008/12/email-injection.html category: security technology: - django subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body shortlink: https://sg.run/RoBe semgrep.dev: rule: r_id: 9505 rv_id: 1263390 rule_id: qNUj02 version_id: 8KT5rOn url: https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... $EMAIL.content_subtype = "html" ... - pattern-either: - pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.EmailMessage($SUBJ, $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $B.$C(..., $DATA, ...) ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) - pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.EmailMessage($SUBJ, $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $B.$C(..., $DATA, ...) ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) - pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.EmailMessage($SUBJ, $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $B.$C(..., $DATA, ...) ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) - pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...) - pattern: | $DATA = request.$W ... django.core.mail.EmailMessage($SUBJ, $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $B.$C(..., $DATA, ...) ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.EmailMessage($SUBJ, f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.core.mail.EmailMessage($SUBJ, $INTERM, ...) - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...) - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...) - id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message message: Found request data in 'send_mail(...)' that uses 'html_message'. This is dangerous because HTML emails are susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. metadata: cwe: - 'CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (''Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://www.damonkohler.com/2008/12/email-injection.html category: security technology: - django subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message shortlink: https://sg.run/Avx8 semgrep.dev: rule: r_id: 9506 rv_id: 1263391 rule_id: lBU9Ll version_id: gETB7Gn url: https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.send_mail(..., html_message=$DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) - pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) - pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.send_mail(..., html_message=$DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...), ...) - pattern: return django.core.mail.send_mail(..., html_message=request.$W(...), ...) - pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.send_mail(..., html_message=$DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...], ...) - pattern: return django.core.mail.send_mail(..., html_message=request.$W[...], ...) - pattern: django.core.mail.send_mail(..., html_message=request.$W, ...) - pattern: | $DATA = request.$W ... django.core.mail.send_mail(..., html_message=$DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.send_mail(..., html_message=$STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.send_mail(..., html_message=f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: | $DATA = request.$W ... django.core.mail.send_mail(..., html_message=$STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.core.mail.send_mail(..., html_message=$INTERM, ...) - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...) - pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...) - id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could result in path traversal attacks and therefore sensitive data being leaked. To mitigate, consider using os.path.abspath or os.path.realpath or the pathlib library. metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Path_Traversal category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open shortlink: https://sg.run/W8qg semgrep.dev: rule: r_id: 9509 rv_id: 1263396 rule_id: oqUe7z version_id: JdTzxAw url: https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: open(..., request.$W.get(...), ...) - pattern: open(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: open(..., $S % request.$W.get(...), ...) - pattern: open(..., f"...{request.$W.get(...)}...", ...) - pattern: | $DATA = request.$W.get(...) ... open(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W.get(...) ... open(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W.get(...) ... open(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W.get(...) ... open(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W.get(...) ... open(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: $A = open(..., request.$W.get(...), ...) - pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $A = open(..., $S % request.$W.get(...), ...) - pattern: $A = open(..., f"...{request.$W.get(...)}...", ...) - pattern: return open(..., request.$W.get(...), ...) - pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: return open(..., $S % request.$W.get(...), ...) - pattern: return open(..., f"...{request.$W.get(...)}...", ...) - pattern: | $DATA = request.$W.get(...) ... with open(..., $DATA, ...) as $FD: ... - pattern: open(..., request.$W(...), ...) - pattern: open(..., $S.format(..., request.$W(...), ...), ...) - pattern: open(..., $S % request.$W(...), ...) - pattern: open(..., f"...{request.$W(...)}...", ...) - pattern: | $DATA = request.$W(...) ... open(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W(...) ... open(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W(...) ... open(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W(...) ... open(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W(...) ... open(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: $A = open(..., request.$W(...), ...) - pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...) - pattern: $A = open(..., $S % request.$W(...), ...) - pattern: $A = open(..., f"...{request.$W(...)}...", ...) - pattern: return open(..., request.$W(...), ...) - pattern: return open(..., $S.format(..., request.$W(...), ...), ...) - pattern: return open(..., $S % request.$W(...), ...) - pattern: return open(..., f"...{request.$W(...)}...", ...) - pattern: | $DATA = request.$W(...) ... with open(..., $DATA, ...) as $FD: ... - pattern: open(..., request.$W[...], ...) - pattern: open(..., $S.format(..., request.$W[...], ...), ...) - pattern: open(..., $S % request.$W[...], ...) - pattern: open(..., f"...{request.$W[...]}...", ...) - pattern: | $DATA = request.$W[...] ... open(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W[...] ... open(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W[...] ... open(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W[...] ... open(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W[...] ... open(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: $A = open(..., request.$W[...], ...) - pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...) - pattern: $A = open(..., $S % request.$W[...], ...) - pattern: $A = open(..., f"...{request.$W[...]}...", ...) - pattern: return open(..., request.$W[...], ...) - pattern: return open(..., $S.format(..., request.$W[...], ...), ...) - pattern: return open(..., $S % request.$W[...], ...) - pattern: return open(..., f"...{request.$W[...]}...", ...) - pattern: | $DATA = request.$W[...] ... with open(..., $DATA, ...) as $FD: ... - pattern: open(..., request.$W, ...) - pattern: open(..., $S.format(..., request.$W, ...), ...) - pattern: open(..., $S % request.$W, ...) - pattern: open(..., f"...{request.$W}...", ...) - pattern: | $DATA = request.$W ... open(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W ... open(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W ... open(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W ... open(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... with open(..., $INTERM, ...) as $FD: ... - pattern: | $DATA = request.$W ... open(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... open(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... with open(..., $INTERM, ...) as $FD: ... - pattern: $A = open(..., request.$W, ...) - pattern: $A = open(..., $S.format(..., request.$W, ...), ...) - pattern: $A = open(..., $S % request.$W, ...) - pattern: $A = open(..., f"...{request.$W}...", ...) - pattern: return open(..., request.$W, ...) - pattern: return open(..., $S.format(..., request.$W, ...), ...) - pattern: return open(..., $S % request.$W, ...) - pattern: return open(..., f"...{request.$W}...", ...) - pattern: | $DATA = request.$W ... with open(..., $DATA, ...) as $FD: ... - id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where message: User-controlled data from a request is passed to 'extra()'. This could lead to a SQL injection and therefore protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by using `params` and not using quote placeholders in the SQL string. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where shortlink: https://sg.run/0Ql5 semgrep.dev: rule: r_id: 9510 rv_id: 1263402 rule_id: zdUkx1 version_id: DkTRb4l url: https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...), ...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...", ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) - pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...), ...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) - pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...], ...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) - pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...), ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...], ...) - pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., $DATA, ...], ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., f"...{$DATA}...", ...], ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) - pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W ... $MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.extra(..., where=[..., $INTERM, ...], ...) - id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql message: User-controlled data from request is passed to 'RawSQL()'. This could lead to a SQL injection and therefore protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by using `params` and not using quote placeholders in the SQL string. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql shortlink: https://sg.run/Kl4X semgrep.dev: rule: r_id: 9511 rv_id: 1263403 rule_id: pKUOBp version_id: WrTqK2L url: https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...), ...) - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...", ...) - pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) - pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...), ...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...) - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...", ...) - pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...) - pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...], ...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...) - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...", ...) - pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...) - pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...) - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W, ...), ...) - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...) - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...) - pattern: django.db.models.expressions.RawSQL(..., request.$W, ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... django.db.models.expressions.RawSQL(..., $INTERM, ...) - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...) - pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...) - pattern: | $DATA = request.$W.get(...) ... django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... django.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % (..., $DATA, ...) ... django.db.models.expressions.RawSQL($INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % (..., $DATA, ...) ... django.db.models.expressions.RawSQL($INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % (..., $DATA, ...) ... django.db.models.expressions.RawSQL($INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % (..., $DATA, ...) ... django.db.models.expressions.RawSQL($INTERM, ...) - id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute message: User-controlled data from a request is passed to 'execute()'. This could lead to a SQL injection and therefore protected information could be leaked. Instead, use django's QuerySets, which are built with query parameterization and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute shortlink: https://sg.run/qx7y semgrep.dev: rule: r_id: 9512 rv_id: 1263404 rule_id: 2ZUbDL version_id: 0bTKzRj url: https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...) - pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...) - pattern: $CURSOR.execute(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...) - pattern: return $CURSOR.execute(..., request.$W.get(...), ...) - pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...) - pattern: $CURSOR.execute(..., $S % request.$W(...), ...) - pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...) - pattern: $CURSOR.execute(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: $A = $CURSOR.execute(..., request.$W(...), ...) - pattern: return $CURSOR.execute(..., request.$W(...), ...) - pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...) - pattern: $CURSOR.execute(..., $S % request.$W[...], ...) - pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...) - pattern: $CURSOR.execute(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: $A = $CURSOR.execute(..., request.$W[...], ...) - pattern: return $CURSOR.execute(..., request.$W[...], ...) - pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...) - pattern: $CURSOR.execute(..., $S % request.$W, ...) - pattern: $CURSOR.execute(..., f"...{request.$W}...", ...) - pattern: $CURSOR.execute(..., request.$W, ...) - pattern: | $DATA = request.$W ... $CURSOR.execute(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $CURSOR.execute(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $CURSOR.execute(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $CURSOR.execute(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... $CURSOR.execute(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $CURSOR.execute(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... $CURSOR.execute(..., $INTERM, ...) - pattern: $A = $CURSOR.execute(..., request.$W, ...) - pattern: return $CURSOR.execute(..., request.$W, ...) - pattern: | $DATA = request.$W.get(...) ... $CURSOR.execute($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $CURSOR.execute($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $CURSOR.execute($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $CURSOR.execute($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % (..., $DATA, ...) ... $CURSOR.execute($INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % (..., $DATA, ...) ... $CURSOR.execute($INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % (..., $DATA, ...) ... $CURSOR.execute($INTERM, ...) - pattern: |- $DATA = request.$W ... $INTERM = $STR % (..., $DATA, ...) ... $CURSOR.execute($INTERM, ...) - id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw message: Data that is possible user-controlled from a python request is passed to `raw()`. This could lead to SQL injection and attackers gaining access to protected information. Instead, use django's QuerySets, which are built with query parameterization and therefore not vulnerable to sql injection. For example, you could use `Entry.objects.filter(date=2006)`. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw shortlink: https://sg.run/l2v9 semgrep.dev: rule: r_id: 9513 rv_id: 1263405 rule_id: X5U8v5 version_id: K3TKkBW url: https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw origin: community languages: - python severity: WARNING patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...) - pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...) - pattern: $MODEL.objects.raw(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...) - pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...) - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...) - pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...) - pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...) - pattern: $MODEL.objects.raw(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...) - pattern: return $MODEL.objects.raw(..., request.$W(...), ...) - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...) - pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...) - pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...) - pattern: $MODEL.objects.raw(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...) - pattern: return $MODEL.objects.raw(..., request.$W[...], ...) - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...) - pattern: $MODEL.objects.raw(..., $S % request.$W, ...) - pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...) - pattern: $MODEL.objects.raw(..., request.$W, ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... $MODEL.objects.raw(..., $INTERM, ...) - pattern: $A = $MODEL.objects.raw(..., request.$W, ...) - pattern: return $MODEL.objects.raw(..., request.$W, ...) - pattern: | $DATA = request.$W.get(...) ... $MODEL.objects.raw($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $MODEL.objects.raw($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $MODEL.objects.raw($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $MODEL.objects.raw($STR % (..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.raw($INTERM, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.raw($INTERM, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.raw($INTERM, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % (..., $DATA, ...) ... $MODEL.objects.raw($INTERM, ...) - id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests message: Data from request object is passed to a new server-side request. This could lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the response to the user, and ensure proper authentication and transport-layer security in the proxied request. See https://owasp.org/www-community/attacks/Server_Side_Request_Forgery to learn more about SSRF vulnerabilities. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests shortlink: https://sg.run/YvY4 semgrep.dev: rule: r_id: 9514 rv_id: 1263406 rule_id: j2UvEw version_id: qkTR7zn url: https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests origin: community languages: - python severity: ERROR patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: requests.$METHOD(..., $S % request.$W.get(...), ...) - pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...) - pattern: requests.$METHOD(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... requests.$METHOD(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... requests.$METHOD(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... requests.$METHOD(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... requests.$METHOD(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: $A = requests.$METHOD(..., request.$W.get(...), ...) - pattern: return requests.$METHOD(..., request.$W.get(...), ...) - pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...) - pattern: requests.$METHOD(..., $S % request.$W(...), ...) - pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...) - pattern: requests.$METHOD(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... requests.$METHOD(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... requests.$METHOD(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... requests.$METHOD(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... requests.$METHOD(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: $A = requests.$METHOD(..., request.$W(...), ...) - pattern: return requests.$METHOD(..., request.$W(...), ...) - pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...) - pattern: requests.$METHOD(..., $S % request.$W[...], ...) - pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...) - pattern: requests.$METHOD(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... requests.$METHOD(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... requests.$METHOD(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... requests.$METHOD(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... requests.$METHOD(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: $A = requests.$METHOD(..., request.$W[...], ...) - pattern: return requests.$METHOD(..., request.$W[...], ...) - pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...) - pattern: requests.$METHOD(..., $S % request.$W, ...) - pattern: requests.$METHOD(..., f"...{request.$W}...", ...) - pattern: requests.$METHOD(..., request.$W, ...) - pattern: | $DATA = request.$W ... requests.$METHOD(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W ... requests.$METHOD(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W ... requests.$METHOD(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W ... requests.$METHOD(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... requests.$METHOD(..., $INTERM, ...) - pattern: | $DATA = request.$W ... requests.$METHOD(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... requests.$METHOD(..., $INTERM, ...) - pattern: $A = requests.$METHOD(..., request.$W, ...) - pattern: return requests.$METHOD(..., request.$W, ...) - id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib message: Data from request object is passed to a new server-side request. This could lead to a server-side request forgery (SSRF), which could result in attackers gaining access to private organization data. To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the response to the user, and ensure proper authentication and transport-layer security in the proxied request. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery category: security technology: - django cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib shortlink: https://sg.run/6n2B semgrep.dev: rule: r_id: 9515 rv_id: 1263407 rule_id: 10UKDo version_id: l4TJRwD url: https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib origin: community languages: - python severity: ERROR patterns: - pattern-inside: | def $FUNC(...): ... - pattern-either: - pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...), ...) - pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...) - pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...) - pattern: urllib.request.urlopen(..., request.$W.get(...), ...) - pattern: | $DATA = request.$W.get(...) ... urllib.request.urlopen(..., $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR.format(..., $DATA, ...) ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... urllib.request.urlopen(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR % $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... urllib.request.urlopen(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = f"...{$DATA}..." ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W.get(...) ... urllib.request.urlopen(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W.get(...) ... $INTERM = $STR + $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...) - pattern: return urllib.request.urlopen(..., request.$W.get(...), ...) - pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...) - pattern: urllib.request.urlopen(..., $S % request.$W(...), ...) - pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...) - pattern: urllib.request.urlopen(..., request.$W(...), ...) - pattern: | $DATA = request.$W(...) ... urllib.request.urlopen(..., $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR.format(..., $DATA, ...) ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... urllib.request.urlopen(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR % $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... urllib.request.urlopen(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W(...) ... $INTERM = f"...{$DATA}..." ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W(...) ... urllib.request.urlopen(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W(...) ... $INTERM = $STR + $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: $A = urllib.request.urlopen(..., request.$W(...), ...) - pattern: return urllib.request.urlopen(..., request.$W(...), ...) - pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...) - pattern: urllib.request.urlopen(..., $S % request.$W[...], ...) - pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...) - pattern: urllib.request.urlopen(..., request.$W[...], ...) - pattern: | $DATA = request.$W[...] ... urllib.request.urlopen(..., $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR.format(..., $DATA, ...) ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... urllib.request.urlopen(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR % $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... urllib.request.urlopen(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W[...] ... $INTERM = f"...{$DATA}..." ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W[...] ... urllib.request.urlopen(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W[...] ... $INTERM = $STR + $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: $A = urllib.request.urlopen(..., request.$W[...], ...) - pattern: return urllib.request.urlopen(..., request.$W[...], ...) - pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...) - pattern: urllib.request.urlopen(..., $S % request.$W, ...) - pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...) - pattern: urllib.request.urlopen(..., request.$W, ...) - pattern: | $DATA = request.$W ... urllib.request.urlopen(..., $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W ... urllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...) - pattern: | $DATA = request.$W ... $INTERM = $STR.format(..., $DATA, ...) ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W ... urllib.request.urlopen(..., $STR % $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR % $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W ... urllib.request.urlopen(..., f"...{$DATA}...", ...) - pattern: | $DATA = request.$W ... $INTERM = f"...{$DATA}..." ... urllib.request.urlopen(..., $INTERM, ...) - pattern: | $DATA = request.$W ... urllib.request.urlopen(..., $STR + $DATA, ...) - pattern: | $DATA = request.$W ... $INTERM = $STR + $DATA ... urllib.request.urlopen(..., $INTERM, ...) - pattern: $A = urllib.request.urlopen(..., request.$W, ...) - pattern: return urllib.request.urlopen(..., request.$W, ...) - id: python.django.security.passwords.password-empty-string.password-empty-string message: '''$VAR'' is the empty string and is being used to set the password on ''$MODEL''. If you meant to set an unusable password, set the password to None or call ''set_unusable_password()''.' metadata: cwe: - 'CWE-521: Weak Password Requirements' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password category: security technology: - django subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string shortlink: https://sg.run/oxnR semgrep.dev: rule: r_id: 9516 rv_id: 1263411 rule_id: 9AU1jW version_id: GxTke5Q url: https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string origin: community patterns: - pattern-either: - pattern: | $MODEL.set_password($EMPTY) ... $MODEL.save() - pattern: | $VAR = $EMPTY ... $MODEL.set_password($VAR) ... $MODEL.save() - metavariable-regex: metavariable: $EMPTY regex: (\'\'|\"\") languages: - python severity: ERROR - id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default message: '''$VAR'' is using the empty string as its default and is being used to set the password on ''$MODEL''. If you meant to set an unusable password, set the default value to ''None'' or call ''set_unusable_password()''.' metadata: cwe: - 'CWE-521: Weak Password Requirements' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password category: security technology: - django subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default shortlink: https://sg.run/zvBW semgrep.dev: rule: r_id: 9517 rv_id: 1263412 rule_id: yyUn6Z version_id: RGT0LYX url: https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default origin: community languages: - python severity: ERROR patterns: - pattern-either: - pattern: | $VAR = request.$W.get($X, $EMPTY) ... $MODEL.set_password($VAR) ... $MODEL.save(...) - pattern: | def $F(..., $VAR=$EMPTY, ...): ... $MODEL.set_password($VAR) - metavariable-pattern: metavariable: $EMPTY pattern: '""' - focus-metavariable: $EMPTY fix: | None - id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host message: Running flask app with host 0.0.0.0 could expose the server publicly. metadata: cwe: - 'CWE-668: Exposure of Resource to Wrong Sphere' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - flask references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host shortlink: https://sg.run/eLby semgrep.dev: rule: r_id: 9532 rv_id: 1263414 rule_id: L1Uy1n version_id: BjTkZOY url: https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host origin: community languages: - python severity: WARNING pattern-either: - pattern: app.run(..., host="0.0.0.0", ...) - pattern: app.run(..., "0.0.0.0", ...) - id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly patterns: - pattern-not-inside: | if __name__ == '__main__': ... - pattern-not-inside: | def $X(...): ... - pattern: app.run(...) message: top-level app.run(...) is ignored by flask. Consider putting app.run(...) behind a guard, like inside a function metadata: cwe: - 'CWE-668: Exposure of Resource to Wrong Sphere' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - flask references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly shortlink: https://sg.run/vz5b semgrep.dev: rule: r_id: 9533 rv_id: 1263415 rule_id: 8GUjdX version_id: DkTRb4z url: https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly origin: community languages: - python severity: WARNING - id: python.flask.security.audit.debug-enabled.debug-enabled patterns: - pattern-inside: | import flask ... - pattern: $APP.run(..., debug=True, ...) message: Detected Flask app with debug=True. Do not deploy to production with this flag enabled as it will leak sensitive information. Instead, consider using Flask configuration variables or setting 'debug' using system environment variables. metadata: cwe: - 'CWE-489: Active Debug Code' owasp: A06:2017 - Security Misconfiguration references: - https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ category: security technology: - flask subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled shortlink: https://sg.run/dKrd semgrep.dev: rule: r_id: 9534 rv_id: 946206 rule_id: gxU1bd version_id: 8KTKjwR url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled origin: community severity: WARNING languages: - python - id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string message: Detected Flask route directly returning a formatted string. This is subject to cross-site scripting if user input can reach the string. Consider using the template engine instead and rendering pages with 'render_template()'. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - flask references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string shortlink: https://sg.run/Zv6o semgrep.dev: rule: r_id: 9535 rv_id: 1263416 rule_id: QrUz49 version_id: WrTqKAz url: https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string origin: community languages: - python severity: WARNING mode: taint pattern-sources: - pattern-either: - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $PARAM, ...): ... - pattern: $PARAM - pattern: | request.$FUNC.get(...) - pattern: | request.$FUNC(...) - pattern: request.$FUNC[...] pattern-sinks: - patterns: - pattern-not-inside: return "..." - pattern-either: - pattern: return "...".format(...) - pattern: return "..." % ... - pattern: return "..." + ... - pattern: return ... + "..." - pattern: return f"...{...}..." - patterns: - pattern: return $X - pattern-either: - pattern-inside: | $X = "...".format(...) ... - pattern-inside: | $X = "..." % ... ... - pattern-inside: | $X = "..." + ... ... - pattern-inside: | $X = ... + "..." ... - pattern-inside: | $X = f"...{...}..." ... - pattern-not-inside: | $X = "..." ... - id: python.flask.security.injection.os-system-injection.os-system-injection languages: - python severity: ERROR message: User data detected in os.system. This could be vulnerable to a command injection and should be avoided. If this must be done, use the 'subprocess' module instead and pass the arguments as a list. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/Command_Injection category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection shortlink: https://sg.run/4xzz semgrep.dev: rule: r_id: 9544 rv_id: 1263429 rule_id: BYUN99 version_id: 1QTypw7 url: https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection origin: community pattern-either: - patterns: - pattern: os.system(...) - pattern-either: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... os.system(..., <... $ROUTEVAR ...>, ...) - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... $INTERM = <... $ROUTEVAR ...> ... os.system(..., <... $INTERM ...>, ...) - pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...) - pattern: os.system(..., <... flask.request.$W[...] ...>, ...) - pattern: os.system(..., <... flask.request.$W(...) ...>, ...) - pattern: os.system(..., <... flask.request.$W ...>, ...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... os.system(<... $INTERM ...>) - pattern: os.system(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... os.system(<... $INTERM ...>) - pattern: os.system(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... os.system(<... $INTERM ...>) - pattern: os.system(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... os.system(<... $INTERM ...>) - pattern: os.system(...) - id: python.flask.security.injection.path-traversal-open.path-traversal-open languages: - python severity: ERROR message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could result in path traversal attacks. metadata: cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Path_Traversal category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open shortlink: https://sg.run/PJRW semgrep.dev: rule: r_id: 9545 rv_id: 1263430 rule_id: DbUpOQ version_id: 9lT4b94 url: https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open origin: community pattern-either: - patterns: - pattern: open(...) - pattern-either: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... open(..., <... $ROUTEVAR ...>, ...) - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... with open(..., <... $ROUTEVAR ...>, ...) as $FD: ... - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... $INTERM = <... $ROUTEVAR ...> ... open(..., <... $INTERM ...>, ...) - pattern: open(..., <... flask.request.$W.get(...) ...>, ...) - pattern: open(..., <... flask.request.$W[...] ...>, ...) - pattern: open(..., <... flask.request.$W(...) ...>, ...) - pattern: open(..., <... flask.request.$W ...>, ...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... open(<... $INTERM ...>, ...) - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... open(<... $INTERM ...>, ...) - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... open(<... $INTERM ...>, ...) - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... open(<... $INTERM ...>, ...) - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... with open(<... $INTERM ...>, ...) as $F: ... - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... with open(<... $INTERM ...>, ...) as $F: ... - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... with open(<... $INTERM ...>, ...) as $F: ... - pattern: open(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... with open(<... $INTERM ...>, ...) as $F: ... - pattern: open(...) - id: python.flask.security.injection.ssrf-requests.ssrf-requests languages: - python severity: ERROR message: Data from request object is passed to a new server-side request. This could lead to a server-side request forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the response to the user, and ensure proper authentication and transport-layer security in the proxied request. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests shortlink: https://sg.run/J9LW semgrep.dev: rule: r_id: 9546 rv_id: 1263432 rule_id: WAUoRx version_id: rxTAKJn url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests origin: community pattern-either: - patterns: - pattern: requests.$FUNC(...) - pattern-either: - pattern-inside: | @$APP.$ROUTE_METHOD($ROUTE, ...) def $ROUTE_FUNC(..., $ROUTEVAR, ...): ... requests.$FUNC(..., <... $ROUTEVAR ...>, ...) - pattern-inside: | @$APP.$ROUTE_METHOD($ROUTE, ...) def $ROUTE_FUNC(..., $ROUTEVAR, ...): ... $INTERM = <... $ROUTEVAR ...> ... requests.$FUNC(..., <... $INTERM ...>, ...) - metavariable-regex: metavariable: $ROUTE_METHOD regex: ^(route|get|post|put|delete|patch)$ - pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...) - pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...) - pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...) - pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... requests.$FUNC(<... $INTERM ...>, ...) - pattern: requests.$FUNC(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... requests.$FUNC(<... $INTERM ...>, ...) - pattern: requests.$FUNC(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... requests.$FUNC(<... $INTERM ...>, ...) - pattern: requests.$FUNC(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... requests.$FUNC(<... $INTERM ...>, ...) - pattern: requests.$FUNC(...) - id: python.flask.security.injection.user-eval.eval-injection languages: - python severity: ERROR message: Detected user data flowing into eval. This is code injection and should be avoided. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html category: security technology: - flask subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection shortlink: https://sg.run/5QpX semgrep.dev: rule: r_id: 9547 rv_id: 1263436 rule_id: 0oU54W version_id: w8TRoB0 url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection origin: community pattern-either: - patterns: - pattern: eval(...) - pattern-either: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... eval(..., <... $ROUTEVAR ...>, ...) - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... $INTERM = <... $ROUTEVAR ...> ... eval(..., <... $INTERM ...>, ...) - pattern: eval(..., <... flask.request.$W.get(...) ...>, ...) - pattern: eval(..., <... flask.request.$W[...] ...>, ...) - pattern: eval(..., <... flask.request.$W(...) ...>, ...) - pattern: eval(..., <... flask.request.$W ...>, ...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... eval(..., <... $INTERM ...>, ...) - pattern: eval(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... eval(..., <... $INTERM ...>, ...) - pattern: eval(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... eval(..., <... $INTERM ...>, ...) - pattern: eval(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... eval(..., <... $INTERM ...>, ...) - pattern: eval(...) - id: python.flask.security.injection.user-exec.exec-injection languages: - python severity: ERROR message: Detected user data flowing into exec. This is code injection and should be avoided. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html category: security technology: - flask subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection shortlink: https://sg.run/Ge42 semgrep.dev: rule: r_id: 9548 rv_id: 1263437 rule_id: KxUbl2 version_id: xyTjzD9 url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection origin: community pattern-either: - patterns: - pattern: exec(...) - pattern-either: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... exec(..., <... $ROUTEVAR ...>, ...) - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... $INTERM = <... $ROUTEVAR ...> ... exec(..., <... $INTERM ...>, ...) - pattern: exec(..., <... flask.request.$W.get(...) ...>, ...) - pattern: exec(..., <... flask.request.$W[...] ...>, ...) - pattern: exec(..., <... flask.request.$W(...) ...>, ...) - pattern: exec(..., <... flask.request.$W ...>, ...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W.get(...) ...> ... exec(..., <... $INTERM ...>, ...) - pattern: exec(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W[...] ...> ... exec(..., <... $INTERM ...>, ...) - pattern: exec(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W(...) ...> ... exec(..., <... $INTERM ...>, ...) - pattern: exec(...) - patterns: - pattern-inside: | $INTERM = <... flask.request.$W ...> ... exec(..., <... $INTERM ...>, ...) - pattern: exec(...) - id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' metadata: cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret shortlink: https://sg.run/l2E9 semgrep.dev: rule: r_id: 9557 rv_id: 1263452 rule_id: X5U8P5 version_id: PkTR3X3 url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret origin: community patterns: - pattern: | jwt.encode($_, "...", ...) languages: - python severity: ERROR - id: python.jwt.security.jwt-none-alg.jwt-python-none-alg message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ category: security technology: - jwt references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg shortlink: https://sg.run/Yvp4 semgrep.dev: rule: r_id: 9558 rv_id: 1263453 rule_id: j2UvKw version_id: JdTzxYj url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg origin: community languages: - python severity: ERROR pattern-either: - pattern: | jwt.encode(...,algorithm="none",...) - pattern: jwt.decode(...,algorithms=[...,"none",...],...) - id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode patterns: - pattern-either: - patterns: - pattern: | jwt.decode(..., options={..., "verify_signature": $BOOL, ...}, ...) - metavariable-pattern: metavariable: $BOOL pattern: | False - focus-metavariable: $BOOL - patterns: - pattern: | $OPTS = {..., "verify_signature": $BOOL, ...} ... jwt.decode(..., options=$OPTS, ...) - metavariable-pattern: metavariable: $BOOL pattern: | False - focus-metavariable: $BOOL message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity checks for the token which means the token could be tampered with by malicious actors. Ensure that the JWT token is verified. metadata: owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-287: Improper Authentication' references: - https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96 category: security technology: - jwt cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode shortlink: https://sg.run/6nyB semgrep.dev: rule: r_id: 9559 rv_id: 1263454 rule_id: 10UKjo version_id: 5PTo12w url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode origin: community fix: | True severity: ERROR languages: - python - id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 pattern: hashlib.sha1(...) fix-regex: regex: sha1 replacement: sha256 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B303 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.2 Insecure Custom Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - python subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 shortlink: https://sg.run/ydYx semgrep.dev: rule: r_id: 9624 rv_id: 1263537 rule_id: x8UnBk version_id: w8TRoE7 url: https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 origin: community severity: WARNING languages: - python - id: python.lang.security.insecure-hash-function.insecure-hash-function message: Detected use of an insecure MD4 or MD5 hash function. These functions have known vulnerabilities and are considered deprecated. Consider using 'SHA256' or a similar function instead. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.2 Insecure Custom Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://tools.ietf.org/html/rfc6151 - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function shortlink: https://sg.run/rdBn semgrep.dev: rule: r_id: 9625 rv_id: 1263538 rule_id: OrU30g version_id: xyTjzEe url: https://semgrep.dev/playground/r/xyTjzEe/python.lang.security.insecure-hash-function.insecure-hash-function origin: community languages: - python severity: WARNING pattern-either: - pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...) - pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...) - id: python.lang.security.unverified-ssl-context.unverified-ssl-context patterns: - pattern-either: - pattern: ssl._create_unverified_context(...) - pattern: ssl._create_default_https_context = ssl._create_unverified_context fix-regex: regex: _create_unverified_context replacement: create_default_context message: Unverified SSL context detected. This will permit insecure connections without verifying SSL certificates. Use 'ssl.create_default_context' instead. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-295: Improper Certificate Validation' references: - https://docs.python.org/3/library/ssl.html#ssl-security - https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context shortlink: https://sg.run/N4lp semgrep.dev: rule: r_id: 9627 rv_id: 1263540 rule_id: v8UnkQ version_id: e1Tyjlj url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context origin: community severity: ERROR languages: - python - id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated pattern: ssl.wrap_socket(...) message: '''ssl.wrap_socket()'' is deprecated. This function creates an insecure socket without server name indication or hostname matching. Instead, create an SSL context using ''ssl.SSLContext()'' and use that to wrap a socket.' metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://docs.python.org/3/library/ssl.html#ssl.wrap_socket - https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket category: security technology: - python subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated shortlink: https://sg.run/PJOY semgrep.dev: rule: r_id: 9645 rv_id: 1263516 rule_id: BYUN2e version_id: DkTRbgn url: https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated origin: community languages: - python severity: WARNING - id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true patterns: - pattern: subprocess.$FUNC(..., shell=$TRUE, ...) - metavariable-pattern: metavariable: $TRUE pattern: "True \n" - pattern-not: subprocess.$FUNC("...", shell=True, ...) - focus-metavariable: $TRUE message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. fix: | False metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess - https://docs.python.org/3/library/subprocess.html category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - secure default likelihood: HIGH impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true shortlink: https://sg.run/J92w semgrep.dev: rule: r_id: 9646 rv_id: 1263518 rule_id: DbUpz2 version_id: 0bTKzDK url: https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true origin: community languages: - python severity: ERROR - id: python.lang.security.audit.weak-ssl-version.weak-ssl-version message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2' or higher. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30 asvs: section: V9 Communications Verification Requirements control_id: 9.1.3 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements version: '4' references: - https://tools.ietf.org/html/rfc7568 - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html - https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2 category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version shortlink: https://sg.run/RoZO semgrep.dev: rule: r_id: 9649 rv_id: 1263520 rule_id: KxUbNG version_id: qkTR7Ev url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version origin: community languages: - python severity: WARNING pattern-either: - pattern: ssl.PROTOCOL_SSLv2 - pattern: ssl.PROTOCOL_SSLv3 - pattern: ssl.PROTOCOL_TLSv1 - pattern: ssl.PROTOCOL_TLSv1_1 - pattern: pyOpenSSL.SSL.SSLv2_METHOD - pattern: pyOpenSSL.SSL.SSLv23_METHOD - pattern: pyOpenSSL.SSL.SSLv3_METHOD - pattern: pyOpenSSL.SSL.TLSv1_METHOD - pattern: pyOpenSSL.SSL.TLSv1_1_METHOD - id: python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context options: symbolic_propagation: true mode: taint pattern-sources: - patterns: - pattern: | "$URL" - metavariable-pattern: metavariable: $URL language: regex patterns: - pattern-regex: http:// - pattern-not-regex: .*://localhost - pattern-not-regex: .*://127\.0\.0\.1 pattern-sinks: - patterns: - pattern-inside: | with requests.Session(...) as $SESSION: ... - pattern-either: - pattern: $SESSION.$W($SINK, ...) - pattern: $SESSION.request($METHOD, $SINK, ...) - focus-metavariable: $SINK fix-regex: regex: '[Hh][Tt][Tt][Pp]://' replacement: https:// count: 1 message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' asvs: section: V9 Communications Verification Requirements control_id: 9.2.1 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements version: '4' category: security technology: - requests references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context shortlink: https://sg.run/Bk5W semgrep.dev: rule: r_id: 9651 rv_id: 1263484 rule_id: lBU9BZ version_id: vdT06wb url: https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context origin: community languages: - python severity: INFO - id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http options: symbolic_propagation: true mode: taint pattern-sources: - patterns: - pattern: | "$URL" - metavariable-pattern: metavariable: $URL language: regex patterns: - pattern-regex: http:// - pattern-not-regex: .*://localhost - pattern-not-regex: .*://127\.0\.0\.1 pattern-sinks: - patterns: - pattern-either: - pattern: requests.Session(...).$W($SINK, ...) - pattern: requests.Session(...).request($METHOD, $SINK, ...) - focus-metavariable: $SINK fix-regex: regex: '[Hh][Tt][Tt][Pp]://' replacement: https:// count: 1 message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. languages: - python severity: INFO metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' asvs: section: V9 Communications Verification Requirements control_id: 9.1.1 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements version: '4' category: security technology: - requests references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http shortlink: https://sg.run/DoBY semgrep.dev: rule: r_id: 9652 rv_id: 1263485 rule_id: YGURXw version_id: d6Tyx02 url: https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http origin: community - id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http fix-regex: regex: '[Hh][Tt][Tt][Pp]://' replacement: https:// count: 1 message: Detected a request using 'http://'. This request will be unencrypted, and attackers could listen into traffic on the network and be able to obtain sensitive information. Use 'https://' instead. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' asvs: section: V9 Communications Verification Requirements control_id: 9.1.1 Weak TLS control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements version: '4' category: security technology: - requests references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http shortlink: https://sg.run/W8J4 semgrep.dev: rule: r_id: 9653 rv_id: 1263486 rule_id: 6JUjpG version_id: ZRTKA9v url: https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http origin: community languages: - python severity: INFO options: symbolic_propagation: true mode: taint pattern-sources: - patterns: - pattern: | "$URL" - metavariable-pattern: metavariable: $URL language: regex patterns: - pattern-regex: http:// - pattern-not-regex: .*://localhost - pattern-not-regex: .*://127\.0\.0\.1 pattern-sinks: - patterns: - pattern-either: - pattern: requests.$W($SINK, ...) - pattern: requests.request($METHOD, $SINK, ...) - pattern: requests.Request($METHOD, $SINK, ...) - focus-metavariable: $SINK - id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure patterns: - pattern: | $LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...) - metavariable-regex: metavariable: $LOGGER_OBJ regex: (?i)(_logger|logger|self.logger|log) - metavariable-regex: metavariable: $LOGGER_CALL regex: (debug|info|warn|warning|error|exception|critical) - metavariable-regex: metavariable: $FORMAT_STRING regex: (?i).*(api.key|secret|credential|token|password).*\%s.* message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING being logged. This may lead to secret credentials being exposed. Make sure that the logger is not logging sensitive information. severity: WARNING languages: - python metadata: cwe: - 'CWE-532: Insertion of Sensitive Information into Log File' category: security technology: - python owasp: - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures references: - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure shortlink: https://sg.run/ydNx semgrep.dev: rule: r_id: 9668 rv_id: 1263501 rule_id: x8UnJk version_id: A8TgdOR url: https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure origin: community - id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds to all available interfaces. Consider instead getting correct address from an environment variable or configuration file. metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - python references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces shortlink: https://sg.run/rdln semgrep.dev: rule: r_id: 9669 rv_id: 1263505 rule_id: OrU3og version_id: 0bTKzDL url: https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces origin: community languages: - python severity: INFO pattern-either: - pattern: | $S = socket.socket(...) ... $S.bind(("0.0.0.0", ...)) - pattern: | $S = socket.socket(...) ... $S.bind(("::", ...)) - pattern: | $S = socket.socket(...) ... $S.bind(("", ...)) - id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation patterns: - pattern-either: - pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...) - pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...) - pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) - pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) - pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...) - pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...) - pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...) - pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...) - metavariable-regex: metavariable: $REQS regex: (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\") message: certificate verification explicitly disabled, insecure connections possible metadata: cwe: - 'CWE-295: Improper Certificate Validation' owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - python references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation shortlink: https://sg.run/b7yp semgrep.dev: rule: r_id: 9670 rv_id: 1263506 rule_id: eqU87k version_id: K3TKkZn url: https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation origin: community languages: - python severity: ERROR - id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is recommended to use HTTPSConnectionPool instead for to encrypt communications. metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool category: security technology: - python subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection shortlink: https://sg.run/N4Np semgrep.dev: rule: r_id: 9671 rv_id: 1263507 rule_id: v8UnWQ version_id: qkTR7E1 url: https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection origin: community languages: - python severity: ERROR pattern-either: - pattern: urllib3.HTTPConnectionPool(...) - pattern: urllib3.connectionpool.HTTPConnectionPool(...) - id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 category: security technology: - pyyaml cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load shortlink: https://sg.run/we9Y semgrep.dev: rule: r_id: 9673 rv_id: 1263530 rule_id: ZqU5jZ version_id: 1QTyprw url: https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load origin: community languages: - python message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. fix-regex: regex: unsafe_load replacement: safe_load count: 1 severity: ERROR patterns: - pattern-inside: | import yaml ... - pattern-not-inside: | $YAML = ruamel.yaml.YAML(...) ... - pattern-either: - pattern: yaml.unsafe_load(...) - pattern: yaml.load(..., Loader=yaml.Loader, ...) - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) - pattern: yaml.load(..., Loader=yaml.CLoader, ...) - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) - id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ category: security technology: - ruamel.yaml cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel shortlink: https://sg.run/x1rz semgrep.dev: rule: r_id: 9674 rv_id: 1263531 rule_id: nJUzqK version_id: 9lT4bvG url: https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel origin: community languages: - python message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create arbitrary Python objects. A malicious actor could exploit this to run arbitrary code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead. severity: ERROR pattern-either: - pattern: ruamel.yaml.YAML(..., typ='unsafe', ...) - pattern: ruamel.yaml.YAML(..., typ='base', ...) - id: python.lang.security.deserialization.pickle.avoid-shelve metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://docs.python.org/3/library/pickle.html category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve shortlink: https://sg.run/dKkZ semgrep.dev: rule: r_id: 9678 rv_id: 1263535 rule_id: 8GUje2 version_id: NdTzyb4 url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve origin: community languages: - python message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. severity: WARNING pattern: shelve.$FUNC(...) - id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor message: Detected XOR cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use AES instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor shortlink: https://sg.run/L0yr semgrep.dev: rule: r_id: 9683 rv_id: 1263549 rule_id: PeUk5W version_id: gETB7j3 url: https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor origin: community severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.XOR.new(...) - pattern: Crypto.Cipher.XOR.new(...) - id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 shortlink: https://sg.run/3ALr semgrep.dev: rule: r_id: 9687 rv_id: 1263553 rule_id: ReUPO3 version_id: PkTR3vk url: https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 origin: community severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.SHA.new(...) - pattern: Cryptodome.Hash.SHA.new (...) - id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py references: - https://www.pycryptodome.org/src/public_key/dsa - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::key-length::pycryptodome - crypto::search::key-length::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size shortlink: https://sg.run/4y8l semgrep.dev: rule: r_id: 9688 rv_id: 1263554 rule_id: AbUWje version_id: JdTzxbQ url: https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size origin: community options: symbolic_propagation: true languages: - python severity: WARNING patterns: - pattern-either: - pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...) - pattern: Crypto.PublicKey.DSA.generate($SIZE, ...) - pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...) - pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 2048 - id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size message: Detected an insufficient key size for RSA. NIST recommends a key size of 3072 or higher. metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py references: - https://www.pycryptodome.org/src/public_key/rsa#rsa - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::key-length::pycryptodome - crypto::search::key-length::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size shortlink: https://sg.run/PprY semgrep.dev: rule: r_id: 9689 rv_id: 1263555 rule_id: BYUBWe version_id: 5PTo1jL url: https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size origin: community options: symbolic_propagation: true languages: - python severity: WARNING patterns: - pattern-either: - pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...) - pattern: Crypto.PublicKey.RSA.generate($SIZE, ...) - pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...) - pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 3072 - id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection patterns: - pattern-either: - pattern: | def $FUNC(...,$VAR,...): ... $SESSION.query(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) - pattern: | def $FUNC(...,$VAR,...): ... $SESSION.query.join(...).$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) - pattern: | def $FUNC(...,$VAR,...): ... $SESSION.query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) - pattern: | def $FUNC(...,$VAR,...): ... query.$SQLFUNC("...".$FORMATFUNC(...,$VAR,...)) - metavariable-regex: metavariable: $SQLFUNC regex: (group_by|order_by|distinct|having|filter) - metavariable-regex: metavariable: $FORMATFUNC regex: (?!bindparams) message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. fix-regex: regex: format replacement: bindparams languages: - python severity: WARNING metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - sqlalchemy owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection shortlink: https://sg.run/J3Xo semgrep.dev: rule: r_id: 9702 rv_id: 1263579 rule_id: BYUBWo version_id: NdTzyL4 url: https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection origin: community - id: ruby.lang.security.bad-deserialization.bad-deserialization mode: taint pattern-sources: - pattern-either: - pattern: params - pattern: cookies pattern-sinks: - pattern-either: - pattern: | CSV.load(...) - pattern: | Marshal.load(...) - pattern: | Marshal.restore(...) - pattern: | Oj.object_load(...) - pattern: | Oj.load($X) message: Checks for unsafe deserialization. Objects in Ruby can be serialized into strings, then later loaded from strings. However, uses of load and object_load can cause remote code execution. Loading user input with MARSHAL or CSV can potentially be dangerous. Use JSON in a secure fashion instead. metadata: references: - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures technology: - ruby cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization shortlink: https://sg.run/DJj2 semgrep.dev: rule: r_id: 9708 rv_id: 1263595 rule_id: lBUdQg version_id: 3ZT4Xqp url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization origin: community languages: - ruby severity: ERROR - id: ruby.lang.security.force-ssl-false.force-ssl-false message: Checks for configuration setting of force_ssl to false. Force_ssl forces usage of HTTPS, which could lead to network interception of unencrypted application traffic. To fix, set config.force_ssl = true. metadata: cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false shortlink: https://sg.run/YgkW semgrep.dev: rule: r_id: 9714 rv_id: 1263605 rule_id: 2ZU4lx version_id: WrTqKB3 url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false origin: community languages: - ruby severity: WARNING pattern: config.force_ssl = false fix-regex: regex: =\s*false replacement: = true - id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller patterns: - pattern-inside: | class $CONTROLLER < ApplicationController ... http_basic_authenticate_with ..., :password => "$SECRET", ... end - focus-metavariable: $SECRET message: Detected hardcoded password used in basic authentication in a controller class. Including this password in version control could expose this credential. Consider refactoring to use environment variables or configuration files. severity: WARNING metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown category: security technology: - ruby - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller shortlink: https://sg.run/6r0w semgrep.dev: rule: r_id: 9715 rv_id: 1263606 rule_id: X5UZWK version_id: 0bTKzNK url: https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller origin: community languages: - ruby - id: ruby.lang.security.no-eval.ruby-eval message: Use of eval with user-controllable input detected. This can lead to attackers running arbitrary code. Ensure external data does not reach here, otherwise this is a security vulnerability. Consider other ways to do this without eval. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: MEDIUM category: security cwe2022-top25: true cwe2021-top25: true cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb subcategory: - vuln technology: - ruby - rails license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval shortlink: https://sg.run/bDwZ semgrep.dev: rule: r_id: 9726 rv_id: 1263615 rule_id: OrUGNk version_id: A8TgdDv url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval origin: community languages: - ruby mode: taint pattern-sources: - pattern-either: - pattern: params - pattern: cookies - patterns: - pattern: | RubyVM::InstructionSequence.compile(...) - pattern-not: | RubyVM::InstructionSequence.compile("...") pattern-sinks: - patterns: - pattern-either: - pattern: $X.eval - pattern: $X.class_eval - pattern: $X.instance_eval - pattern: $X.module_eval - pattern: $X.eval(...) - pattern: $X.class_eval(...) - pattern: $X.instance_eval(...) - pattern: $X.module_eval(...) - pattern: eval(...) - pattern: class_eval(...) - pattern: module_eval(...) - pattern: instance_eval(...) - pattern-not: $M("...",...) - id: ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify pattern: OpenSSL::SSL::VERIFY_NONE message: Detected SSL that will accept an unverified connection. This makes the connections susceptible to man-in-the-middle attacks. Use 'OpenSSL::SSL::VERIFY_PEER' instead. fix-regex: regex: VERIFY_NONE replacement: VERIFY_PEER severity: WARNING languages: - ruby metadata: cwe: - 'CWE-295: Improper Certificate Validation' category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify shortlink: https://sg.run/kLxX semgrep.dev: rule: r_id: 9728 rv_id: 1263617 rule_id: v8U5Yn version_id: DkTRbl4 url: https://semgrep.dev/playground/r/DkTRbl4/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify origin: community - id: ruby.lang.security.weak-hashes-md5.weak-hashes-md5 message: Should not use md5 to generate hashes. md5 is proven to be vulnerable through the use of brute-force attacks. Could also result in collisions, leading to potential collision attacks. Use SHA256 or other hashing functions instead. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://www.ibm.com/support/pages/security-bulletin-vulnerability-md5-signature-and-hash-algorithm-affects-sterling-integrator-and-sterling-file-gateway-cve-2015-7575 category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 shortlink: https://sg.run/O1re semgrep.dev: rule: r_id: 9731 rv_id: 1263619 rule_id: nJUYxZ version_id: 0bTKzN8 url: https://semgrep.dev/playground/r/0bTKzN8/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 origin: community languages: - ruby severity: WARNING pattern-either: - pattern: Digest::MD5.base64digest $X - pattern: Digest::MD5.hexdigest $X - pattern: Digest::MD5.digest $X - pattern: Digest::MD5.new - pattern: OpenSSL::Digest::MD5.base64digest $X - pattern: OpenSSL::Digest::MD5.hexdigest $X - pattern: OpenSSL::Digest::MD5.digest $X - pattern: OpenSSL::Digest::MD5.new - id: ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 message: Should not use SHA1 to generate hashes. There is a proven SHA1 hash collision by Google, which could lead to vulnerabilities. Use SHA256, SHA3 or other hashing functions instead. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html - https://shattered.io/ category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 shortlink: https://sg.run/e4qX semgrep.dev: rule: r_id: 9732 rv_id: 1263620 rule_id: EwU4jq version_id: K3TKkEZ url: https://semgrep.dev/playground/r/K3TKkEZ/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 origin: community languages: - ruby severity: WARNING pattern-either: - pattern: Digest::SHA1.$FUNC - pattern: OpenSSL::Digest::SHA1.$FUNC - pattern: OpenSSL::HMAC.$FUNC("sha1",...) - id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket pattern: acl = "public-read-write" languages: - hcl severity: ERROR message: S3 bucket with public read-write access detected. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket shortlink: https://sg.run/0nok semgrep.dev: rule: r_id: 9754 rv_id: 1263900 rule_id: 6JUqvn version_id: PkTR3y5 url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket origin: community - id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. If you have to use `$TRUST`, ensure it does not come from user-input or use the appropriate prevention mechanism e.g. input validation or sanitization depending on the context. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://angular.io/api/platform-browser/DomSanitizer - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection confidence: MEDIUM category: security technology: - angular - browser cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust shortlink: https://sg.run/KWxP semgrep.dev: rule: r_id: 9755 rv_id: 1263902 rule_id: oqUzgA version_id: 5PTo1zk url: https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust origin: community languages: - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X: string, ...}) { ... } - pattern-inside: | function ...(..., $X: string, ...) { ... } - focus-metavariable: $X pattern-sinks: - patterns: - pattern-either: - pattern: $X.$TRUST($Y) - focus-metavariable: $Y - pattern-not: | $X.$TRUST(`...`) - pattern-not: | $X.$TRUST("...") - metavariable-regex: metavariable: $TRUST regex: (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern: sanitizer.sanitize(...) - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); - id: typescript.react.security.react-insecure-request.react-insecure-request message: Unencrypted request over HTTP detected. metadata: vulnerability: Insecure Transport owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://www.npmjs.com/package/axios category: security technology: - react subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request shortlink: https://sg.run/1n0b semgrep.dev: rule: r_id: 9766 rv_id: 1263918 rule_id: NbUA3O version_id: A8Tgd2p url: https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request origin: community languages: - typescript - javascript severity: ERROR patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | import $AXIOS from 'axios'; ... $AXIOS.$METHOD(...) - pattern-inside: | $AXIOS = require('axios'); ... $AXIOS.$METHOD(...) - pattern: $AXIOS.$VERB("$URL",...) - metavariable-regex: metavariable: $VERB regex: ^(get|post|delete|head|patch|put|options) - patterns: - pattern-either: - pattern-inside: | import $AXIOS from 'axios'; ... $AXIOS(...) - pattern-inside: | $AXIOS = require('axios'); ... $AXIOS(...) - pattern-either: - pattern: '$AXIOS({url: "$URL"}, ...)' - pattern: | $OPTS = {url: "$URL"} ... $AXIOS($OPTS, ...) - pattern: fetch("$URL", ...) - metavariable-regex: metavariable: $URL regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) - id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml message: Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html category: security confidence: MEDIUM technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml shortlink: https://sg.run/rAx6 semgrep.dev: rule: r_id: 9769 rv_id: 1263912 rule_id: x8UWvK version_id: l4TJR0v url: https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml origin: community languages: - typescript - javascript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X, ...}) { ... } - pattern-inside: | function ...(..., $X, ...) { ... } - focus-metavariable: $X - pattern-not-inside: | $F. ... .$SANITIZEUNC(...) pattern-sinks: - patterns: - focus-metavariable: $X - pattern-either: - pattern: | {...,dangerouslySetInnerHTML: {__html: $X},...} - pattern: | <$Y ... dangerouslySetInnerHTML={{__html: $X}} /> - pattern-not: | <$Y ... dangerouslySetInnerHTML={{__html: "..."}} /> - pattern-not: | {...,dangerouslySetInnerHTML:{__html: "..."},...} - metavariable-pattern: patterns: - pattern-not: | {...} metavariable: $X - pattern-not: | <... {__html: "..."} ...> - pattern-not: | <... {__html: `...`} ...> pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln - https://developer.mozilla.org/en-US/docs/Web/API/Document/write - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML category: security confidence: MEDIUM technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method shortlink: https://sg.run/E5x8 semgrep.dev: rule: r_id: 9781 rv_id: 1263916 rule_id: QrU68w version_id: GxTkeRl url: https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method origin: community languages: - typescript - javascript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X, ...}) { ... } - pattern-inside: | function ...(..., $X, ...) { ... } - focus-metavariable: $X - pattern-either: - pattern: $X.$Y - pattern: $X[...] pattern-sinks: - patterns: - pattern-either: - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" - pattern: "window.document. ... .$HTML('...',$SINK) \n" - pattern: "document.$HTML($SINK) \n" - metavariable-regex: metavariable: $HTML regex: (writeln|write) - focus-metavariable: $SINK - patterns: - pattern-either: - pattern: "$PROP. ... .$HTML('...',$SINK) \n" - metavariable-regex: metavariable: $HTML regex: (insertAdjacentHTML) - focus-metavariable: $SINK pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html category: security confidence: MEDIUM technology: - react cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property shortlink: https://sg.run/70Zv semgrep.dev: rule: r_id: 9782 rv_id: 1263917 rule_id: 3qUBl4 version_id: RGT0Lln url: https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property origin: community languages: - typescript - javascript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | function ...({..., $X, ...}) { ... } - pattern-inside: | function ...(..., $X, ...) { ... } - focus-metavariable: $X - pattern-either: - pattern: $X.$Y - pattern: $X[...] pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $BODY = $REACT.useRef(...) ... - pattern-inside: | $BODY = useRef(...) ... - pattern-inside: | $BODY = findDOMNode(...) ... - pattern-inside: | $BODY = createRef(...) ... - pattern-inside: | $BODY = $REACT.findDOMNode(...) ... - pattern-inside: | $BODY = $REACT.createRef(...) ... - pattern-either: - pattern: "$BODY. ... .$HTML = $SINK \n" - pattern: "$BODY.$HTML = $SINK \n" - metavariable-regex: metavariable: $HTML regex: (innerHTML|outerHTML) - focus-metavariable: $SINK - patterns: - pattern-either: - pattern: ReactDOM.findDOMNode(...).$HTML = $SINK - metavariable-regex: metavariable: $HTML regex: (innerHTML|outerHTML) - focus-metavariable: $SINK pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | import * as $S from "underscore.string" ... - pattern-inside: | import $S from "underscore.string" ... - pattern-inside: | $S = require("underscore.string") ... - pattern-either: - pattern: $S.escapeHTML(...) - patterns: - pattern-either: - pattern-inside: | import $S from "dompurify" ... - pattern-inside: | import { ..., $S,... } from "dompurify" ... - pattern-inside: | import * as $S from "dompurify" ... - pattern-inside: | $S = require("dompurify") ... - pattern-inside: | import $S from "isomorphic-dompurify" ... - pattern-inside: | import * as $S from "isomorphic-dompurify" ... - pattern-inside: | $S = require("isomorphic-dompurify") ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $S(...) ... - pattern: $VALUE.sanitize(...) - patterns: - pattern-inside: | $VALUE = $S.sanitize ... - pattern: $S(...) - pattern: $S.sanitize(...) - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'xss'; ... - pattern-inside: | import * as $S from 'xss'; ... - pattern-inside: | $S = require("xss") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | import $S from 'sanitize-html'; ... - pattern-inside: | import * as $S from "sanitize-html"; ... - pattern-inside: | $S = require("sanitize-html") ... - pattern: $S(...) - patterns: - pattern-either: - pattern-inside: | $S = new Remarkable() ... - pattern: $S.render(...) - id: ruby.lang.security.dangerous-exec.dangerous-exec mode: taint pattern-sources: - patterns: - pattern: | def $F(...,$ARG,...) ... end - focus-metavariable: $ARG - pattern: params - pattern: cookies pattern-sinks: - patterns: - pattern: | $EXEC(...) - pattern-not: | $EXEC("...","...","...",...) - pattern-not: | $EXEC(["...","...","...",...],...) - pattern-not: | $EXEC({...},"...","...","...",...) - pattern-not: | $EXEC({...},["...","...","...",...],...) - metavariable-regex: metavariable: $EXEC regex: ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code. metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - ruby - rails references: - https://guides.rubyonrails.org/security.html#command-line-injection cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec shortlink: https://sg.run/R8GY semgrep.dev: rule: r_id: 9805 rv_id: 1409405 rule_id: WAUZOw version_id: WrT7erb url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec origin: community severity: WARNING languages: - ruby - id: javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run message: Detected non-literal calls to Deno.run(). This could lead to a command injection vulnerability. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - deno references: - https://deno.land/manual/examples/subprocess#simple-example cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run shortlink: https://sg.run/Nrrn semgrep.dev: rule: r_id: 9927 rv_id: 1409397 rule_id: x8UWWg version_id: PkTe7AP url: https://semgrep.dev/playground/r/PkTe7AP/javascript.deno.security.audit.deno-dangerous-run.deno-dangerous-run origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: function ... (..., $ARG,...) {...} - focus-metavariable: $ARG pattern-sinks: - patterns: - pattern-either: - pattern: | Deno.run({cmd: [$INPUT,...]},...) - pattern: | Deno.run({cmd: ["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c",$INPUT,...]},...) - patterns: - pattern: | Deno.run({cmd: [$CMD,"-c",$INPUT,...]},...) - pattern-inside: | $CMD = "=~/(sh|bash|ksh|csh|tcsh|zsh)/" ... - focus-metavariable: $INPUT - id: yaml.docker-compose.security.privileged-service.privileged-service patterns: - pattern-inside: | version: ... ... services: ... $SERVICE: ... privileged: $TRUE - focus-metavariable: $TRUE - metavariable-regex: metavariable: $TRUE regex: (true) fix: | false message: Service '$SERVICE' is running in privileged mode. This grants the container the equivalent of root capabilities on the host machine. This can lead to container escapes, privilege escalation, and other security concerns. Remove the 'privileged' key to disable this capability. metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ category: security technology: - docker-compose subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service shortlink: https://sg.run/AlX0 semgrep.dev: rule: r_id: 10006 rv_id: 1263922 rule_id: DbUW17 version_id: 0bTKzXZ url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation patterns: - pattern-inside: | containers: ... - pattern-inside: | - name: $CONTAINER ... - pattern: | image: ... ... - pattern-inside: | image: ... ... $SC: ... - metavariable-regex: metavariable: $SC regex: ^(securityContext)$ - pattern-not-inside: | image: ... ... securityContext: ... allowPrivilegeEscalation: $VAL - focus-metavariable: $SC fix: | securityContext: allowPrivilegeEscalation: false # message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. By adding the `allowPrivilegeEscalation` parameter to your the `securityContext`, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation shortlink: https://sg.run/ljp6 semgrep.dev: rule: r_id: 10057 rv_id: 1263933 rule_id: 6JUqEO version_id: jQTn527 url: https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled patterns: - pattern-inside: | containers: ... - pattern: | image: ... ... securityContext: ... seccompProfile: unconfined message: 'Container is explicitly disabling seccomp confinement. This runs the service in an unrestricted state. Remove ''seccompProfile: unconfined'' to prevent this.' metadata: cwe: - 'CWE-284: Improper Access Control' references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ category: security technology: - kubernetes owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled shortlink: https://sg.run/6rgY semgrep.dev: rule: r_id: 10059 rv_id: 1263941 rule_id: zdUynw version_id: w8TRoL3 url: https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster pattern: | cluster: ... insecure-skip-tls-verify: true message: 'Cluster is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections insecure. Remove the ''insecure-skip-tls-verify: true'' key to secure communication.' metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster category: security technology: - kubernetes owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster shortlink: https://sg.run/okyn semgrep.dev: rule: r_id: 10116 rv_id: 1263943 rule_id: zdUyWx version_id: O9Tpxbo url: https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service pattern: | spec: ... insecureSkipTLSVerify: true message: 'Service is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections insecure. Remove the ''insecureSkipTLSVerify: true'' key to secure communication.' metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' references: - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io category: security technology: - kubernetes owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service shortlink: https://sg.run/zk10 semgrep.dev: rule: r_id: 10117 rv_id: 1263944 rule_id: pKUGXr version_id: e1TyjnR url: https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service origin: community languages: - yaml severity: WARNING - id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli mode: taint pattern-propagators: - pattern: $X << $Y from: $Y to: $X pattern-sources: - pattern-either: - pattern: | params - pattern: | cookies pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $CON = PG.connect(...) ... - pattern-inside: | $CON = PG::Connection.open(...) ... - pattern-inside: | $CON = PG::Connection.new(...) ... - pattern-either: - pattern: | $CON.$METHOD($X,...) - pattern: | $CON.$METHOD $X, ... - focus-metavariable: $X - metavariable-regex: metavariable: $METHOD regex: ^(exec|exec_params)$ languages: - ruby message: 'Detected string concatenation with a non-literal variable in a pg Ruby SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized queries like so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])` And you can use prepared statements with `exec_prepared`.' metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://www.rubydoc.info/gems/pg/PG/Connection category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli shortlink: https://sg.run/kL0o semgrep.dev: rule: r_id: 10328 rv_id: 1263628 rule_id: NbUAz7 version_id: 2KTv2y2 url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli origin: community severity: WARNING - id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled pattern: management.endpoints.web.exposure.include=* message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless you have Spring Security enabled or another means to protect these endpoints, this functionality is available without authentication, causing a significant security risk. severity: ERROR languages: - generic paths: include: - '*properties' metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators category: security technology: - spring cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled shortlink: https://sg.run/L0vY semgrep.dev: rule: r_id: 10439 rv_id: 1263077 rule_id: EwU4vg version_id: xyTjzwp url: https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled origin: community - id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling patterns: - pattern-either: - pattern: | proxy_http_version 1.1 ...; ... proxy_set_header Upgrade ...; ... proxy_set_header Connection ...; - pattern: | proxy_set_header Upgrade ...; ... proxy_set_header Connection ...; ... proxy_http_version 1.1 ...; - pattern: | proxy_set_header Upgrade ...; ... proxy_http_version 1.1 ...; ... proxy_set_header Connection ...; - pattern-inside: | location ... { ... } languages: - generic severity: WARNING message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading HTTP/1.1 connections to lesser-known HTTP/2 over cleartext (h2c) connections which can allow a bypass of reverse proxy access controls, and lead to long-lived, unrestricted HTTP traffic directly to back-end servers. To mitigate: WebSocket support required: Allow only the value websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket). WebSocket support not required: Do not forward Upgrade headers.' paths: include: - '*.conf' - '*.vhost' - '**/sites-available/*' - '**/sites-enabled/*' metadata: cwe: - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' references: - https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c category: security technology: - nginx confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling shortlink: https://sg.run/ploZ semgrep.dev: rule: r_id: 10562 rv_id: 1262679 rule_id: 6JUq0Z version_id: nWT2Lyp url: https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling origin: community - id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide category: security technology: - .net confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization shortlink: https://sg.run/ZeXW semgrep.dev: rule: r_id: 11135 rv_id: 1262635 rule_id: bwUOjK version_id: nWT2LGp url: https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization origin: community message: The BinaryFormatter type is dangerous and is not recommended for data processing. Applications should stop using BinaryFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. BinaryFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization.Formatters.Binary; ... - pattern: | new BinaryFormatter(); - id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization shortlink: https://sg.run/E5e5 semgrep.dev: rule: r_id: 11137 rv_id: 1262638 rule_id: kxURnR version_id: LjTkgPk url: https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization origin: community message: The FsPickler is dangerous and is not recommended for data processing. Default configuration tend to insecure deserialization vulnerability. patterns: - pattern-inside: | using MBrace.FsPickler.Json; ... - pattern: | FsPickler.CreateJsonSerializer(); - id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization shortlink: https://sg.run/70pG semgrep.dev: rule: r_id: 11138 rv_id: 1262641 rule_id: wdU87G version_id: QkTGqnA url: https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization origin: community message: The LosFormatter type is dangerous and is not recommended for data processing. Applications should stop using LosFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. LosFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Web.UI; ... - pattern: | new LosFormatter(); - id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization shortlink: https://sg.run/L0AX semgrep.dev: rule: r_id: 11139 rv_id: 1262642 rule_id: x8UW7x version_id: 3ZT4X6b url: https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization origin: community message: The NetDataContractSerializer type is dangerous and is not recommended for data processing. Applications should stop using NetDataContractSerializer as soon as possible, even if they believe the data they're processing to be trustworthy. NetDataContractSerializer is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization; ... - pattern: | new NetDataContractSerializer(); - id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization severity: WARNING languages: - C# metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks category: security technology: - .net confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization shortlink: https://sg.run/gJnR semgrep.dev: rule: r_id: 11141 rv_id: 1262644 rule_id: eqUvND version_id: PkTR30n url: https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization origin: community message: The SoapFormatter type is dangerous and is not recommended for data processing. Applications should stop using SoapFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. SoapFormatter is insecure and can't be made secure patterns: - pattern-inside: | using System.Runtime.Serialization.Formatters.Soap; ... - pattern: | new SoapFormatter(); - id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional languages: - hcl message: AWS EC2 Instance allowing use of the IMDSv1 metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' references: - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options category: security technology: - terraform - aws owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional shortlink: https://sg.run/J3BQ semgrep.dev: rule: r_id: 11302 rv_id: 1263884 rule_id: GdU0eA version_id: w8TRooE url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional origin: community pattern-either: - patterns: - pattern: http_tokens = "optional" - pattern-inside: | metadata_options { ... } - patterns: - pattern: | resource "aws_instance" "$NAME" { ... } - pattern-not: | resource "aws_instance" "$NAME" { ... metadata_options { ... http_tokens = "required" ... } ... } - pattern-not: | resource "aws_instance" "$NAME" { ... metadata_options { ... http_tokens = "optional" ... } ... } - pattern-not: | resource "aws_instance" "$NAME" { ... metadata_options { ... http_endpoint = "disabled" ... } ... } severity: ERROR - id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse metadata: functional-categories: - crypto::search::randomness::javax.crypto cwe: - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' category: security source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM technology: - java owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse shortlink: https://sg.run/Dww2 semgrep.dev: rule: r_id: 11908 rv_id: 1263000 rule_id: GdUZZ3 version_id: 0bTKzGk url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse origin: community languages: - java message: 'GCM IV/nonce is reused: encryption can be totally useless' patterns: - pattern-either: - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., $NONCE, ...); severity: ERROR - id: csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos severity: WARNING languages: - C# metadata: cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' owasp: A01:2017 - Injection references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS - https://docs.microsoft.com/en-us/dotnet/standard/base-types/regular-expressions#regular-expression-examples category: security technology: - .net confidence: MEDIUM subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos shortlink: https://sg.run/RPyY semgrep.dev: rule: r_id: 12005 rv_id: 945225 rule_id: 4bU2gd version_id: rxT6rjl url: https://semgrep.dev/playground/r/rxT6rjl/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos origin: community message: When using `System.Text.RegularExpressions` to process untrusted input, pass a timeout. A malicious user can provide input to `RegularExpressions` that abuses the backtracking behaviour of this regular expression engine. This will lead to excessive CPU usage, causing a Denial-of-Service attack patterns: - pattern-inside: | using System.Text.RegularExpressions; ... - pattern-either: - pattern: | public $T $F($X) { Regex $Y = new Regex($P); ... $Y.Match($X); } - pattern: | public $T $F($X) { Regex $Y = new Regex($P, $O); ... $Y.Match($X); } - pattern: | public $T $F($X) { ... Regex.Match($X, $P); } - pattern: | public $T $F($X) { ... Regex.Match($X, $P, $O); } - id: javascript.express.security.express-vm-injection.express-vm-injection message: Make sure that unverified user data can not reach `$VM`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection shortlink: https://sg.run/jkqJ semgrep.dev: rule: r_id: 12821 rv_id: 1263170 rule_id: DbUKPX version_id: 1QTypXQ url: https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | $VM = require('vm'); ... - pattern-either: - pattern: | $VM.runInContext(...) - pattern: | $VM.runInNewContext(...) - pattern: | $VM.compileFunction(...) - pattern: | $VM.runInThisContext(...) - pattern: new $VM.Script(...) - id: javascript.express.security.express-vm2-injection.express-vm2-injection message: Make sure that unverified user data can not reach `vm2`. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - express cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection shortlink: https://sg.run/1GWv semgrep.dev: rule: r_id: 12822 rv_id: 1263171 rule_id: WAUPXJ version_id: 9lT4bnX url: https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-inside: | require('vm2') ... - pattern-either: - patterns: - pattern-either: - pattern-inside: | $VM = new VM(...) ... - pattern-inside: | $VM = new NodeVM(...) ... - pattern: | $VM.run(...) - pattern: | new VM(...).run(...) - pattern: | new NodeVM(...).run(...) - pattern: | new VMScript(...) - pattern: | new VM(...) - pattern: new NodeVM(...) - id: javascript.lang.security.audit.code-string-concat.code-string-concat message: Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible. options: interfile: true metadata: interfile: true confidence: HIGH owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' references: - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html category: security technology: - node.js - Express - Next.js subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat shortlink: https://sg.run/96Yk semgrep.dev: rule: r_id: 13023 rv_id: 1263192 rule_id: DbUKEz version_id: 44TEjYX url: https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - pattern-either: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | import { ...,$IMPORT,... } from 'next/router' ... - pattern-inside: | import $IMPORT from 'next/router'; ... - pattern-either: - patterns: - pattern-inside: | $ROUTER = $IMPORT() ... - pattern-either: - pattern-inside: | const { ...,$PROPS,... } = $ROUTER.query ... - pattern-inside: | var { ...,$PROPS,... } = $ROUTER.query ... - pattern-inside: | let { ...,$PROPS,... } = $ROUTER.query ... - focus-metavariable: $PROPS - patterns: - pattern-inside: | $ROUTER = $IMPORT() ... - pattern: "$ROUTER.query.$VALUE \n" - patterns: - pattern: $IMPORT().query.$VALUE pattern-sinks: - patterns: - pattern: | eval(...) - id: yaml.github-actions.security.run-shell-injection.run-shell-injection languages: - yaml message: 'Using variable interpolation `${{...}}` with `github` context data in a `run:` step could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment variable, like this: "$ENVVAR".' metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections - https://securitylab.github.com/research/github-actions-untrusted-input/ technology: - github-actions cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection shortlink: https://sg.run/pkzk semgrep.dev: rule: r_id: 13162 rv_id: 1423395 rule_id: v8UjQj version_id: GxTl1DQ url: https://semgrep.dev/playground/r/GxTl1DQ/yaml.github-actions.security.run-shell-injection.run-shell-injection origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ ... github.event.issue.title ... }} - pattern: ${{ ... github.event.issue.body ... }} - pattern: ${{ ... github.event.pull_request.title ... }} - pattern: ${{ ... github.event.pull_request.body ... }} - pattern: ${{ ... github.event.comment.body ... }} - pattern: ${{ ... github.event.review.body ... }} - pattern: ${{ ... github.event.review_comment.body ... }} - pattern: ${{ ... github.event.pages ... .page_name ... }} - pattern: ${{ ... github.event.head_commit.message ... }} - pattern: ${{ ... github.event.head_commit.author.email ... }} - pattern: ${{ ... github.event.head_commit.author.name ... }} - pattern: ${{ ... github.event.commits ... .author.email ... }} - pattern: ${{ ... github.event.commits ... .author.name ... }} - pattern: ${{ ... github.event.commits ... .message ... }} - pattern: ${{ ... github.event.pull_request.head.ref ... }} - pattern: ${{ ... github.event.pull_request.head.label ... }} - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} - pattern: ${{ ... github.ref ... }} - pattern: ${{ ... github.base_ref ... }} - pattern: ${{ ... github.head_ref ... }} - pattern: ${{ ... github.ref_name ... }} - pattern: ${{ ... github.workflow ... }} - pattern: ${{ ... github.event.inputs ... }} - pattern: ${{ ... github.event.discussion.title ... }} - pattern: ${{ ... github.event.discussion.body ... }} - pattern: ${{ ... github.event.workflow_run.head_branch ... }} - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} - pattern: ${{ ... github.event.milestone.title ... }} - pattern: ${{ ... github.event.milestone.description ... }} - pattern: ${{ ... github.event.project_card.note ... }} - pattern: ${{ ... github.event.project.name ... }} - pattern: ${{ ... github.event.project_column.name ... }} - pattern: ${{ ... github.event.release.name ... }} - pattern: ${{ ... github.event.release.body ... }} - pattern: ${{ ... github.event.deployment.ref ... }} - pattern: ${{ ... inputs ... }} - pattern-not: ${{ ... github.event.issue.title && ... }} - pattern-not: ${{ ... github.event.issue.body && ... }} - pattern-not: ${{ ... github.event.pull_request.title && ... }} - pattern-not: ${{ ... github.event.pull_request.body && ... }} - pattern-not: ${{ ... github.event.comment.body && ... }} - pattern-not: ${{ ... github.event.review.body && ... }} - pattern-not: ${{ ... github.event.review_comment.body && ... }} - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} - pattern-not: ${{ ... github.event.head_commit.message && ... }} - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .message && ... }} - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} - pattern-not: ${{ ... github.ref && ... }} - pattern-not: ${{ ... github.base_ref && ... }} - pattern-not: ${{ ... github.head_ref && ... }} - pattern-not: ${{ ... github.ref_name && ... }} - pattern-not: ${{ ... github.workflow && ... }} - pattern-not: ${{ ... github.event.inputs && ... }} - pattern-not: ${{ ... github.event.discussion.title && ... }} - pattern-not: ${{ ... github.event.discussion.body && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} - pattern-not: ${{ ... github.event.milestone.title && ... }} - pattern-not: ${{ ... github.event.milestone.description && ... }} - pattern-not: ${{ ... github.event.project_card.note && ... }} - pattern-not: ${{ ... github.event.project.name && ... }} - pattern-not: ${{ ... github.event.project_column.name && ... }} - pattern-not: ${{ ... github.event.release.name && ... }} - pattern-not: ${{ ... github.event.release.body && ... }} - pattern-not: ${{ ... github.event.deployment.ref && ... }} severity: ERROR - id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout languages: - yaml message: This GitHub Actions workflow file uses `pull_request_target` and checks out code from the incoming pull request. When using `pull_request_target`, the Action runs in the context of the target repository, which includes access to all repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. metadata: category: security owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software and Data Integrity Failures cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' references: - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout shortlink: https://sg.run/jkdn semgrep.dev: rule: r_id: 13365 rv_id: 1413423 rule_id: d8Ulkd version_id: O9TQ2nX url: https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout origin: community patterns: - pattern-either: - pattern-inside: | on: ... pull_request_target: ... ... ... - pattern-inside: | on: [..., pull_request_target, ...] ... - pattern-inside: | on: pull_request_target ... - pattern-inside: | jobs: ... $JOBNAME: ... steps: ... - pattern: | ... uses: "$ACTION" with: ... ref: $EXPR - metavariable-regex: metavariable: $ACTION regex: actions/checkout@.* - metavariable-pattern: language: generic metavariable: $EXPR patterns: - pattern-inside: ${{ ... }} - pattern-either: - pattern: github.event.pull_request ... - pattern: github.head_ref ... severity: ERROR - id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands languages: - yaml severity: WARNING message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this workflow permissions to use the `set-env` and `add-path` commands. There is a vulnerability in these commands that could result in environment variables being modified by an attacker. Depending on the use of the environment variable, this could enable an attacker to, at worst, modify the system path to run a different command than intended, resulting in arbitrary code execution. This could result in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, use Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files for more information. metadata: cwe: - 'CWE-749: Exposed Dangerous Method or Function' owasp: A06:2017 - Security Misconfiguration references: - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files category: security technology: - github-actions subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Dangerous Method or Function source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands shortlink: https://sg.run/qq78 semgrep.dev: rule: r_id: 13412 rv_id: 947039 rule_id: EwUQ9x version_id: jQTzq34 url: https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands origin: community patterns: - pattern-either: - patterns: - pattern-inside: '{env: ...}' - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' - id: json.aws.security.public-s3-bucket.public-s3-bucket languages: - json message: Detected public S3 bucket. This policy allows anyone to have some kind of access to the bucket. The exact level of access and types of actions allowed will depend on the configuration of bucket policy and ACLs. Please review the bucket configuration to make sure they are set with intended values. metadata: category: security cwe: - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html technology: - aws subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket shortlink: https://sg.run/lxv5 semgrep.dev: rule: r_id: 13413 rv_id: 1263254 rule_id: 7KUpLy version_id: RGT0Ld0 url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket origin: community patterns: - pattern-inside: | $BUCKETNAME: { "Type": "AWS::S3::Bucket", "Properties": { ..., }, ..., } - pattern-either: - pattern: | "PublicAccessBlockConfiguration": { ..., "RestrictPublicBuckets": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "IgnorePublicAcls": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "BlockPublicAcls": false, ..., }, - pattern: | "PublicAccessBlockConfiguration": { ..., "BlockPublicPolicy": false, ..., }, severity: WARNING - id: javascript.express.security.cors-misconfiguration.cors-misconfiguration message: By letting user input control CORS parameters, there is a risk that software does not properly verify that the source of data or communication is valid. Use literal values for CORS settings. metadata: owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-346: Origin Validation Error' category: security references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS technology: - express subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration shortlink: https://sg.run/nKXO semgrep.dev: rule: r_id: 13580 rv_id: 1263162 rule_id: 5rULJQ version_id: YDTZe8Y url: https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.set($HEADER, $X) - pattern: $RES.header($HEADER, $X) - pattern: $RES.setHeader($HEADER, $X) - pattern: | $RES.set({$HEADER: $X}, ...) - pattern: | $RES.writeHead($STATUS, {$HEADER: $X}, ...) - focus-metavariable: $X - metavariable-regex: metavariable: $HEADER regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* - id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration message: By letting user input control `X-Frame-Options` header, there is a risk that software does not properly verify whether or not a browser should be allowed to render a page in an `iframe`. metadata: references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' category: security technology: - express subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration shortlink: https://sg.run/EvjA semgrep.dev: rule: r_id: 13581 rv_id: 1263178 rule_id: GdUrLy version_id: xyTjz3D url: https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.set($HEADER, ...) - pattern: $RES.header($HEADER, ...) - pattern: $RES.setHeader($HEADER, ...) - pattern: | $RES.set({$HEADER: ...}, ...) - pattern: | $RES.writeHead($STATUS, {$HEADER: ...}, ...) - metavariable-regex: metavariable: $HEADER regex: .*(X-Frame-Options|x-frame-options).* - id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation metadata: shortDescription: Allowing an attacker to manipulate the session may lead to unintended behavior. tags: - security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-276: Incorrect Default Permissions' references: - https://brakemanscanner.org/docs/warning_types/session_manipulation/ category: security technology: - rails help: | ## Remediation Session manipulation can occur when an application allows user-input in session keys. Since sessions are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker to manipulate the session may lead to unintended behavior. ## References [Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/) cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation shortlink: https://sg.run/86q7 semgrep.dev: rule: r_id: 13584 rv_id: 1263621 rule_id: BYUdW6 version_id: qkTR76G url: https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation origin: community message: This gets data from session using user inputs. A malicious user may be able to retrieve information from your session that you didn't intend them to. Do not use user input as a session key. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern: session[...] - id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access shortlink: https://sg.run/gYln semgrep.dev: rule: r_id: 13585 rv_id: 1263622 rule_id: DbU1dr version_id: l4TJRkk url: https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-either: - pattern: Dir.$X(...) - pattern: File.$X(...) - pattern: IO.$X(...) - pattern: Kernel.$X(...) - pattern: PStore.$X(...) - pattern: Pathname.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: chdir - pattern: chroot - pattern: delete - pattern: entries - pattern: foreach - pattern: glob - pattern: install - pattern: lchmod - pattern: lchown - pattern: link - pattern: load - pattern: load_file - pattern: makedirs - pattern: move - pattern: new - pattern: open - pattern: read - pattern: readlines - pattern: rename - pattern: rmdir - pattern: safe_unlink - pattern: symlink - pattern: syscopy - pattern: sysopen - pattern: truncate - pattern: unlink - id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call shortlink: https://sg.run/Q9gP semgrep.dev: rule: r_id: 13586 rv_id: 1263623 rule_id: WAUyzp version_id: YDTZeWL url: https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern-either: - pattern: Net::FTP.$X(...) - patterns: - pattern-inside: | $FTP = Net::FTP.$OPEN(...) ... $FTP.$METHOD(...) - pattern: $FTP.$METHOD(...) - id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request metadata: owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request shortlink: https://sg.run/3rLb semgrep.dev: rule: r_id: 13587 rv_id: 1263624 rule_id: 0oU2x3 version_id: 6xT29nN url: https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - pattern-either: - patterns: - pattern: Net::HTTP::$METHOD.new(...) - metavariable-pattern: metavariable: $METHOD patterns: - pattern-either: - pattern: Copy - pattern: Delete - pattern: Get - pattern: Head - pattern: Lock - pattern: Mkcol - pattern: Move - pattern: Options - pattern: Patch - pattern: Post - pattern: Propfind - pattern: Proppatch - pattern: Put - pattern: Trace - pattern: Unlock - patterns: - pattern: Net::HTTP.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: get - pattern: get2 - pattern: head - pattern: head2 - pattern: options - pattern: patch - pattern: post - pattern: post2 - pattern: post_form - pattern: put - pattern: request - pattern: request_get - pattern: request_head - pattern: request_post - pattern: send_request - pattern: trace - pattern: get_print - pattern: get_response - pattern: start - id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call shortlink: https://sg.run/4e8E semgrep.dev: rule: r_id: 13588 rv_id: 1263625 rule_id: KxU72k version_id: o5TbDq8 url: https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call origin: community message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or access files they have no right to. languages: - ruby severity: ERROR mode: taint pattern-sources: - pattern-either: - pattern: params[...] - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: Kernel.$X(...) - patterns: - pattern-either: - pattern: Shell.$X(...) - patterns: - pattern-inside: | $SHELL = Shell.$ANY(...) ... $SHELL.$X(...) - pattern: $SHELL.$X(...) - metavariable-pattern: metavariable: $X patterns: - pattern-either: - pattern: cat - pattern: chdir - pattern: chroot - pattern: delete - pattern: entries - pattern: exec - pattern: foreach - pattern: glob - pattern: install - pattern: lchmod - pattern: lchown - pattern: link - pattern: load - pattern: load_file - pattern: makedirs - pattern: move - pattern: new - pattern: open - pattern: read - pattern: readlines - pattern: rename - pattern: rmdir - pattern: safe_unlink - pattern: symlink - pattern: syscopy - pattern: sysopen - pattern: system - pattern: truncate - pattern: unlink - id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://brakemanscanner.org/docs/warning_types/link_to/ - https://brakemanscanner.org/docs/warning_types/link_to_href/ category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to shortlink: https://sg.run/JxXQ semgrep.dev: rule: r_id: 13590 rv_id: 1263632 rule_id: lBU8Qj version_id: 9lT4brj url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to origin: community message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` is not escaped. This means that user input which reaches the body will be executed when the HTML is rendered. Even in other versions, values starting with `javascript:` or `data:` are not escaped. It is better to create and use a safer function which checks the body argument. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env - pattern-either: - pattern: $MODEL.url(...) - pattern: $MODEL.uri(...) - pattern: $MODEL.link(...) - pattern: $MODEL.page(...) - pattern: $MODEL.site(...) pattern-sinks: - pattern: link_to(...) pattern-sanitizers: - patterns: - pattern: | "...#{...}..." - pattern-not: | "#{...}..." - id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect metadata: owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' references: - https://brakemanscanner.org/docs/warning_types/redirect/ category: security technology: - rails subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect shortlink: https://sg.run/5DY3 semgrep.dev: rule: r_id: 13591 rv_id: 1263634 rule_id: YGUDqJ version_id: rxTAKdY url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect origin: community message: When a redirect uses user input, a malicious user can spoof a website under a trusted URL or access restricted parts of a site. When using user-supplied values, sanitize the value before using it for the redirect. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env - patterns: - pattern: $MODEL.$X(...) - pattern-not: $MODEL.$X("...") - metavariable-pattern: metavariable: $X pattern-either: - pattern: all - pattern: create - pattern: create! - pattern: find - pattern: find_by_sql - pattern: first - pattern: last - pattern: new - pattern: from - pattern: group - pattern: having - pattern: joins - pattern: lock - pattern: order - pattern: reorder - pattern: select - pattern: where - pattern: find_by - pattern: find_by! - pattern: take pattern-sinks: - pattern: redirect_to(...) pattern-sanitizers: - pattern: params.merge(:only_path => true) - pattern: params.merge(:host => ...) - id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' references: - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ category: security technology: - rails cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path shortlink: https://sg.run/GO2n semgrep.dev: rule: r_id: 13592 rv_id: 1263635 rule_id: 6JU1bL version_id: bZT53p0 url: https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path origin: community message: Avoid rendering user input. It may be possible for a malicious user to input a path that lets them access a template they shouldn't. To prevent this, check dynamic template paths against a predefined allowlist to make sure it's an allowed template. languages: - ruby severity: WARNING mode: taint pattern-sources: - pattern: params - pattern: cookies - pattern: request.env pattern-sinks: - patterns: - pattern-inside: render($X => $INPUT, ...) - pattern: $INPUT - metavariable-pattern: metavariable: $X pattern-either: - pattern: action - pattern: template - pattern: partial - pattern: file - id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions languages: - python severity: WARNING metadata: category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-276: Incorrect Default Permissions' technology: - python references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions shortlink: https://sg.run/AXY4 semgrep.dev: rule: r_id: 13594 rv_id: 1263482 rule_id: zdUYqR version_id: O9Tpxqr url: https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions origin: community message: These permissions `$BITS` are widely permissive and grant access to more people than may be necessary. A good default is `0o644` which gives read and write access to yourself and read access to everyone else. patterns: - pattern-inside: os.$METHOD(...) - metavariable-pattern: metavariable: $METHOD patterns: - pattern-either: - pattern: chmod - pattern: lchmod - pattern: fchmod - pattern-either: - patterns: - pattern: os.$METHOD($FILE, $BITS, ...) - metavariable-comparison: metavariable: $BITS comparison: $BITS >= 0o650 and $BITS < 0o100000 - patterns: - pattern: os.$METHOD($FILE, $BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS >= 0o100650 - patterns: - pattern: os.$METHOD($FILE, $BITS, ...) - metavariable-pattern: metavariable: $BITS patterns: - pattern-either: - pattern: <... stat.S_IWGRP ...> - pattern: <... stat.S_IXGRP ...> - pattern: <... stat.S_IWOTH ...> - pattern: <... stat.S_IXOTH ...> - pattern: <... stat.S_IRWXO ...> - pattern: <... stat.S_IRWXG ...> - patterns: - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) - metavariable-comparison: metavariable: $MOD comparison: $MOD == 0o111 - id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query languages: - php message: '`$QUERY` Detected string concatenation with a non-literal variable in a Doctrine QueryBuilder method. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead.' metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html technology: - doctrine cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query shortlink: https://sg.run/jwDJ semgrep.dev: rule: r_id: 13965 rv_id: 1263271 rule_id: kxUw23 version_id: 1QTypnG url: https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query origin: community mode: taint pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: $QUERY->add(...,$SINK,...) - pattern: $QUERY->select(...,$SINK,...) - pattern: $QUERY->addSelect(...,$SINK,...) - pattern: $QUERY->delete(...,$SINK,...) - pattern: $QUERY->update(...,$SINK,...) - pattern: $QUERY->insert(...,$SINK,...) - pattern: $QUERY->from(...,$SINK,...) - pattern: $QUERY->join(...,$SINK,...) - pattern: $QUERY->innerJoin(...,$SINK,...) - pattern: $QUERY->leftJoin(...,$SINK,...) - pattern: $QUERY->rightJoin(...,$SINK,...) - pattern: $QUERY->where(...,$SINK,...) - pattern: $QUERY->andWhere(...,$SINK,...) - pattern: $QUERY->orWhere(...,$SINK,...) - pattern: $QUERY->groupBy(...,$SINK,...) - pattern: $QUERY->addGroupBy(...,$SINK,...) - pattern: $QUERY->having(...,$SINK,...) - pattern: $QUERY->andHaving(...,$SINK,...) - pattern: $QUERY->orHaving(...,$SINK,...) - pattern: $QUERY->orderBy(...,$SINK,...) - pattern: $QUERY->addOrderBy(...,$SINK,...) - pattern: $QUERY->set($SINK,...) - pattern: $QUERY->setValue($SINK,...) - pattern-either: - pattern-inside: | $Q = $X->createQueryBuilder(); ... - pattern-inside: | $Q = new QueryBuilder(...); ... pattern-sources: - patterns: - pattern-either: - pattern: sprintf(...) - pattern: | "...".$SMTH severity: WARNING - id: python.django.security.injection.raw-html-format.raw-html-format languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates (`django.shortcuts.render`) which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - django references: - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/oYj1 semgrep.dev: rule: r_id: 14360 rv_id: 1263397 rule_id: 2ZUPER version_id: 5PTo100 url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern: django.utils.html.escape(...) pattern-sources: - patterns: - pattern: request.$ANYTHING - pattern-not: request.build_absolute_uri pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: python.flask.security.injection.raw-html-concat.raw-html-format languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates (`flask.render_template`) which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - flask references: - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format shortlink: https://sg.run/Pb7e semgrep.dev: rule: r_id: 14389 rv_id: 1409401 rule_id: GdUrJv version_id: RGTEN1l url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern: jinja2.escape(...) - pattern: flask.escape(...) - patterns: - pattern: flask.render_template($TPL, ...) - metavariable-regex: metavariable: $TPL regex: .*\.html pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: go.lang.security.injection.tainted-url-host.tainted-url-host languages: - go message: A request was found to be crafted from user-input `$REQUEST`. This can lead to Server-Side Request Forgery (SSRF) vulnerabilities, potentially exposing sensitive data. It is recommend where possible to not allow user-input to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommended to follow OWASP best practices to prevent abuse, including using an allowlist. options: interfile: true metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://goteleport.com/blog/ssrf-attacks/ category: security technology: - go confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/5DjW semgrep.dev: rule: r_id: 14391 rv_id: 1262970 rule_id: AbUQLr version_id: yeTxpOj url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - label: INPUT patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ - label: CLEAN requires: INPUT patterns: - pattern-either: - pattern: | "$URLSTR" + $INPUT - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) - pattern: fmt.Printf("$URLSTR", $INPUT, ...) - metavariable-regex: metavariable: $URLSTR regex: .*//[a-zA-Z0-10]+\..* pattern-sinks: - requires: INPUT and not CLEAN patterns: - pattern-either: - patterns: - pattern-either: - patterns: - pattern-inside: | $CLIENT := &http.Client{...} ... - pattern: $CLIENT.$METHOD($URL, ...) - pattern: http.$METHOD($URL, ...) - metavariable-regex: metavariable: $METHOD regex: ^(Get|Head|Post|PostForm)$ - patterns: - pattern: | http.NewRequest("$METHOD", $URL, ...) - metavariable-regex: metavariable: $METHOD regex: ^(GET|HEAD|POST|POSTFORM)$ - focus-metavariable: $URL severity: WARNING - id: go.lang.security.injection.raw-html-format.raw-html-format languages: - go severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. Use the `html/template` package which will safely render HTML instead, or inspect that the HTML is rendered safely. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - go references: - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/3r1G semgrep.dev: rule: r_id: 14443 rv_id: 1262968 rule_id: PeUonQ version_id: 1QTyp2p url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sanitizers: - pattern: html.EscapeString(...) pattern-sinks: - patterns: - pattern-either: - pattern: fmt.Printf("$HTMLSTR", ...) - pattern: fmt.Sprintf("$HTMLSTR", ...) - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) - pattern: '"$HTMLSTR" + ...' - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: ruby.rails.security.injection.raw-html-format.raw-html-format languages: - ruby severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. Use the `render template` and make template files which will safely render HTML instead, or inspect that the HTML is absolutely rendered safely with a function like `sanitize`. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://www.netsparker.com/blog/web-security/preventing-xss-ruby-on-rails-web-applications/ - https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/b2JQ semgrep.dev: rule: r_id: 14470 rv_id: 1409408 rule_id: kxUwZX version_id: qkTvgYY url: https://semgrep.dev/playground/r/qkTvgYY/ruby.rails.security.injection.raw-html-format.raw-html-format origin: community mode: taint pattern-sanitizers: - pattern-either: - pattern: sanitize(...) - pattern: strip_tags(...) pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | $HTMLSTR - pattern-regex: <\w+.* - patterns: - pattern-either: - pattern: Kernel::sprintf("$HTMLSTR", ...) - pattern: | "$HTMLSTR" + $EXPR - pattern: | "$HTMLSTR" % $EXPR - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - id: bash.curl.security.curl-eval.curl-eval severity: WARNING languages: - bash message: Data is being eval'd from a `curl` command. An attacker with control of the server in the `curl` command could inject malicious code into the `eval`, resulting in a system comrpomise. Avoid eval'ing untrusted data if you can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its integrity. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' category: security technology: - bash - curl confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval shortlink: https://sg.run/0yqJ semgrep.dev: rule: r_id: 14554 rv_id: 1262601 rule_id: KxU7Rq version_id: JdTzxL2 url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval origin: community mode: taint pattern-sources: - pattern: | $(curl ...) - pattern: | `curl ...` pattern-sinks: - pattern: eval ... - id: python.flask.security.injection.tainted-url-host.tainted-url-host languages: - python message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - flask cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/RXpK semgrep.dev: rule: r_id: 14649 rv_id: 1409403 rule_id: ReU3Wb version_id: BjTy42w url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: '"$URLSTR" % ...' - metavariable-pattern: metavariable: $URLSTR language: generic patterns: - pattern-either: - pattern: $SCHEME://%s - pattern: $SCHEME://%r - patterns: - pattern: '"$URLSTR".format(...)' - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME:// { ... } - patterns: - pattern: '"$URLSTR" + ...' - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern: f"$URLSTR{...}..." - metavariable-regex: metavariable: $URLSTR regex: .*://$ - patterns: - pattern-inside: | $URL = "$URLSTR" ... - pattern: $URL += ... - metavariable-regex: metavariable: $URLSTR regex: .*://$ pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR severity: WARNING - id: go.lang.security.audit.md5-used-as-password.md5-used-as-password languages: - go severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can use the `golang.org/x/crypto/bcrypt` package. options: interfile: true metadata: category: security technology: - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://pkg.go.dev/golang.org/x/crypto/bcrypt owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/4eOE semgrep.dev: rule: r_id: 14688 rv_id: 1262938 rule_id: 4bU1Wj version_id: nWT2L9r url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: md5.New - pattern: md5.Sum pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: go.lang.security.injection.tainted-sql-string.tainted-sql-string languages: - go message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) or a safe library. options: interfile: true metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://golang.org/doc/database/sql-injection - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ category: security technology: - go confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/PbEq semgrep.dev: rule: r_id: 14689 rv_id: 1409388 rule_id: PeUoqy version_id: nWTQ5qD url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint severity: ERROR pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - patterns: - pattern-inside: | var $SB strings.Builder ... - pattern-inside: | $SB.WriteString("$SQLSTR") ... $SB.String(...) - pattern: | $SB.WriteString(...) - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop).* - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$SQLSTR", ...) - pattern: fmt.Sprintf("$SQLSTR", ...) - pattern: fmt.Printf("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* pattern-sanitizers: - pattern-either: - pattern: strconv.Atoi(...) - pattern: | ($X: bool) - id: java.lang.security.audit.md5-used-as-password.md5-used-as-password languages: - java severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as PBKDF2 or bcrypt. You can use `javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")` or, if using Spring, `org.springframework.security.crypto.bcrypt`. metadata: category: security technology: - java - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory - https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/JxEQ semgrep.dev: rule: r_id: 14690 rv_id: 1263029 rule_id: JDULAW version_id: bZT53QB url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-inside: | $TYPE $MD = MessageDigest.getInstance("MD5"); ... - pattern: $MD.digest(...); pattern-sinks: - patterns: - pattern: $MODEL.$METHOD(...); - metavariable-regex: metavariable: $METHOD regex: (?i)(.*password.*) - id: javascript.express.security.injection.raw-html-format.raw-html-format message: User data flows into the host portion of this manually-constructed HTML. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. Consider using a sanitization library such as DOMPurify to sanitize the HTML within. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html category: security technology: - express cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format shortlink: https://sg.run/5DO3 semgrep.dev: rule: r_id: 14691 rv_id: 1263175 rule_id: 5rUL0X version_id: NdTzyQv url: https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - label: EXPRESS patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - label: EXPRESSTS patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - label: CLEAN by-side-effect: true patterns: - pattern-either: - pattern: $A($SOURCE) - pattern: $SANITIZE. ... .$A($SOURCE) - pattern: $A. ... .$SANITIZE($SOURCE) - focus-metavariable: $SOURCE - metavariable-regex: metavariable: $A regex: (?i)(.*valid|.*sanitiz) pattern-sinks: - requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" + $EXPR' - pattern: '"$HTMLSTR".concat(...)' - pattern: util.format($HTMLSTR, ...) - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - patterns: - pattern: | `...` - pattern-regex: | .*<\w+.* - id: kotlin.lang.security.ecb-cipher.ecb-cipher metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher shortlink: https://sg.run/DzLj semgrep.dev: rule: r_id: 14696 rv_id: 1263263 rule_id: DbU1Zd version_id: YDTZexg url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher origin: community message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. severity: WARNING languages: - kt patterns: - pattern-either: - pattern: | val $VAR : Cipher = $CIPHER.getInstance($MODE) - pattern: | var $VAR : Cipher = $CIPHER.getInstance($MODE) - pattern: | val $VAR = $CIPHER.getInstance($MODE) - pattern: | var $VAR = $CIPHER.getInstance($MODE) - metavariable-regex: metavariable: $MODE regex: .*ECB.* - id: kotlin.lang.security.no-null-cipher.no-null-cipher pattern: NullCipher(...) metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher shortlink: https://sg.run/0ywb semgrep.dev: rule: r_id: 14698 rv_id: 1263265 rule_id: 0oU2Yy version_id: o5TbDPj url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher origin: community message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - kt - scala - id: kotlin.lang.security.use-of-md5.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - kt severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5 shortlink: https://sg.run/4eQx semgrep.dev: rule: r_id: 14700 rv_id: 1263267 rule_id: qNUXPj version_id: pZT03Jd url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5 origin: community pattern-either: - pattern: | java.security.MessageDigest.getInstance("MD5") - pattern: | org.apache.commons.codec.digest.DigestUtils.getMd5Digest() - id: python.flask.security.injection.tainted-sql-string.tainted-sql-string message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as SQLAlchemy which will protect your queries. metadata: cwe: - 'CWE-704: Incorrect Type Conversion or Cast' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column category: security technology: - sqlalchemy - flask subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/JxZj semgrep.dev: rule: r_id: 14702 rv_id: 1409402 rule_id: YGUDKQ version_id: A8TEvb4 url: https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string origin: community severity: ERROR languages: - python mode: taint pattern-sources: - patterns: - pattern-either: - pattern: flask.request.$ANYTHING - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR" % ... - pattern: | "$SQLSTR".format(...) - pattern: | f"$SQLSTR{...}..." - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* - id: python.lang.security.audit.md5-used-as-password.md5-used-as-password severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as scrypt. You can use `hashlib.scrypt`. languages: - python metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://tools.ietf.org/html/rfc6151 - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt category: security technology: - pycryptodome - hashlib - md5 subcategory: - vuln likelihood: HIGH impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/5DwD semgrep.dev: rule: r_id: 14703 rv_id: 1263504 rule_id: 6JU1w1 version_id: WrTqKDz url: https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: hashlib.md5 - pattern: hashlib.new(..., name="MD5", ...) - pattern: Cryptodome.Hash.MD5 - pattern: Crypto.Hash.MD5 - pattern: cryptography.hazmat.primitives.hashes.MD5 pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: ruby.lang.security.md5-used-as-password.md5-used-as-password languages: - ruby severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Instead, use a suitable password hashing function such as bcrypt. You can use the `bcrypt` gem. metadata: category: security technology: - md5 references: - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/GOZy semgrep.dev: rule: r_id: 14704 rv_id: 1263611 rule_id: oqU4p2 version_id: JdTzx0e url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - pattern: Digest::MD5 pattern-sinks: - patterns: - pattern: $FUNCTION(...); - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: json.aws.security.wildcard-assume-role.wildcard-assume-role patterns: - pattern-inside: | "Statement": [...] - pattern-inside: | {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} - pattern: | "Principal": {..., "AWS": "*", ...} message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone with your AWS account ID and the name of the role can assume the role. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - aws references: - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role shortlink: https://sg.run/7YEZ semgrep.dev: rule: r_id: 15138 rv_id: 1263256 rule_id: JDULx5 version_id: BjTkZoy url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role origin: community languages: - json severity: ERROR - id: ruby.rails.security.injection.tainted-url-host.tainted-url-host languages: - ruby severity: WARNING message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Use the `ssrf_filter` gem and guard the url construction with `SsrfFilter(...)`, or create an allowlist for approved hosts. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://github.com/arkadiyt/ssrf_filter cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/RX3g semgrep.dev: rule: r_id: 14705 rv_id: 1263668 rule_id: zdUY0W version_id: 6xT29BN url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sanitizers: - pattern: SsrfFilter pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | $URLSTR - pattern-regex: \w+:\/\/#{.*} - patterns: - pattern-either: - pattern: Kernel::sprintf("$URLSTR", ...) - pattern: | "$URLSTR" + $EXPR - pattern: | "$URLSTR" % $EXPR - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME:// ... - id: terraform.aws.security.wildcard-assume-role.wildcard-assume-role patterns: - pattern-inside: | resource "aws_iam_role" $NAME { ... } - pattern: assume_role_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-inside: | {..., "Effect": "Allow", ..., "Action": "sts:AssumeRole", ...} - pattern: | "Principal": {..., "AWS": "*", ...} message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone with your AWS account ID and the name of the role can assume the role. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - aws references: - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ owasp: - A06:2017 - Security Misconfiguration - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role shortlink: https://sg.run/LXWr semgrep.dev: rule: r_id: 15139 rv_id: 1263749 rule_id: 5rUL1P version_id: LjTkg8D url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0, 1.1, and 1.2. Azure Storage uses TLS 1.2 on public HTTPS endpoints, but TLS 1.0 and TLS 1.1 are still supported for backward compatibility. This check will warn if the minimum TLS is not set to TLS1_2.' patterns: - pattern-either: - pattern-inside: | resource "azurerm_storage_account" "..." { ... min_tls_version = "$ANYTHING" ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... } - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... min_tls_version = "TLS1_2" ... } metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version - https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy shortlink: https://sg.run/KXD7 semgrep.dev: rule: r_id: 15155 rv_id: 1263807 rule_id: AbUQdL version_id: WrTqKpv url: https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy origin: community languages: - hcl severity: ERROR - id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set metadata: cwe: - 'CWE-780: Use of RSA Algorithm without OAEP' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - scala - cryptography resources: - https://blog.codacy.com/9-scala-security-issues/ confidence: HIGH references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set shortlink: https://sg.run/GO5p semgrep.dev: rule: r_id: 15192 rv_id: 1263677 rule_id: 3qUj1Q version_id: yeTxpoX url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set origin: community message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken encryption. This could lead to sensitive data exposure. Instead, use RSA with `OAEPWithMD5AndMGF1Padding` instead. severity: WARNING languages: - scala patterns: - pattern: | $VAR = $CIPHER.getInstance($MODE) - metavariable-regex: metavariable: $MODE regex: .*RSA/.*/NoPadding.* - id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" to the bucket props for Bucket construct $X' metadata: cwe: - 'CWE-311: Missing Encryption of Sensitive Data' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption shortlink: https://sg.run/eowX semgrep.dev: rule: r_id: 15276 rv_id: 1263903 rule_id: bwU8qz version_id: GxTkeRx url: https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption origin: community languages: - typescript severity: ERROR pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3' ... - pattern: const $X = new Bucket(...) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...}) - pattern-not: | const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3' ... - pattern: const $X = new $Y.Bucket(...) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...}) - pattern-not: | const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...}) - id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl message: Bucket $X is not set to enforce encryption-in-transit, if not explictly setting this on the bucket policy - the property "enforceSSL" should be set to true metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl shortlink: https://sg.run/vqBX semgrep.dev: rule: r_id: 15277 rv_id: 1263904 rule_id: NbUN8B version_id: RGT0Llg url: https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl origin: community languages: - ts severity: ERROR pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3'; ... - pattern: const $X = new Bucket(...) - pattern-not: | const $X = new Bucket(..., {enforceSSL: true}, ...) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3'; ... - pattern: const $X = new $Y.Bucket(...) - pattern-not: | const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...}) - id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" or "encryption: $Y.QueueEncryption.KMS_MANAGED" to the queue props to enable encryption at rest for the queue.' metadata: category: security cwe: - 'CWE-311: Missing Encryption of Sensitive Data' technology: - AWS-CDK references: - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue shortlink: https://sg.run/d23P semgrep.dev: rule: r_id: 15278 rv_id: 1263905 rule_id: kxUwqO version_id: A8Tgd2W url: https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Queue} from '@aws-cdk/aws-sqs' ... - pattern: const $X = new Queue(...) - pattern-not: | const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-sqs' ... - pattern: const $X = new $Y.Queue(...) - pattern-not: | const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...}) - pattern-not: | const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...}) - id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod message: Using the GrantPublicAccess method on bucket contruct $X will make the objects in the bucket world accessible. Verify if this is intentional. metadata: cwe: - 'CWE-306: Missing Authentication for Critical Function' category: security technology: - AWS-CDK references: - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod shortlink: https://sg.run/Z4p7 semgrep.dev: rule: r_id: 15279 rv_id: 1263906 rule_id: wdUjZK version_id: BjTkZA7 url: https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Bucket} from '@aws-cdk/aws-s3' ... - pattern: | const $X = new Bucket(...) ... $X.grantPublicAccess(...) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-s3' ... - pattern: | const $X = new $Y.Bucket(...) ... $X.grantPublicAccess(...) - id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public message: CodeBuild Project $X is set to have a public URL. This will make the build results, logs, artifacts publically accessible, including builds prior to the project being public. Ensure this is acceptable for the project. metadata: category: security cwe: - 'CWE-306: Missing Authentication for Critical Function' technology: - AWS-CDK references: - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public shortlink: https://sg.run/nK7G semgrep.dev: rule: r_id: 15280 rv_id: 1263907 rule_id: x8UxXZ version_id: DkTRbj1 url: https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public origin: community languages: - ts severity: WARNING pattern-either: - patterns: - pattern-inside: | import {Project} from '@aws-cdk/aws-codebuild' ... - pattern: | const $X = new Project(..., {..., badge: true, ...}) - patterns: - pattern-inside: | import * as $Y from '@aws-cdk/aws-codebuild' ... - pattern: | const $X = new $Y.Project(..., {..., badge: true, ...}) - id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text mode: taint pattern-sinks: - pattern: | sqlalchemy.text(...) pattern-sources: - patterns: - pattern: | $X + $Y - metavariable-type: metavariable: $X type: string - patterns: - pattern: | $X + $Y - metavariable-type: metavariable: $Y type: string - patterns: - pattern: | f"..." - patterns: - pattern: | $X.format(...) - metavariable-type: metavariable: $X type: string - patterns: - pattern: | $X % $Y - metavariable-type: metavariable: $X type: string message: sqlalchemy.text passes the constructed SQL statement to the database mostly unchanged. This means that the usual SQL injection protections are not applied and this function is vulnerable to SQL injection if user input can reach here. Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct SQL. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - sqlalchemy confidence: MEDIUM references: - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text shortlink: https://sg.run/yP1O semgrep.dev: rule: r_id: 15824 rv_id: 1263577 rule_id: r6U2wE version_id: rxTAKqq url: https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text origin: community languages: - python severity: ERROR - id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code pattern-either: - patterns: - pattern: password = "..." - pattern-inside: | resource "aws_db_instance" "..." { ... } - patterns: - pattern: master_password = "..." - pattern-inside: | resource "aws_rds_cluster" "..." { ... } languages: - hcl severity: WARNING message: RDS instance or cluster with hardcoded credentials in source code. It is recommended to pass the credentials at runtime, or generate random credentials using the random_password resource. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password - https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password cwe: - 'CWE-522: Insufficiently Protected Credentials' category: security technology: - terraform - aws - secrets owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code shortlink: https://sg.run/x4qA semgrep.dev: rule: r_id: 15830 rv_id: 1263896 rule_id: OrUl6W version_id: gETB77b url: https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code origin: community - id: generic.ci.security.bash-reverse-shell.bash_reverse_shell metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - ci confidence: HIGH owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true subcategory: - audit likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell shortlink: https://sg.run/4l9l semgrep.dev: rule: r_id: 16200 rv_id: 1262664 rule_id: gxUJrJ version_id: jQTn5QE url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell origin: community message: Semgrep found a bash reverse shell severity: ERROR languages: - generic pattern-either: - pattern: | sh -i >& /dev/udp/.../... 0>&1 - pattern: | <...>/dev/tcp/.../...; sh <&... >&... 2>& - pattern: | <...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done - pattern: | sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>& - id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket patterns: - pattern: a - pattern: b languages: - hcl severity: INFO message: This rule has been deprecated, as all s3 buckets are encrypted by default with no way to disable it. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration for more info. metadata: references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html cwe: - 'CWE-311: Missing Encryption of Sensitive Data' category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM deprecated: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket shortlink: https://sg.run/Jezw semgrep.dev: rule: r_id: 16202 rv_id: 1263901 rule_id: 3qU62L version_id: JdTzxjN url: https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket origin: community - id: php.lang.security.injection.tainted-filename.tainted-filename severity: WARNING message: File name based on user input risks server-side request forgery. metadata: technology: - php category: security cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename shortlink: https://sg.run/Ayqp semgrep.dev: rule: r_id: 16250 rv_id: 1263287 rule_id: 5rUpro version_id: 7ZTE3J1 url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sanitizers: - patterns: - pattern-either: - pattern-inside: basename($PATH, ...) - pattern-inside: linkinfo($PATH, ...) - pattern-inside: readlink($PATH, ...) - pattern-inside: realpath($PATH, ...) pattern-sinks: - patterns: - pattern-either: - pattern-inside: opcache_compile_file($FILENAME, ...) - pattern-inside: opcache_invalidate($FILENAME, ...) - pattern-inside: opcache_is_script_cached($FILENAME, ...) - pattern-inside: runkit7_import($FILENAME, ...) - pattern-inside: readline_read_history($FILENAME, ...) - pattern-inside: readline_write_history($FILENAME, ...) - pattern-inside: rar_open($FILENAME, ...) - pattern-inside: zip_open($FILENAME, ...) - pattern-inside: gzfile($FILENAME, ...) - pattern-inside: gzopen($FILENAME, ...) - pattern-inside: readgzfile($FILENAME, ...) - pattern-inside: hash_file($ALGO, $FILENAME, ...) - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) - pattern-inside: pg_trace($FILENAME, ...) - pattern-inside: dio_open($FILENAME, ...) - pattern-inside: finfo_file($FINFO, $FILENAME, ...) - pattern-inside: mime_content_type($FILENAME, ...) - pattern-inside: chgrp($FILENAME, ...) - pattern-inside: chmod($FILENAME, ...) - pattern-inside: chown($FILENAME, ...) - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) - pattern-inside: file_exists($FILENAME, ...) - pattern-inside: file_get_contents($FILENAME, ...) - pattern-inside: file_put_contents($FILENAME, ...) - pattern-inside: file($FILENAME, ...) - pattern-inside: fileatime($FILENAME, ...) - pattern-inside: filectime($FILENAME, ...) - pattern-inside: filegroup($FILENAME, ...) - pattern-inside: fileinode($FILENAME, ...) - pattern-inside: filemtime($FILENAME, ...) - pattern-inside: fileowner($FILENAME, ...) - pattern-inside: fileperms($FILENAME, ...) - pattern-inside: filesize($FILENAME, ...) - pattern-inside: filetype($FILENAME, ...) - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) - pattern-inside: fopen($FILENAME, ...) - pattern-inside: is_dir($FILENAME, ...) - pattern-inside: is_executable($FILENAME, ...) - pattern-inside: is_file($FILENAME, ...) - pattern-inside: is_link($FILENAME, ...) - pattern-inside: is_readable($FILENAME, ...) - pattern-inside: is_uploaded_file($FILENAME, ...) - pattern-inside: is_writable($FILENAME, ...) - pattern-inside: lchgrp($FILENAME, ...) - pattern-inside: lchown($FILENAME, ...) - pattern-inside: lstat($FILENAME, ...) - pattern-inside: parse_ini_file($FILENAME, ...) - pattern-inside: readfile($FILENAME, ...) - pattern-inside: stat($FILENAME, ...) - pattern-inside: touch($FILENAME, ...) - pattern-inside: unlink($FILENAME, ...) - pattern-inside: xattr_get($FILENAME, ...) - pattern-inside: xattr_list($FILENAME, ...) - pattern-inside: xattr_remove($FILENAME, ...) - pattern-inside: xattr_set($FILENAME, ...) - pattern-inside: xattr_supported($FILENAME, ...) - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) - pattern-inside: pspell_new_personal($FILENAME, ...) - pattern-inside: exif_imagetype($FILENAME, ...) - pattern-inside: getimagesize($FILENAME, ...) - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) - pattern-inside: imagecreatefromavif($FILENAME, ...) - pattern-inside: imagecreatefrombmp($FILENAME, ...) - pattern-inside: imagecreatefromgd2($FILENAME, ...) - pattern-inside: imagecreatefromgd2part($FILENAME, ...) - pattern-inside: imagecreatefromgd($FILENAME, ...) - pattern-inside: imagecreatefromgif($FILENAME, ...) - pattern-inside: imagecreatefromjpeg($FILENAME, ...) - pattern-inside: imagecreatefrompng($FILENAME, ...) - pattern-inside: imagecreatefromtga($FILENAME, ...) - pattern-inside: imagecreatefromwbmp($FILENAME, ...) - pattern-inside: imagecreatefromwebp($FILENAME, ...) - pattern-inside: imagecreatefromxbm($FILENAME, ...) - pattern-inside: imagecreatefromxpm($FILENAME, ...) - pattern-inside: imageloadfont($FILENAME, ...) - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, ...) - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) - pattern-inside: fdf_open($FILENAME, ...) - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) - pattern-inside: posix_access($FILENAME, ...) - pattern-inside: posix_mkfifo($FILENAME, ...) - pattern-inside: posix_mknod($FILENAME, ...) - pattern-inside: ftok($FILENAME, ...) - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) - pattern-inside: fann_read_train_from_file($FILENAME, ...) - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) - pattern-inside: highlight_file($FILENAME, ...) - pattern-inside: php_strip_whitespace($FILENAME, ...) - pattern-inside: stream_resolve_include_path($FILENAME, ...) - pattern-inside: swoole_async_read($FILENAME, ...) - pattern-inside: swoole_async_readfile($FILENAME, ...) - pattern-inside: swoole_async_write($FILENAME, ...) - pattern-inside: swoole_async_writefile($FILENAME, ...) - pattern-inside: swoole_load_module($FILENAME, ...) - pattern-inside: tidy_parse_file($FILENAME, ...) - pattern-inside: tidy_repair_file($FILENAME, ...) - pattern-inside: get_meta_tags($FILENAME, ...) - pattern-inside: yaml_emit_file($FILENAME, ...) - pattern-inside: yaml_parse_file($FILENAME, ...) - pattern-inside: curl_file_create($FILENAME, ...) - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) - pattern-inside: ftp_delete($FTP, $FILENAME, ...) - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) - pattern-inside: ftp_size($FTP, $FILENAME, ...) - pattern-inside: rrd_create($FILENAME, ...) - pattern-inside: rrd_fetch($FILENAME, ...) - pattern-inside: rrd_graph($FILENAME, ...) - pattern-inside: rrd_info($FILENAME, ...) - pattern-inside: rrd_last($FILENAME, ...) - pattern-inside: rrd_lastupdate($FILENAME, ...) - pattern-inside: rrd_tune($FILENAME, ...) - pattern-inside: rrd_update($FILENAME, ...) - pattern-inside: snmp_read_mib($FILENAME, ...) - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) - pattern-inside: apache_lookup_uri($FILENAME, ...) - pattern-inside: md5_file($FILENAME, ...) - pattern-inside: sha1_file($FILENAME, ...) - pattern-inside: simplexml_load_file($FILENAME, ...) - pattern: $FILENAME - id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation languages: - php severity: WARNING message: <- A new object is created where the class name is based on user input. This could lead to remote code execution, as it allows to instantiate any class in the application. metadata: cwe: - 'CWE-470: Use of Externally-Controlled Input to Select Classes or Code (''Unsafe Reflection'')' category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation shortlink: https://sg.run/7ndw semgrep.dev: rule: r_id: 16438 rv_id: 1263288 rule_id: v8U4DA version_id: LjTkgLy url: https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sinks: - patterns: - pattern-either: - pattern-inside: new $SINK(...) - pattern: $SINK - id: terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials patterns: - pattern-inside: | provider "aws" { ... secret_key = "$SECRET" } - focus-metavariable: $SECRET message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). languages: - hcl severity: WARNING metadata: technology: - secrets - aws - terraform category: security cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials shortlink: https://sg.run/L3kn semgrep.dev: rule: r_id: 16439 rv_id: 1263735 rule_id: d8U4n0 version_id: rxTAK76 url: https://semgrep.dev/playground/r/rxTAK76/terraform.aws.security.aws-provider-static-credentials.aws-provider-static-credentials origin: community - id: php.laravel.security.laravel-sql-injection.laravel-sql-injection metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' category: security technology: - laravel references: - https://laravel.com/docs/8.x/queries cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection shortlink: https://sg.run/x40p semgrep.dev: rule: r_id: 16830 rv_id: 1263313 rule_id: j2UQdp version_id: BjTkZ45 url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection origin: community severity: WARNING message: Detected a SQL query based on user input. This could lead to SQL injection, which could potentially result in sensitive data being exfiltrated by attackers. Instead, use parameterized queries and prepared statements. languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: $_SERVER pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $SQL - pattern-either: - pattern-inside: DB::table(...)->whereRaw($SQL, ...) - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) - pattern-inside: DB::table(...)->havingRaw($SQL, ...) - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) - patterns: - pattern: $EXPRESSION - pattern-either: - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) - patterns: - pattern: $COLUMNS - pattern-either: - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) - pattern-inside: DB::table(...)->orWhereNull($COLUMN) - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) - pattern-inside: DB::table(...)->find($ID, $COLUMNS) - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) - pattern-inside: DB::table(...)->select($COLUMNS) - pattern-inside: DB::table(...)->get($COLUMNS) - pattern-inside: DB::table(...)->count($COLUMNS) - patterns: - pattern: $COLUMN - pattern-either: - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) - pattern-inside: DB::table(...)->having($COLUMN, ...) - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) - pattern-inside: DB::table(...)->orderByDesc($COLUMN) - pattern-inside: DB::table(...)->latest($COLUMN) - pattern-inside: DB::table(...)->oldest($COLUMN) - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) - pattern-inside: DB::table(...)->value($COLUMN) - pattern-inside: DB::table(...)->pluck($COLUMN, ...) - pattern-inside: DB::table(...)->implode($COLUMN, ...) - pattern-inside: DB::table(...)->min($COLUMN) - pattern-inside: DB::table(...)->max($COLUMN) - pattern-inside: DB::table(...)->sum($COLUMN) - pattern-inside: DB::table(...)->avg($COLUMN) - pattern-inside: DB::table(...)->average($COLUMN) - pattern-inside: DB::table(...)->increment($COLUMN, ...) - pattern-inside: DB::table(...)->decrement($COLUMN, ...) - pattern-inside: DB::table(...)->where($COLUMN, ...) - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) - pattern-inside: DB::table(...)->addSelect($COLUMN) - patterns: - pattern: $QUERY - pattern-inside: DB::unprepared($QUERY) - id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use HMAC instead. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::java.security owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 shortlink: https://sg.run/ryJn semgrep.dev: rule: r_id: 17325 rv_id: 1263013 rule_id: KxU5lW version_id: 0bTKzGX url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 origin: community patterns: - pattern: | java.security.MessageDigest.getInstance($ALGO, ...); - metavariable-regex: metavariable: $ALGO regex: (?i)(.MD5.) - focus-metavariable: $ALGO fix: | "SHA-512" - id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function applications. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::javax.crypto owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 shortlink: https://sg.run/bXNp semgrep.dev: rule: r_id: 17326 rv_id: 1263016 rule_id: qNUWNn version_id: l4TJRpL url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 origin: community pattern-either: - patterns: - pattern: | java.security.MessageDigest.getInstance("$ALGO", ...); - metavariable-regex: metavariable: $ALGO regex: (SHA1|SHA-1) - pattern: | $DU.getSha1Digest().digest(...) - id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version patterns: - pattern: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2018" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2019" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2021" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.2_2025" ... } ... } - pattern-not-inside: | resource "aws_cloudfront_distribution" $ANYTHING { ... viewer_certificate { ... minimum_protocol_version = "TLSv1.3_2025" ... } ... } message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS versions less than 1.2 are considered insecure because they can be broken. To fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", "TLSv1.2_2019", "TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version shortlink: https://sg.run/Q6o4 semgrep.dev: rule: r_id: 17342 rv_id: 1263700 rule_id: kxU6A8 version_id: 5PTo1bY url: https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention patterns: - pattern: | resource "aws_cloudwatch_log_group" $ANYTHING { ... } - pattern-not-inside: | resource "aws_cloudwatch_log_group" $ANYTHING { ... retention_in_days = ... ... } message: The AWS CloudWatch Log Group has no retention. Missing retention in log groups can cause losing important event information. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention shortlink: https://sg.run/4lwl semgrep.dev: rule: r_id: 17344 rv_id: 946665 rule_id: x8UGBG version_id: BjT1N2B url: https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention origin: community - id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted patterns: - pattern: | resource "aws_codebuild_project" $ANYTHING { ... } - pattern-not-inside: | resource "aws_codebuild_project" $ANYTHING { ... encryption_key = ... ... } message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects projects in the CodeBuild. To create your own, create a aws_kms_key resource or use the ARN string of a key in your account. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted shortlink: https://sg.run/5yxA semgrep.dev: rule: r_id: 17347 rv_id: 946669 rule_id: v8U4kG version_id: K3TJbNr url: https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted origin: community - id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging patterns: - pattern: | resource "aws_db_instance" $ANYTHING { ... } - pattern-not-inside: | resource "aws_db_instance" $ANYTHING { ... enabled_cloudwatch_logs_exports = [$SOMETHING, ...] ... } message: Database instance has no logging. Missing logs can cause missing important event information. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - vuln likelihood: MEDIUM impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging shortlink: https://sg.run/GyAp semgrep.dev: rule: r_id: 17348 rv_id: 1263704 rule_id: d8U4RA version_id: BjTkZ6j url: https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging origin: community - id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted patterns: - pattern: | resource "aws_dynamodb_table" $ANYTHING { ... } - pattern-not-inside: | resource "aws_dynamodb_table" $ANYTHING { ... server_side_encryption { enabled = true kms_key_arn = ... } ... } message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However, for added security, it's recommended to configure your own AWS KMS encryption key to protect your data in the DynamoDB table. You can either create a new aws_kms_key resource or use the ARN of an existing key in your AWS account to do so. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted shortlink: https://sg.run/Ay4p semgrep.dev: rule: r_id: 17350 rv_id: 1263707 rule_id: nJUGe2 version_id: 0bTKzj8 url: https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted origin: community - id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk patterns: - pattern: | resource "aws_ebs_snapshot_copy" $ANYTHING { ... encrypted = true ... } - pattern-not-inside: | resource "aws_ebs_snapshot_copy" $ANYTHING { ... encrypted = true kms_key_id = ... ... } message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk shortlink: https://sg.run/ByPW semgrep.dev: rule: r_id: 17351 rv_id: 946677 rule_id: EwUqko version_id: A8TJzb0 url: https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted patterns: - pattern: | resource "aws_ebs_encryption_by_default" $ANYTHING { ... enabled = false ... } message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the EBS. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted shortlink: https://sg.run/Dy5Y semgrep.dev: rule: r_id: 17352 rv_id: 946678 rule_id: 7KUW7K version_id: BjT1N2v url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted origin: community - id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip patterns: - pattern-either: - pattern: | resource "aws_instance" $ANYTHING { ... associate_public_ip_address = true ... } - pattern: | resource "aws_launch_template" $ANYTHING { ... network_interfaces { ... associate_public_ip_address = true ... } ... } message: EC2 instances should not have a public IP address attached in order to block public access to the instances. To fix this, set your `associate_public_ip_address` to `"false"`. metadata: category: security technology: - terraform - aws owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip shortlink: https://sg.run/08rv semgrep.dev: rule: r_id: 17354 rv_id: 1263709 rule_id: 8GUA2n version_id: qkTR73G url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk patterns: - pattern: | resource "aws_efs_file_system" $ANYTHING { ... encrypted = true ... } - pattern-not-inside: | resource "aws_efs_file_system" $ANYTHING { ... encrypted = true kms_key_id = ... ... } message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in terms of access and rotation. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk shortlink: https://sg.run/Kk07 semgrep.dev: rule: r_id: 17355 rv_id: 946690 rule_id: gxUJ4n version_id: 2KTYbWy url: https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled patterns: - pattern-either: - pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... node_to_node_encryption { ... enabled = false ... } ... } - pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... cluster_config { ... instance_count = $COUNT ... } } - pattern-not-inside: | resource "aws_elasticsearch_domain" $ANYTHING { ... cluster_config { ... instance_count = $COUNT ... } node_to_node_encryption { ... enabled = true ... } } - metavariable-comparison: metavariable: $COUNT comparison: $COUNT > 1 message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t" metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled shortlink: https://sg.run/lp3y semgrep.dev: rule: r_id: 17357 rv_id: 1263719 rule_id: 3qU6J7 version_id: WrTqK0v url: https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal patterns: - pattern-inside: | resource "aws_glacier_vault" $ANYTHING { ... } - pattern: access_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-inside: | {..., "Effect": "Allow", ...} - pattern-either: - pattern: | "Principal": "*" - pattern: | "Principal": {..., "AWS": "*", ...} - pattern-inside: | "Principal": {..., "AWS": ..., ...} - pattern-regex: | (^\"arn:aws:iam::\*:(.*)\"$) message: 'Detected wildcard access granted to Glacier Vault. This means anyone within your AWS account ID can perform actions on Glacier resources. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::`.' metadata: category: security technology: - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal shortlink: https://sg.run/XN9K semgrep.dev: rule: r_id: 17364 rv_id: 1263723 rule_id: AbUeYK version_id: l4TJRGB url: https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin patterns: - pattern-inside: | resource "aws_ssoadmin_permission_set_inline_policy" $ANYTHING { ... } - pattern: inline_policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} - pattern: | {..., "Action": "*", "Resource": "*", ...} - pattern: | {..., "Action": "*", "Resource": [...], ...} - pattern: | {..., "Action": [...], "Resource": "*", ...} message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative actions. Instead, limit actions and resources to what you need according to least privilege. metadata: category: security technology: - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin shortlink: https://sg.run/jzgY semgrep.dev: rule: r_id: 17365 rv_id: 1263724 rule_id: BYUzY5 version_id: YDTZe9q url: https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy patterns: - pattern-inside: | resource "aws_iam_policy" $ANYTHING { ... } - pattern: policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Action": [..., "*", ...], "Resource": [..., "*", ...], ...} - pattern: | {..., "Action": "*", "Resource": "*", ...} - pattern: | {..., "Action": "*", "Resource": [...], ...} - pattern: | {..., "Action": [...], "Resource": "*", ...} message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative actions. Instead, limit actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy shortlink: https://sg.run/1zbw semgrep.dev: rule: r_id: 17366 rv_id: 1263725 rule_id: DbUx8l version_id: 6xT29Pv url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration patterns: - pattern: | resource "aws_redshift_parameter_group" $ANYTHING { ... } - pattern-not-inside: | resource "aws_redshift_parameter_group" $ANYTHING { ... parameter { name = "require_ssl" value = "true" } ... } - pattern-not-inside: | resource "aws_redshift_parameter_group" $ANYTHING { ... parameter { name = "require_ssl" value = true } ... } message: Detected an AWS Redshift configuration with a SSL disabled. To fix this, set your `require_ssl` to `"true"`. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration shortlink: https://sg.run/yPYx semgrep.dev: rule: r_id: 17368 rv_id: 1263727 rule_id: 0oUrOj version_id: zyTb27A url: https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration origin: community languages: - hcl severity: WARNING - id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal patterns: - pattern-inside: | resource "aws_kms_key" $ANYTHING { ... } - pattern: policy = "$STATEMENT" - metavariable-pattern: metavariable: $STATEMENT language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": { "AWS": "*" }, "Action": "kms:*", "Resource": "*", ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, "Action": "kms:*", "Resource": "*", ...} message: Detected wildcard access granted in your KMS key. This means anyone with this policy can perform administrative actions over the keys. Instead, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal shortlink: https://sg.run/Nwlp semgrep.dev: rule: r_id: 17371 rv_id: 1263729 rule_id: lBUWPD version_id: 2KTv2J4 url: https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation patterns: - pattern-either: - pattern: | resource "aws_kms_key" $ANYTHING { ... enable_key_rotation = false ... } - pattern: | resource "aws_kms_key" $ANYTHING { ... customer_master_key_spec = "SYMMETRIC_DEFAULT" enable_key_rotation = false ... } - pattern: | resource "aws_kms_key" $ANYTHING { ... } - pattern-not-inside: | resource "aws_kms_key" $ANYTHING { ... enable_key_rotation = true ... } - pattern-not-inside: | resource "aws_kms_key" $ANYTHING { ... customer_master_key_spec = "RSA_2096" ... } message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be used by attackers. To fix this, set a `enable_key_rotation`. languages: - hcl severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' technology: - aws - terraform category: security references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation shortlink: https://sg.run/kz47 semgrep.dev: rule: r_id: 17372 rv_id: 1263730 rule_id: PeU0L3 version_id: X0Tzy67 url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation origin: community - id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials patterns: - pattern-inside: | resource "$ANYTING" $ANYTHING { ... environment { variables = { ... } } ... } - pattern-either: - pattern-inside: | AWS_ACCESS_KEY_ID = "$Y" - pattern-regex: | (? pattern-sinks: - patterns: - focus-metavariable: $X - pattern: | File.$METHOD($X,...) - metavariable-regex: metavariable: $METHOD regex: (?i)^(read|write) pattern-sanitizers: - pattern: | Path.GetFileName(...) - patterns: - pattern-inside: | $X = Path.GetFileName(...); ... - pattern: $X - patterns: - pattern: $X - pattern-inside: | if(<... Path.GetFileName($X) != $X ...>){ ... throw new $EXCEPTION(...); } ... message: String argument $A is used to read or write data from a file via Path.Combine without direct sanitization via Path.GetFileName. If the path is user-supplied data this can lead to path traversal. languages: - csharp severity: WARNING metadata: category: security confidence: MEDIUM references: - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks technology: - .net cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine shortlink: https://sg.run/1RvG semgrep.dev: rule: r_id: 18222 rv_id: 1262632 rule_id: 3qU3bE version_id: vdT0644 url: https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine origin: community - id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings severity: WARNING languages: - C# metadata: cwe: - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0 category: security technology: - .net confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings shortlink: https://sg.run/9LJr semgrep.dev: rule: r_id: 18223 rv_id: 1262633 rule_id: 4bUQ81 version_id: d6Tyx4K url: https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings origin: community message: The top level wildcard bindings $PREFIX leaves your application open to security vulnerabilities and give attackers more control over where traffic is routed. If you must use wildcards, consider using subdomain wildcard binding. For example, you can use "*.asdf.gov" if you own all of "asdf.gov". patterns: - pattern-inside: | using System.Net; ... - pattern: $LISTENER.Prefixes.Add("$PREFIX") - metavariable-regex: metavariable: $PREFIX regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+ - id: csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout severity: WARNING languages: - C# metadata: cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' owasp: A01:2017 - Injection references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0 category: security technology: - .net confidence: MEDIUM subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout shortlink: https://sg.run/NgRy semgrep.dev: rule: r_id: 18227 rv_id: 945224 rule_id: GdUDBP version_id: yeT0nDq url: https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout origin: community message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based Denial of Service (DoS) attack. Consider setting the timeout to a short amount of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double check that your context meets the conditions outlined in the "Notes to Callers" section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0' patterns: - pattern-inside: | using System.Text.RegularExpressions; ... - pattern-either: - pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout) - patterns: - pattern: new Regex(..., TimeSpan.FromSeconds($TIME)) - metavariable-comparison: metavariable: $TIME comparison: $TIME > 5 - pattern: new Regex(..., TimeSpan.FromMinutes(...)) - pattern: new Regex(..., TimeSpan.FromHours(...)) - id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | $XMLDOCUMENT.$METHOD(...) - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver = new XmlUrlResolver(...);\n... \n" message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override shortlink: https://sg.run/k98P semgrep.dev: rule: r_id: 18228 rv_id: 1262654 rule_id: ReUK9k version_id: K3TKk5E url: https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override origin: community - id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | XmlReader $READER = XmlReader.Create(...,$RS,...); - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing = DtdProcessing.Parse;\n... \n" message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override shortlink: https://sg.run/wXjA semgrep.dev: rule: r_id: 18229 rv_id: 1262655 rule_id: AbU3pX version_id: qkTR7WD url: https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override origin: community - id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | public $T $M(...,string $ARG,...){...} pattern-sinks: - patterns: - pattern: | $READER.$METHOD(...) - pattern-not-inside: | $READER.DtdProcessing = DtdProcessing.Prohibit; ... - pattern-inside: | XmlTextReader $READER = new XmlTextReader(...); ... message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied with user-controllable data. languages: - csharp severity: WARNING metadata: category: security references: - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks technology: - .net - xml cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults shortlink: https://sg.run/xXjL semgrep.dev: rule: r_id: 18230 rv_id: 1262656 rule_id: BYUevk version_id: l4TJRWG url: https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults origin: community - id: go.aws-lambda.security.database-sqli.database-sqli languages: - go message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' calls. mode: taint metadata: references: - https://pkg.go.dev/database/sql#DB.Query category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - database - sql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli shortlink: https://sg.run/e5e8 semgrep.dev: rule: r_id: 18232 rv_id: 1262909 rule_id: WAUdJ7 version_id: BjTkZkQ url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.Exec($QUERY,...) - pattern: $DB.ExecContent($QUERY,...) - pattern: $DB.Query($QUERY,...) - pattern: $DB.QueryContext($QUERY,...) - pattern: $DB.QueryRow($QUERY,...) - pattern: $DB.QueryRowContext($QUERY,...) - pattern-inside: | import "database/sql" ... pattern-sources: - patterns: - pattern-either: - pattern-inside: | func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} ... lambda.Start($HANDLER, ...) - patterns: - pattern-inside: | func $HANDLER($EVENT $TYPE) {...} ... lambda.Start($HANDLER, ...) - pattern-not-inside: | func $HANDLER($EVENT context.Context) {...} ... lambda.Start($HANDLER, ...) - focus-metavariable: $EVENT severity: WARNING - id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - go severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/vX3Y semgrep.dev: rule: r_id: 18233 rv_id: 1262910 rule_id: 0oUwqg version_id: DkTRbRL url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...} ... lambda.Start($HANDLER, ...) - patterns: - pattern-inside: | func $HANDLER($EVENT $TYPE) {...} ... lambda.Start($HANDLER, ...) - pattern-not-inside: | func $HANDLER($EVENT context.Context) {...} ... lambda.Start($HANDLER, ...) - focus-metavariable: $EVENT pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | "$SQLSTR" + ... - metavariable-regex: metavariable: $SQLSTR regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* - patterns: - pattern-either: - pattern: fmt.Fprintf($F, "$SQLSTR", ...) - pattern: fmt.Sprintf("$SQLSTR", ...) - pattern: fmt.Printf("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* - pattern-not-inside: | log.$PRINT(...) pattern-sanitizers: - pattern: strconv.Atoi(...) - id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse message: '`Clean` is not intended to sanitize against path traversal attacks. This function is for finding the shortest path name equivalent to the given input. Using `Clean` to sanitize file reads may expose this application to path traversal attacks, where an attacker could access arbitrary files on the server. To fix this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, "/")))` However, a better solution is using the `SecureJoin` function in the package `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' severity: ERROR languages: - go mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : *http.Request).$ANYTHING - pattern: | ($REQUEST : http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sinks: - patterns: - pattern-either: - pattern: filepath.Clean($...INNER) - pattern: path.Clean($...INNER) pattern-sanitizers: - pattern-either: - pattern: | "/" + ... fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) options: interfile: true metadata: references: - https://pkg.go.dev/path#Clean - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ - https://dzx.cz/2021/04/02/go_path_traversal/ - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - go cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse shortlink: https://sg.run/ZKzw semgrep.dev: rule: r_id: 18235 rv_id: 1262967 rule_id: qNUQJe version_id: jQTn5Bj url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse origin: community - id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - java severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. options: interfile: true metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/EBYN semgrep.dev: rule: r_id: 18237 rv_id: 1262977 rule_id: YGUl4z version_id: O9TpxQN url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - focus-metavariable: $EVENT - pattern-either: - pattern: | $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } - pattern: | $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$SQLSTR", ...) - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - pattern-not-inside: | System.out.$PRINTLN(...) - id: java.aws-lambda.security.tainted-sqli.tainted-sqli message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize user input instead. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - focus-metavariable: $EVENT - pattern-either: - pattern: | $HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } - pattern: | $HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" - pattern: | (java.sql.Statement $STMT) = ...; - pattern: | (java.sql.PreparedStatement $STMT) = ...; - pattern: | $VAR = $CONN.prepareStatement(...) - pattern: | $PATH.queryForObject(...); - pattern: | (java.util.Map $STMT) = $PATH.queryForMap(...); - pattern: | (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; - patterns: - pattern-inside: | (String $SQL) = "$SQLSTR" + ...; ... - pattern: $PATH.$SQLCMD(..., $SQL, ...); - metavariable-regex: metavariable: $SQLSTR regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) - metavariable-regex: metavariable: $SQLCMD regex: (execute|query|executeUpdate|batchUpdate) options: interfile: true metadata: category: security technology: - sql - java - aws-lambda cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli shortlink: https://sg.run/7942 semgrep.dev: rule: r_id: 18238 rv_id: 1262978 rule_id: 6JUDWk version_id: e1Tyj4g url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli origin: community - id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request message: Detected input from a HTTPServletRequest going into a SQL sink or statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize user input instead. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' cwe2021-top25: true cwe2022-top25: true owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html - https://owasp.org/www-community/attacks/SQL_Injection subcategory: - vuln technology: - sql - java - servlets - spring license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request shortlink: https://sg.run/Lg56 semgrep.dev: rule: r_id: 18239 rv_id: 1409390 rule_id: oqUBJG version_id: 7ZTKJNj url: https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request origin: community languages: - java mode: taint options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ).$REQFUNC(...) - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" - metavariable-regex: metavariable: $REQFUNC regex: (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) pattern-sinks: - patterns: - pattern-either: - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" - pattern: | (java.sql.Statement $STMT) = ...; ... $OUTPUT = $STMT.$FUNC(...); - pattern: | (java.sql.PreparedStatement $STMT) = ...; - pattern: | $VAR = $CONN.prepareStatement(...) - pattern: | $PATH.queryForObject(...); - pattern: | (java.util.Map $STMT) = $PATH.queryForMap(...); - pattern: | (org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...; - pattern: | (org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...) - patterns: - pattern-inside: | (String $SQL) = "$SQLSTR" + ...; ... - pattern: $PATH.$SQLCMD(..., $SQL, ...); - metavariable-regex: metavariable: $SQLSTR regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) - metavariable-regex: metavariable: $SQLCMD regex: (execute|query|executeUpdate|batchUpdate) - id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' or 'exec' command. This could lead to command injection if variables passed into the exec commands are not properly sanitized. Instead, avoid using these OS commands with user-supplied input, or, if you must use these commands, use a whitelist of specific values. languages: - java severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (ProcessBuilder $PB) = ...; - patterns: - pattern: | (Process $P) = ...; - pattern-not: | (Process $P) = (java.lang.Runtime $R).exec(...); - patterns: - pattern: (java.lang.Runtime $R).exec($CMD, ...); - focus-metavariable: $CMD - patterns: - pattern-either: - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n...\n$PB.command($ARGLIST);\n" - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n" - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process $P) = ...;\n" - pattern: | $ARGLIST.add(...); metadata: category: security technology: - java cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request shortlink: https://sg.run/8zPN semgrep.dev: rule: r_id: 18240 rv_id: 1263042 rule_id: zdUWrg version_id: LjTkg9J url: https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request origin: community - id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request message: Detected input from a HTTPServletRequest going into an LDAP query. This could lead to LDAP injection if the input is not properly sanitized, which could result in attackers modifying objects in the LDAP tree structure. Ensure data passed to an LDAP query is not controllable or properly sanitize the data. metadata: cwe: - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection category: security technology: - java subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - LDAP Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request shortlink: https://sg.run/gRg0 semgrep.dev: rule: r_id: 18241 rv_id: 1409392 rule_id: pKUXAv version_id: 8KT3Pe6 url: https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request origin: community severity: WARNING languages: - java mode: taint pattern-sources: - patterns: - pattern: (HttpServletRequest $REQ) pattern-sinks: - patterns: - pattern-either: - pattern: | (javax.naming.directory.InitialDirContext $IDC).search(...) - pattern: | (javax.naming.directory.DirContext $CTX).search(...) - pattern-not: | (javax.naming.directory.InitialDirContext $IDC).search($Y, "...", ...) - pattern-not: | (javax.naming.directory.DirContext $CTX).search($Y, "...", ...) - id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request message: Detected input from a HTTPServletRequest going into a session command, like `setAttribute`. User input into such a command could lead to an attacker inputting malicious code into your session parameters, blurring the line between what's trusted and untrusted, and therefore leading to a trust boundary violation. This could lead to programmers trusting unvalidated data. Instead, thoroughly sanitize user input before passing it into such function calls. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - patterns: - pattern: | (HttpServletRequest $REQ).$FUNC(...) - pattern-not: | (HttpServletRequest $REQ).getSession() - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) - patterns: - pattern-inside: | $TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... ); ... - pattern: | $PARAM = $VALS[$INDEX]; - patterns: - pattern-inside: | $HEADERS = (HttpServletRequest $REQ).getHeaders(...); ... $PARAM = $HEADERS.$FUNC(...); ... - pattern: | java.net.URLDecoder.decode($PARAM, ...) pattern-sinks: - patterns: - pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE); - metavariable-regex: metavariable: $FUNC regex: ^(putValue|setAttribute)$ - focus-metavariable: $VALUE options: interfile: true metadata: category: security technology: - java cwe: - 'CWE-501: Trust Boundary Violation' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request shortlink: https://sg.run/QbDZ semgrep.dev: rule: r_id: 18242 rv_id: 1409393 rule_id: 2ZU7Eo version_id: gETrv9j url: https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request origin: community - id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request message: Detected input from a HTTPServletRequest going into a XPath evaluate or compile command. This could lead to xpath injection if variables passed into the evaluate or compile commands are not properly sanitized. Xpath injection could lead to unauthorized access to sensitive information in XML documents. Instead, thoroughly sanitize user input or use parameterized xpath queries if you can. languages: - java severity: WARNING mode: taint pattern-sources: - patterns: - pattern: | (HttpServletRequest $REQ).$FUNC(...) pattern-sinks: - patterns: - pattern-either: - pattern: | (javax.xml.xpath.XPath $XP).evaluate(...) - pattern: | (javax.xml.xpath.XPath $XP).compile(...).evaluate(...) metadata: category: security technology: - java cwe: - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XPath Injection source: https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request shortlink: https://sg.run/3BvK semgrep.dev: rule: r_id: 18243 rv_id: 1409394 rule_id: X5U5nj version_id: QkTERKP url: https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request origin: community - id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false shortlink: https://sg.run/4Dv5 semgrep.dev: rule: r_id: 18244 rv_id: 1263057 rule_id: j2UrJ8 version_id: 0bTKzgX url: https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false origin: community message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external entity declarations, this is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. patterns: - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", false); - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $DBF.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); ... } - pattern-not-inside: | $RETURNTYPE $METHOD(...){ ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, ""); ... $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing shortlink: https://sg.run/PYBz semgrep.dev: rule: r_id: 18245 rv_id: 1263058 rule_id: 10UPQB version_id: K3TKk80 url: https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing origin: community message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = DocumentBuilderFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = DocumentBuilderFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newDocumentBuilder(); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); $FACTORY.newDocumentBuilder(); languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true shortlink: https://sg.run/JgPy semgrep.dev: rule: r_id: 18246 rv_id: 1263059 rule_id: 9AUJ6r version_id: qkTR7Lk url: https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true origin: community message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-general-entities" to false. pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", true); fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); languages: - java - id: java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true shortlink: https://sg.run/5Lv0 semgrep.dev: rule: r_id: 18247 rv_id: 1263060 rule_id: yyUNeo version_id: l4TJRoL url: https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true origin: community message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this by setting the feature "http://xml.org/sax/features/external-parameter-entities" to false. pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", true); fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); languages: - java - id: javascript.aws-lambda.security.detect-child-process.detect-child-process message: Allowing spawning arbitrary programs or running shell processes with arbitrary arguments may end up in a command injection vulnerability. Try to avoid non-literal values for the command string. If it is not possible, then do not let running arbitrary commands, use a white list for inputs. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - javascript - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process shortlink: https://sg.run/Ggoq semgrep.dev: rule: r_id: 18248 rv_id: 1263105 rule_id: r6UDNQ version_id: YDTZe4o url: https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: exec($CMD,...) - pattern: execSync($CMD,...) - pattern: spawn($CMD,...) - pattern: spawnSync($CMD,...) - pattern: $CP.exec($CMD,...) - pattern: $CP.execSync($CMD,...) - pattern: $CP.spawn($CMD,...) - pattern: $CP.spawnSync($CMD,...) - pattern-either: - pattern-inside: | require('child_process') ... - pattern-inside: | import 'child_process' ... - id: javascript.aws-lambda.security.knex-sqli.knex-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `knex.raw(''SELECT $1 from table'', [userinput])`' metadata: references: - https://knexjs.org/#Builder-fromRaw - https://knexjs.org/#Builder-whereRaw category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - knex cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli shortlink: https://sg.run/RgWq semgrep.dev: rule: r_id: 18249 rv_id: 1263106 rule_id: bwUBlj version_id: JdTzxKg url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $KNEX.fromRaw($QUERY, ...) - pattern: $KNEX.whereRaw($QUERY, ...) - pattern: $KNEX.raw($QUERY, ...) - pattern-either: - pattern-inside: | require('knex') ... - pattern-inside: | import 'knex' ... - id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `connection.query(''SELECT $1 from table'', [userinput])`' metadata: references: - https://www.npmjs.com/package/mysql2 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql - mysql2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli shortlink: https://sg.run/A502 semgrep.dev: rule: r_id: 18250 rv_id: 1263107 rule_id: NbUBJ2 version_id: 5PTo1En url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $POOL.query($QUERY, ...) - pattern: $POOL.execute($QUERY, ...) - pattern-either: - pattern-inside: | require('mysql') ... - pattern-inside: | require('mysql2') ... - pattern-inside: | require('mysql2/promise') ... - pattern-inside: | import 'mysql' ... - pattern-inside: | import 'mysql2' ... - pattern-inside: | import 'mysql2/promise' ... - id: javascript.aws-lambda.security.pg-sqli.pg-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `connection.query(''SELECT $1 from table'', [userinput])`' metadata: references: - https://node-postgres.com/features/queries category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - postgres - pg cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli shortlink: https://sg.run/BGKA semgrep.dev: rule: r_id: 18251 rv_id: 1263108 rule_id: kxU25P version_id: GxTkeJL url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.query($QUERY, ...) - pattern-either: - pattern-inside: | require('pg') ... - pattern-inside: | import 'pg' ... - id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli message: 'Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `sequelize.query(''SELECT * FROM projects WHERE status = ?'', { replacements: [''active''], type: QueryTypes.SELECT });`' metadata: references: - https://sequelize.org/master/manual/raw-queries.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sequelize cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli shortlink: https://sg.run/DAlP semgrep.dev: rule: r_id: 18252 rv_id: 1263109 rule_id: wdUA5o version_id: RGT0LrD url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $DB.query($QUERY, ...) - pattern-either: - pattern-inside: | require('sequelize') ... - pattern-inside: | import 'sequelize' ... - id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/0Gvj semgrep.dev: rule: r_id: 18254 rv_id: 1263111 rule_id: OrUJBY version_id: BjTkZ8D url: https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - focus-metavariable: $BODY - pattern-inside: | {..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... } - id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection message: The `vm` module enables compiling and running code within V8 Virtual Machine contexts. The `vm` module is not a security mechanism. Do not use it to run untrusted code. If code passed to `vm` functions is controlled by user input it could result in command injection. Do not let user input in `vm` functions. metadata: owasp: - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' category: security technology: - javascript - aws-lambda cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection shortlink: https://sg.run/q9w7 semgrep.dev: rule: r_id: 18256 rv_id: 1263114 rule_id: v8UOdZ version_id: 0bTKz9J url: https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - pattern-either: - pattern-inside: | require('vm'); ... - pattern-inside: | import 'vm' ... - pattern-either: - pattern: $VM.runInContext($X,...) - pattern: $VM.runInNewContext($X,...) - pattern: $VM.runInThisContext($X,...) - pattern: $VM.compileFunction($X,...) - pattern: new $VM.Script($X,...) - pattern: new $VM.SourceTextModule($X,...) - pattern: runInContext($X,...) - pattern: runInNewContext($X,...) - pattern: runInThisContext($X,...) - pattern: compileFunction($X,...) - pattern: new Script($X,...) - pattern: new SourceTextModule($X,...) - id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli message: 'Detected SQL statement that is tainted by `$REQ` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared statements. An example of parameterized queries like so: `knex.raw(''SELECT $1 from table'', [userinput])` can help prevent SQLi.' metadata: confidence: MEDIUM references: - https://knexjs.org/#Builder-fromRaw - https://knexjs.org/#Builder-whereRaw - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - express - nodejs - knex cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli shortlink: https://sg.run/l9eE semgrep.dev: rule: r_id: 18257 rv_id: 1263205 rule_id: d8UKLD version_id: l4TJRey url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options) - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern-inside: $KNEX.fromRaw($QUERY, ...) - pattern-inside: $KNEX.whereRaw($QUERY, ...) - pattern-inside: $KNEX.raw($QUERY, ...) - pattern-either: - pattern-inside: | require('knex') ... - pattern-inside: | import 'knex' ... pattern-sanitizers: - patterns: - pattern: parseInt(...) - id: php.lang.security.deserialization.extract-user-data mode: taint pattern-sources: - pattern-either: - pattern: $_GET[...] - pattern: $_FILES[...] - pattern: $_POST[...] pattern-sinks: - pattern: extract(...) pattern-sanitizers: - pattern: extract($VAR, EXTR_SKIP,...) message: Do not call 'extract()' on user-controllable data. If you must, then you must also provide the EXTR_SKIP flag to prevent overwriting existing variables. languages: - php metadata: category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures technology: - php references: - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data shortlink: https://sg.run/6bv1 semgrep.dev: rule: r_id: 18259 rv_id: 1263278 rule_id: nJUykq version_id: w8TRovw url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data origin: community severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) message: Detected 'create_subprocess_exec' function with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec - https://docs.python.org/3/library/shlex.html category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec shortlink: https://sg.run/oyv0 semgrep.dev: rule: r_id: 18260 rv_id: 1263331 rule_id: EwUrX8 version_id: rxTAKgo url: https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec shortlink: https://sg.run/z14d semgrep.dev: rule: r_id: 18261 rv_id: 1263332 rule_id: 7KUxXg version_id: bZT53Ww url: https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) - pattern: asyncio.create_subprocess_shell($CMD, ...) message: Detected asyncio subprocess function with argument tainted by `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-subprocess.html - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell shortlink: https://sg.run/p9vZ semgrep.dev: rule: r_id: 18262 rv_id: 1263333 rule_id: L1UEl7 version_id: NdTzyWA url: https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell origin: community languages: - python severity: ERROR - id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process mode: taint message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach this function call because it allows a malicious actor to execute commands. Ensure no external data reaches here. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - python - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process shortlink: https://sg.run/2AjL semgrep.dev: rule: r_id: 18263 rv_id: 1263334 rule_id: 8GUGBq version_id: kbTzGv8 url: https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - patterns: - pattern: os.$METHOD($MODE, $CMD, ...) - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) - patterns: - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) - metavariable-regex: metavariable: $METHOD regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use mode: taint message: Detected subprocess function with argument tainted by an `event` object. If this data can be controlled by a malicious actor, it may be an instance of command injection. The default option for `shell` is False, and this is secure by default. Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` means you have to split the command string into an array of strings for the command and its arguments. You may consider using 'shlex.split()' for this purpose. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/subprocess.html - https://docs.python.org/3/library/shlex.html category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use shortlink: https://sg.run/XZ7B semgrep.dev: rule: r_id: 18264 rv_id: 1263335 rule_id: gxUyn1 version_id: w8TRogj url: https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern: subprocess.$FUNC(..., shell=True, ...) pattern-sanitizers: - pattern: shlex.split(...) - pattern: pipes.quote(...) - pattern: shlex.quote(...) - id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call mode: taint message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach this function call because it allows a malicious actor to execute commands. Use the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection vulnerability. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call shortlink: https://sg.run/jDvN semgrep.dev: rule: r_id: 18265 rv_id: 1263336 rule_id: QrUkg6 version_id: xyTjzbG url: https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call origin: community languages: - python severity: ERROR pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $CMD - pattern-either: - pattern: os.system($CMD,...) - pattern: os.popen($CMD,...) - pattern: os.popen2($CMD,...) - pattern: os.popen3($CMD,...) - pattern: os.popen4($CMD,...) - id: python.aws-lambda.security.mysql-sqli.mysql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', (''active''))`' mode: taint metadata: references: - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli shortlink: https://sg.run/1RjG semgrep.dev: rule: r_id: 18266 rv_id: 1263337 rule_id: 3qU3eE version_id: O9TpxLJ url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $CURSOR.execute($QUERY,...) - pattern: $CURSOR.executemany($QUERY,...) - pattern-either: - pattern-inside: | import mysql ... - pattern-inside: | import mysql.cursors ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', ''active'')`' mode: taint metadata: references: - https://www.psycopg.org/docs/cursor.html#cursor.execute - https://www.psycopg.org/docs/cursor.html#cursor.executemany - https://www.psycopg.org/docs/cursor.html#cursor.mogrify category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - psycopg - psycopg2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli shortlink: https://sg.run/9L8r semgrep.dev: rule: r_id: 18267 rv_id: 1263338 rule_id: 4bUQG1 version_id: e1TyjPZ url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern-either: - pattern: $CURSOR.execute($QUERY,...) - pattern: $CURSOR.executemany($QUERY,...) - pattern: $CURSOR.mogrify($QUERY,...) - pattern-inside: | import psycopg2 ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', ''active'')`' mode: taint metadata: references: - https://pypi.org/project/pymssql/ category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - pymssql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli shortlink: https://sg.run/yXvP semgrep.dev: rule: r_id: 18268 rv_id: 1263339 rule_id: PeUxO0 version_id: vdT06bG url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-inside: | import pymssql ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = %s'', (''active''))`' mode: taint metadata: references: - https://pypi.org/project/PyMySQL/#id4 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - pymysql cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli shortlink: https://sg.run/reve semgrep.dev: rule: r_id: 18269 rv_id: 1263340 rule_id: JDUlel version_id: d6TyxNA url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-either: - pattern-inside: | import pymysql ... - pattern-inside: | import pymysql.cursors ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli languages: - python message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `cursor.execute(''SELECT * FROM projects WHERE status = ?'', ''active'')`' mode: taint metadata: references: - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sqlalchemy cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli shortlink: https://sg.run/b48W semgrep.dev: rule: r_id: 18270 rv_id: 1263341 rule_id: 5rUy3N version_id: ZRTKARp url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli origin: community pattern-sinks: - patterns: - focus-metavariable: $QUERY - pattern: $CURSOR.execute($QUERY,...) - pattern-inside: | import sqlalchemy ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: WARNING - id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern-either: - pattern: eval($CODE, ...) - pattern: exec($CODE, ...) message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec shortlink: https://sg.run/Ng7y semgrep.dev: rule: r_id: 18271 rv_id: 1263342 rule_id: GdUDJP version_id: nWT2LD2 url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec origin: community languages: - python severity: WARNING - id: python.aws-lambda.security.tainted-html-response.tainted-html-response mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern: $BODY - pattern-inside: | {..., "headers": {..., "Content-Type": "text/html", ...}, "body": $BODY, ... } message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/k9vP semgrep.dev: rule: r_id: 18272 rv_id: 1263343 rule_id: ReUKrk version_id: ExTEx5o url: https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response origin: community languages: - python severity: WARNING - id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - python message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://owasp.org/www-community/attacks/SQL_Injection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/wXvA semgrep.dev: rule: r_id: 18273 rv_id: 1263346 rule_id: AbU3LX version_id: 8KT5ron url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR" % ... - pattern: | "$SQLSTR".format(...) - pattern: | f"$SQLSTR{...}..." - metavariable-regex: metavariable: $SQLSTR regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= - pattern-not-inside: | print(...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... severity: ERROR - id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT title FROM posts WHERE author = ? AND created > ?", author_id, start_date]`' mode: taint metadata: references: - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - active-record cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli shortlink: https://sg.run/vXvY semgrep.dev: rule: r_id: 18277 rv_id: 1263581 rule_id: 0oUw9g version_id: w8TRor7 url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: ActiveRecord::Base.connection.execute($QUERY,...) - pattern: $MODEL.find_by_sql($QUERY,...) - pattern: $MODEL.select_all($QUERY,...) - pattern-inside: | require 'active_record' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' mode: taint metadata: references: - https://github.com/brianmario/mysql2 category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - mysql2 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli shortlink: https://sg.run/dJLE semgrep.dev: rule: r_id: 18278 rv_id: 1263582 rule_id: KxUrQ3 version_id: xyTjzOe url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: $CLIENT.query($QUERY,...) - pattern: $CLIENT.prepare($QUERY,...) - pattern-inside: | require 'mysql2' ... pattern-sanitizers: - pattern: $CLIENT.escape(...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.pg-sqli.pg-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `conn.exec_params(''SELECT $1 AS a, $2 AS b, $3 AS c'', [1, 2, nil])`' mode: taint metadata: references: - https://www.rubydoc.info/gems/pg/PG/Connection category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - postgres - pg cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli shortlink: https://sg.run/ZKww semgrep.dev: rule: r_id: 18279 rv_id: 1263583 rule_id: qNUQee version_id: O9Tpxz7 url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: $CONN.exec($QUERY,...) - pattern: $CONN.exec_params($QUERY,...) - pattern: $CONN.exec_prepared($QUERY,...) - pattern: $CONN.async_exec($QUERY,...) - pattern: $CONN.async_exec_params($QUERY,...) - pattern: $CONN.async_exec_prepared($QUERY,...) - pattern-inside: | require 'pg' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli languages: - ruby message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can use parameterized statements like so: `DB[''select * from items where name = ?'', name]`' mode: taint metadata: references: - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda - sequel cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli shortlink: https://sg.run/n9vY semgrep.dev: rule: r_id: 18280 rv_id: 1263584 rule_id: lBUy2N version_id: e1Tyj5j url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli origin: community pattern-sinks: - patterns: - pattern: $QUERY - pattern-either: - pattern: DB[$QUERY,...] - pattern: DB.run($QUERY,...) - pattern-inside: | require 'sequel' ... pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string languages: - ruby severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. metadata: references: - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet category: security owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/EB7N semgrep.dev: rule: r_id: 18281 rv_id: 1263586 rule_id: PeUxOE version_id: d6Tyx1Z url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | "...#{...}..." - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* - patterns: - pattern-either: - pattern: Kernel::sprintf("$SQLSTR", ...) - pattern: | "$SQLSTR" + $EXPR - pattern: | "$SQLSTR" % $EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* - pattern-not-inside: | puts(...) - id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings patterns: - pattern: secure = false - pattern-inside: | session = { ... } message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag for cookies prevents the client from transmitting the cookie over insecure channels such as HTTP. Set the `Secure` flag by setting `secure` to `true` in configuration file. languages: - generic severity: WARNING paths: include: - '*.conf' metadata: category: security references: - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security - https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration technology: - play - scala cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration confidence: MEDIUM subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings shortlink: https://sg.run/8z8N semgrep.dev: rule: r_id: 18284 rv_id: 1263685 rule_id: GdUDJO version_id: e1TyjJv url: https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings origin: community - id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli mode: taint metadata: references: - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - scala - slick - play confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli shortlink: https://sg.run/k9K2 semgrep.dev: rule: r_id: 18328 rv_id: 1263687 rule_id: GdUDWO version_id: d6TyxJe url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli origin: community message: Detected a tainted SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Avoid using using user input for generating SQL strings. pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sinks: - patterns: - pattern-either: - pattern: $MODEL.overrideSql(...) - pattern: sql"..." - pattern-inside: | import slick.$DEPS ... severity: ERROR languages: - scala - id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check patterns: - pattern-inside: | import ("github.com/gorilla/websocket") ... - patterns: - pattern-not-inside: | $UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...} ... - pattern-not-inside: | $UPGRADER.CheckOrigin = $FN2 ... - pattern: | $UPGRADER.Upgrade(...) message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee that the connection accepted by the WebSocket is from a trusted origin domain. Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" documentation: "A CheckOrigin function should carefully validate the request origin to prevent cross-site request forgery."' languages: - go severity: WARNING metadata: category: security cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader technology: - gorilla confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check shortlink: https://sg.run/xXpz semgrep.dev: rule: r_id: 18430 rv_id: 1262914 rule_id: ReUKdz version_id: qkTR7RP url: https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check origin: community - id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string shortlink: https://sg.run/Lgqr semgrep.dev: rule: r_id: 18483 rv_id: 1263112 rule_id: PeUxwW version_id: DkTRbvp url: https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern: $EVENT pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$HTMLSTR" + $EXPR - pattern: | "$HTMLSTR".concat(...) - pattern: $UTIL.format($HTMLSTR, ...) - pattern: format($HTMLSTR, ...) - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - patterns: - pattern: | `...${...}...` - pattern-regex: | .*<\w+.* - pattern-not-inside: | console.$LOG(...) - id: python.aws-lambda.security.tainted-html-string.tainted-html-string languages: - python severity: WARNING message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. Otherwise, use templates which will safely render HTML instead. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - aws-lambda references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string shortlink: https://sg.run/8zNy semgrep.dev: rule: r_id: 18484 rv_id: 1263344 rule_id: JDUlwy version_id: 7ZTE36K url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string origin: community mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: '"$HTMLSTR" % ...' - pattern: '"$HTMLSTR".format(...)' - pattern: '"$HTMLSTR" + ...' - pattern: f"$HTMLSTR{...}..." - patterns: - pattern-inside: | $HTML = "$HTMLSTR" ... - pattern-either: - pattern: $HTML % ... - pattern: $HTML.format(...) - pattern: $HTML + ... - metavariable-pattern: metavariable: $HTMLSTR language: generic pattern: <$TAG ... - pattern-not-inside: | print(...) - id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf patterns: - pattern-either: - pattern: Source.fromURL($URL,...) - pattern: Source.fromURI($URL,...) - pattern-inside: | import scala.io.$SOURCE ... - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } message: A parameter being passed directly into `fromURL` most likely lead to SSRF. This could allow an attacker to send data to their own server, potentially exposing sensitive data sent with this request. They could also probe internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource category: security technology: - scala confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf shortlink: https://sg.run/Qbz4 semgrep.dev: rule: r_id: 18486 rv_id: 1263675 rule_id: GdUDOZ version_id: 1QTypG9 url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf origin: community languages: - scala severity: WARNING - id: scala.lang.security.audit.scalac-debug.scalac-debug patterns: - pattern-either: - pattern: scalacOptions ... "-Vdebug" - pattern: scalacOptions ... "-Ydebug" message: Scala applications built with `debug` set to true in production may leak debug information to attackers. Debug mode also affects performance and reliability. Remove it from configuration. languages: - generic severity: WARNING paths: include: - '*.sbt*' metadata: category: security cwe: - 'CWE-489: Active Debug Code' owasp: A05:2021 - Security Misconfiguration technology: - scala - sbt references: - https://docs.scala-lang.org/overviews/compiler-options/index.html confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Active Debug Code source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug shortlink: https://sg.run/QbGd semgrep.dev: rule: r_id: 18686 rv_id: 946569 rule_id: JDUlE0 version_id: qkT4j0N url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug origin: community - id: scala.play.security.tainted-html-response.tainted-html-response mode: taint metadata: category: security cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection technology: - scala - play confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response shortlink: https://sg.run/BG96 semgrep.dev: rule: r_id: 18795 rv_id: 1263686 rule_id: 0oUwn2 version_id: vdT06yj url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response origin: community message: Detected a request with potential user-input going into an `Ok()` response. This bypasses any view or template environments, including HTML escaping, which may expose this application to cross-site scripting (XSS) vulnerabilities. Consider using a view technology such as Twirl which automatically escapes HTML views. pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sanitizers: - pattern-either: - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) - pattern: org.owasp.encoder.Encode.forHtml(...) pattern-sinks: - pattern-either: - pattern: Html.apply(...) - pattern: Ok(...).as(HTML) - pattern: Ok(...).as(ContentTypes.HTML) - patterns: - pattern: Ok(...).as($CTYPE) - metavariable-regex: metavariable: $CTYPE regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' - patterns: - pattern: Ok(...).as($CTYPE) - pattern-not: Ok(...).as("...") - pattern-either: - pattern-inside: | def $FUNC(..., $URL: $T, ...) = $A { ... } - pattern-inside: | def $FUNC(..., $URL: $T, ...) = { ... } severity: WARNING languages: - scala - id: terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version patterns: - pattern-either: - pattern: | resource "aws_api_gateway_domain_name" $ANYTHING { ... security_policy = "..." ... } - pattern: | resource "aws_apigatewayv2_domain_name" $ANYTHING { ... domain_name_configuration {...} ... } - pattern-not: | resource "aws_api_gateway_domain_name" $ANYTHING { ... security_policy = "TLS_1_2" ... } - pattern-not: | resource "aws_apigatewayv2_domain_name" $ANYTHING { ... domain_name_configuration { ... security_policy = "TLS_1_2" ... } } message: Detected AWS API Gateway to be using an insecure version of TLS. To fix this issue make sure to set "security_policy" equal to "TLS_1_2". languages: - terraform severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - aws - terraform references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version shortlink: https://sg.run/p98J semgrep.dev: rule: r_id: 18818 rv_id: 1263726 rule_id: v8UOle version_id: o5TbD8k url: https://semgrep.dev/playground/r/o5TbD8k/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version origin: community - id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv patterns: - pattern-either: - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); - metavariable-comparison: metavariable: $M comparison: re.match(".*-CBC",$M) message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext attacks against encrypted data. languages: - php severity: ERROR metadata: cwe: - 'CWE-329: Generation of Predictable IV with CBC Mode' references: - https://csrc.nist.gov/publications/detail/sp/800-38a/final owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures technology: - php - openssl category: security subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv shortlink: https://sg.run/LgWJ semgrep.dev: rule: r_id: 19039 rv_id: 1263295 rule_id: DbUGbE version_id: JdTzxOD url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv origin: community - id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode patterns: - pattern-inside: | import pdi.jwt.$DEPS ... - pattern-either: - pattern: $JWT.encode($X, "...", ...) - pattern: $JWT.decode($X, "...", ...) - pattern: $JWT.decodeRawAll($X, "...", ...) - pattern: $JWT.decodeRaw($X, "...", ...) - pattern: $JWT.decodeAll($X, "...", ...) - pattern: $JWT.validate($X, "...", ...) - pattern: $JWT.isValid($X, "...", ...) - pattern: $JWT.decodeJson($X, "...", ...) - pattern: $JWT.decodeJsonAll($X, "...", ...) - patterns: - pattern-either: - pattern: $JWT.encode($X, $KEY, ...) - pattern: $JWT.decode($X, $KEY, ...) - pattern: $JWT.decodeRawAll($X, $KEY, ...) - pattern: $JWT.decodeRaw($X, $KEY, ...) - pattern: $JWT.decodeAll($X, $KEY, ...) - pattern: $JWT.validate($X, $KEY, ...) - pattern: $JWT.isValid($X, $KEY, ...) - pattern: $JWT.decodeJson($X, $KEY, ...) - pattern: $JWT.decodeJsonAll($X, $KEY, ...) - pattern: $JWT.encode($X, this.$KEY, ...) - pattern: $JWT.decode($X, this.$KEY, ...) - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) - pattern: $JWT.decodeRaw($X, this.$KEY, ...) - pattern: $JWT.decodeAll($X, this.$KEY, ...) - pattern: $JWT.validate($X, this.$KEY, ...) - pattern: $JWT.isValid($X, this.$KEY, ...) - pattern: $JWT.decodeJson($X, this.$KEY, ...) - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) - pattern-either: - pattern-inside: | class $CL { ... $KEY = "..." ... } - pattern-inside: | object $CL { ... $KEY = "..." ... } - metavariable-pattern: metavariable: $JWT patterns: - pattern-either: - pattern: Jwt - pattern: JwtArgonaut - pattern: JwtCirce - pattern: JwtJson4s - pattern: JwtJson - pattern: JwtUpickle message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' languages: - scala severity: WARNING metadata: references: - https://jwt-scala.github.io/jwt-scala/ category: security cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design technology: - scala confidence: HIGH cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode shortlink: https://sg.run/8zE7 semgrep.dev: rule: r_id: 19040 rv_id: 1263669 rule_id: WAUdK0 version_id: o5TbDA8 url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode origin: community - id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled patterns: - pattern-either: - pattern: | $DF = DocumentBuilderFactory.newInstance(...) ... $DB = $DF.newDocumentBuilder(...) - patterns: - pattern: $DB = DocumentBuilderFactory.newInstance(...) - pattern-not-inside: | ... $X = $DB.newDocumentBuilder(...) - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $DB.setXIncludeAware(true) ... $DB.setNamespaceAware(true) ... $DB.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $DB.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $DB.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) message: Document Builder being instantiated without calling the `setFeature` functions that are generally used for disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled shortlink: https://sg.run/gRQn semgrep.dev: rule: r_id: 19041 rv_id: 1263673 rule_id: 0oUwzP version_id: X0TzyRq url: https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled origin: community - id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled patterns: - pattern-either: - pattern: $SR = new SAXReader(...) - pattern: | $SF = SAXParserFactory.newInstance(...) ... $SR = $SF.newSAXParser(...) - patterns: - pattern: $SR = SAXParserFactory.newInstance(...) - pattern-not-inside: | ... $X = $SR.newSAXParser(...) - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) - pattern: $SR = new SAXBuilder(...) - pattern-not-inside: | ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) - pattern-not-inside: | ... $SR.setFeature("http://xml.org/sax/features/external-general-entities", false) ... $SR.setFeature("http://xml.org/sax/features/external-parameter-entities", false) ... $SR.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) message: XML processor being instantiated without calling the `setFeature` functions that are generally used for disabling entity processing. User controlled data in XML Parsers can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled shortlink: https://sg.run/QbYP semgrep.dev: rule: r_id: 19042 rv_id: 1263678 rule_id: KxUrkq version_id: rxTAKWY url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled origin: community - id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled patterns: - pattern-not-inside: | ... $XMLFACTORY.setProperty("javax.xml.stream.isSupportingExternalEntities", false) - pattern-either: - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) - pattern: $XMLFACTORY = new XMLInputFactory(...) message: XMLInputFactory being instantiated without calling the setProperty functions that are generally used for disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), port scanning. Make sure to disable entity processing functionality. languages: - scala severity: WARNING metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html category: security technology: - scala confidence: HIGH references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled shortlink: https://sg.run/3BEb semgrep.dev: rule: r_id: 19043 rv_id: 1263683 rule_id: qNUQ7w version_id: xyTjzkA url: https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled origin: community - id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass patterns: - pattern-either: - pattern: X-Requested-With = "*" - pattern: Csrf-Token = "..." - pattern-inside: | bypassHeaders {... ... ...} - pattern-not-inside: | {... ... ...blackList = [..."application/x-www-form-urlencoded"..."multipart/form-data"..."text/plain"...] ... ...} - pattern-not-inside: | {... ... ...blackList = [..."application/x-www-form-urlencoded"..."text/plain"..."multipart/form-data"...] ... ...} - pattern-not-inside: | {... ... ...blackList = [..."multipart/form-data"..."application/x-www-form-urlencoded"..."text/plain"...] ... ...} - pattern-not-inside: | {... ... ...blackList = [..."multipart/form-data"..."text/plain"..."application/x-www-form-urlencoded"...] ... ...} - pattern-not-inside: | {... ... ...blackList = [..."text/plain"..."application/x-www-form-urlencoded"..."multipart/form-data"...] ... ...} - pattern-not-inside: | {... ... ...blackList = [..."text/plain"..."multipart/form-data"..."application/x-www-form-urlencoded"...] ... ...} message: "Possibly bypassable CSRF configuration found. CSRF is an attack that forces an end user to execute unwanted actions on a web application in which they\u2019re currently authenticated. Make sure that Content-Type black list is configured and CORS filter is turned on." languages: - generic severity: ERROR paths: include: - '*.conf' metadata: references: - https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes - https://owasp.org/www-community/attacks/csrf cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - scala - play confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass shortlink: https://sg.run/4DEE semgrep.dev: rule: r_id: 19044 rv_id: 1263684 rule_id: lBUyRR version_id: O9Tpx53 url: https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass origin: community - id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version pattern: | resource "aws_elasticsearch_domain" $ANYTHING { ... domain_endpoint_options { ... enforce_https = true tls_security_policy = "Policy-Min-TLS-1-0-2019-07" ... } ... } message: Detected an AWS Elasticsearch domain using an insecure version of TLS. To fix this, set "tls_security_policy" equal to "Policy-Min-TLS-1-2-2019-07". languages: - terraform severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - aws - terraform references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version shortlink: https://sg.run/PYlq semgrep.dev: rule: r_id: 19045 rv_id: 1263718 rule_id: YGUle7 version_id: DkTRbA5 url: https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version origin: community - id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage message: User data from `$REQ` is being compiled into the template, which can lead to a Server Side Template Injection (SSTI) vulnerability. options: interfile: true metadata: interfile: true category: security cwe: - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' owasp: - A03:2021 - Injection - A01:2017 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html technology: - javascript - typescript - express - pug - jade - dot - ejs - nunjucks - lodash - handlbars - mustache - hogan.js - eta - squirrelly source_rule_url: - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage shortlink: https://sg.run/b49v semgrep.dev: rule: r_id: 19226 rv_id: 1263165 rule_id: EwUr9k version_id: zyTb2eD url: https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-propagators: - pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) from: $E to: $S pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $PUG = require('pug') ... - pattern-inside: | import * as $PUG from 'pug' ... - pattern-inside: | $PUG = require('jade') ... - pattern-inside: | import * as $PUG from 'jade' ... - pattern-either: - pattern: $PUG.compile(...) - pattern: $PUG.compileClient(...) - pattern: $PUG.compileClientWithDependenciesTracked(...) - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('dot') ... - pattern-inside: | import * as $PUG from 'dot' ... - pattern-either: - pattern: $PUG.template(...) - pattern: $PUG.compile(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('ejs') ... - pattern-inside: | import * as $PUG from 'ejs' ... - pattern-either: - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('nunjucks') ... - pattern-inside: | import * as $PUG from 'nunjucks' ... - pattern-either: - pattern: $PUG.renderString(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('lodash') ... - pattern-inside: | import * as $PUG from 'lodash' ... - pattern-either: - pattern: $PUG.template(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('mustache') ... - pattern-inside: | import * as $PUG from 'mustache' ... - pattern-inside: | $PUG = require('eta') ... - pattern-inside: | import * as $PUG from 'eta' ... - pattern-inside: | $PUG = require('squirrelly') ... - pattern-inside: | import * as $PUG from 'squirrelly' ... - pattern-either: - pattern: $PUG.render(...) - patterns: - pattern-either: - pattern-inside: | $PUG = require('hogan.js') ... - pattern-inside: | import * as $PUG from 'hogan.js' ... - pattern-inside: | $PUG = require('handlebars') ... - pattern-inside: | import * as $PUG from 'handlebars' ... - pattern-either: - pattern: $PUG.compile(...) - id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled patterns: - pattern: jinja2.Environment(... , autoescape=$VAL, ...) - pattern-not: jinja2.Environment(... , autoescape=True, ...) - pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...), ...) - focus-metavariable: $VAL fix: | True message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous if you are rendering to a browser because this allows for cross-site scripting (XSS) attacks. If you are in a web context, enable 'autoescaping' by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' to only enable automatic escaping for certain file extensions. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html cwe: - 'CWE-116: Improper Encoding or Escaping of Output' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://jinja.palletsprojects.com/en/2.11.x/api/#basics category: security technology: - jinja2 subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Encoding source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled shortlink: https://sg.run/L2L7 semgrep.dev: rule: r_id: 20039 rv_id: 1263448 rule_id: QrU1Xg version_id: gETB7oN url: https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled origin: community languages: - python severity: WARNING - id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled patterns: - pattern-not: jinja2.Environment(..., autoescape=$VAL, ...) - pattern: jinja2.Environment(...) fix-regex: regex: (.*)\) replacement: \1, autoescape=True) message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape by default. This is dangerous if you are rendering to a browser because this allows for cross-site scripting (XSS) attacks. If you are in a web context, enable autoescaping by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' to only enable automatic escaping for certain file extensions. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html cwe: - 'CWE-116: Improper Encoding or Escaping of Output' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://jinja.palletsprojects.com/en/2.11.x/api/#basics category: security technology: - jinja2 subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Encoding source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled shortlink: https://sg.run/8kY4 semgrep.dev: rule: r_id: 20040 rv_id: 1263449 rule_id: 3qULRx version_id: QkTGqje url: https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled origin: community languages: - python severity: WARNING - id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include mode: search paths: include: - '*.erb' patterns: - pattern: | params[...] - pattern-inside: | render :file => ... message: Found request parameters in a call to `render` in a dynamic context. This can allow end users to request arbitrary local files which may result in leaking sensitive information persisted on disk. languages: - generic severity: WARNING metadata: technology: - ruby - rails category: security cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb references: - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion - https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include shortlink: https://sg.run/3QWl semgrep.dev: rule: r_id: 20043 rv_id: 1263651 rule_id: JDUokO version_id: QkTGq9X url: https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include origin: community - id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include mode: taint pattern-sources: - patterns: - pattern: params[...] pattern-sinks: - patterns: - pattern-either: - pattern: | render ..., file: $X - pattern: | render ..., inline: $X - pattern: | render ..., template: $X - pattern: | render ..., action: $X - pattern: | render $X, ... - focus-metavariable: $X pattern-sanitizers: - patterns: - pattern: $MAP[...] - metavariable-pattern: metavariable: $MAP patterns: - pattern-not-regex: params - pattern: File.basename(...) message: Found request parameters in a call to `render`. This can allow end users to request arbitrary local files which may result in leaking sensitive information persisted on disk. Where possible, avoid letting users specify template paths for `render`. If you must allow user input, use an allow-list of known templates or normalize the user-supplied value with `File.basename(...)`. languages: - ruby severity: WARNING metadata: technology: - ruby - rails category: security cwe: - 'CWE-22: Improper Limitation of a Pathname to a Restricted Directory (''Path Traversal'')' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb references: - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM vulnerability_class: - Path Traversal license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include shortlink: https://sg.run/Jw8Z semgrep.dev: rule: r_id: 20046 rv_id: 1409407 rule_id: ReU2pZ version_id: K3TgANN url: https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include origin: community - id: ruby.rails.security.brakeman.check-secrets.check-secrets patterns: - pattern: $VAR = "$VALUE" - metavariable-regex: metavariable: $VAR regex: (?i)password|secret|(rest_auth_site|api)_key$ - metavariable-regex: metavariable: $VALUE regex: .+ message: Found a Brakeman-style secret - a variable with the name password/secret/api_key/rest_auth_site_key and a non-empty string literal value. languages: - ruby severity: WARNING metadata: technology: - ruby - rails category: security cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_secrets.rb references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html - https://github.com/presidentbeef/brakeman/blob/3f5d5d5f00864cdf7769c50f5bd26f1769a4ba75/test/apps/rails3.1/app/controllers/users_controller.rb cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-secrets.check-secrets shortlink: https://sg.run/5ZKl semgrep.dev: rule: r_id: 20047 rv_id: 1263659 rule_id: AbUNqO version_id: A8TgdBv url: https://semgrep.dev/playground/r/A8TgdBv/ruby.rails.security.brakeman.check-secrets.check-secrets origin: community - id: ruby.rails.security.brakeman.check-send-file.check-send-file mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: | send_file ... message: Allowing user input to `send_file` allows a malicious user to potentially read arbitrary files from the server. Avoid accepting user input in `send_file` or normalize with `File.basename(...)` languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb category: security cwe: - 'CWE-73: External Control of File Name or Path' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design technology: - ruby - rails references: - https://owasp.org/www-community/attacks/Path_Traversal - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file shortlink: https://sg.run/GbY1 semgrep.dev: rule: r_id: 20048 rv_id: 1263660 rule_id: BYUKbl version_id: BjTkZRj url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file origin: community - id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string languages: - scala severity: ERROR mode: taint message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html category: security technology: - scala confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/ALD6 semgrep.dev: rule: r_id: 20050 rv_id: 1263682 rule_id: WAUY8B version_id: w8TRoO6 url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string origin: community pattern-sources: - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = $A { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) { ... } pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".format(...) - patterns: - pattern-inside: | $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR" ... - pattern: $VAR += ... - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - patterns: - pattern-either: - pattern: s"..." - pattern: f"..." - pattern-regex: | .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* - pattern-not-inside: println(...) - pattern-not-inside: throw new $EXCEPTION(...) pattern-sanitizers: - pattern-either: - patterns: - pattern-either: - pattern: $LOGGER.$METHOD(...) - pattern: $LOGGER(...) - metavariable-regex: metavariable: $LOGGER regex: (i?)log.* - patterns: - pattern: $LOGGER.$METHOD(...) - metavariable-regex: metavariable: $METHOD regex: (i?)(trace|info|warn|warning|warnToError|error|debug) - id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request languages: - scala severity: ERROR mode: taint message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html category: security technology: - scala - play confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request shortlink: https://sg.run/BeW9 semgrep.dev: rule: r_id: 20051 rv_id: 1263688 rule_id: 0oUpon version_id: ZRTKAoG url: https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request origin: community pattern-sources: - patterns: - pattern-either: - patterns: - pattern: $REQ - pattern-either: - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" - patterns: - pattern: $PARAM - pattern-either: - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async { ... } - pattern-inside: | def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) { ... } pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".format(...) - patterns: - pattern-inside: | $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR" ... - pattern: $VAR += ... - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - patterns: - pattern: s"..." - pattern-regex: | .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.* - pattern-not-inside: println(...) - id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file patterns: - pattern: | $KEY: $VALUE - pattern-inside: | data: ... - pattern-inside: | kind: Secret ... - metavariable-regex: metavariable: $VALUE regex: (?i)^[aA-zZ0-9+/]+={0,2}$ - metavariable-analysis: analyzer: entropy metavariable: $VALUE message: 'Secrets ($VALUE) should not be stored in infrastructure as code files. Use an alternative such as Bitnami Sealed Secrets or KSOPS to encrypt Kubernetes Secrets. ' metadata: cwe: - 'CWE-798: Use of Hard-coded Credentials' category: security technology: - kubernetes references: - https://kubernetes.io/docs/concepts/configuration/secret/ - https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF - https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html - https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/ - https://github.com/bitnami-labs/sealed-secrets - https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/ - https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/ owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file shortlink: https://sg.run/KyL6 semgrep.dev: rule: r_id: 20055 rv_id: 1263942 rule_id: YGUYEb version_id: xyTjz5B url: https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file origin: community languages: - yaml severity: WARNING - id: dockerfile.security.last-user-is-root.last-user-is-root patterns: - pattern: USER root - pattern-not-inside: patterns: - pattern: | USER root ... USER $X - metavariable-pattern: metavariable: $X patterns: - pattern-not: root message: The last user in the container is 'root'. This is a security hazard because if an attacker gains control of the container they will have root access. Switch back to another user after running commands as 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-269: Improper Privilege Management' source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 references: - https://github.com/hadolint/hadolint/wiki/DL3002 category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root shortlink: https://sg.run/5Z43 semgrep.dev: rule: r_id: 20147 rv_id: 1262658 rule_id: ReU2n5 version_id: 6xT29Eg url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root origin: community - id: dockerfile.security.missing-user.missing-user patterns: - pattern: | CMD $...VARS - pattern-not-inside: | USER $USER ... - pattern-not-inside: | HEALTHCHECK ... CMD ... fix: | USER non-root CMD $...VARS message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-250: Execution with Unnecessary Privileges' category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user shortlink: https://sg.run/Gbvn semgrep.dev: rule: r_id: 20148 rv_id: 1262660 rule_id: AbUN06 version_id: zyTb2n2 url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user origin: community - id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends selecting Argon2id unless you can guarantee an adversary has no direct access to the computing environment. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html - https://eprint.iacr.org/2016/759.pdf - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf - https://datatracker.ietf.org/doc/html/rfc9106#section-4 category: security cwe: - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' technology: - argon2 - cryptography owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln impact: LOW likelihood: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config shortlink: https://sg.run/ALq4 semgrep.dev: rule: r_id: 20150 rv_id: 1263103 rule_id: DbU2X8 version_id: qkTR7Jk url: https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-inside: | $ARGON = require('argon2'); ... - pattern: | {type: ...} pattern-sinks: - patterns: - pattern: | $Y - pattern-inside: | $ARGON.hash(...,$Y) pattern-sanitizers: - patterns: - pattern: '{type: $ARGON.argon2id}' - id: ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling patterns: - pattern-either: - patterns: - pattern: | :$KEY => "$LITERAL" - pattern-inside: | ActionController::Base.session = {...} - pattern: | $RAILS::Application.config.$KEY = "$LITERAL" - pattern: | Rails.application.config.$KEY = "$LITERAL" - metavariable-regex: metavariable: $KEY regex: ^secret(_(token|key_base))?$ message: Found a string literal assignment to a Rails session secret `$KEY`. Do not commit secret values to source control! Any user in possession of this value may falsify arbitrary session data in your application. Read this value from an environment variable, KMS, or file on disk outside of source control. languages: - ruby severity: WARNING metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_session_settings.rb category: security cwe: - 'CWE-540: Inclusion of Sensitive Information in Source Code' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - ruby - rails references: - https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/02-Testing_for_Cookies_Attributes - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails4_with_engines/config/initializers/secret_token.rb - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3/config/initializers/secret_token.rb subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling shortlink: https://sg.run/KyJd semgrep.dev: rule: r_id: 20155 rv_id: 1263656 rule_id: lBUX1r version_id: 5PTo1ZY url: https://semgrep.dev/playground/r/5PTo1ZY/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling origin: community - id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] - patterns: - pattern: $Y - pattern-either: - pattern-inside: | $RECORD.read_attribute($Y) - pattern-inside: | $RECORD[$Y] - metavariable-regex: metavariable: $RECORD regex: '[A-Z][a-z]+' pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: $Y - pattern-inside: | /...#{...}.../ - patterns: - pattern: $Y - pattern-inside: | Regexp.new(...) message: Found a potentially user-controllable argument in the construction of a regular expressions. This may result in excessive resource consumption when applied to certain inputs, or when the user is allowed to control the match target. Avoid allowing users to specify regular expressions processed by the server. If you must support user-controllable input in a regular expression, use an allow-list to restrict the expressions users may supply to limit catastrophic backtracking. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb category: security cwe: - 'CWE-1333: Inefficient Regular Expression Complexity' owasp: - A03:2017 - Sensitive Data Exposure technology: - ruby - rails references: - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Denial-of-Service (DoS) source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos shortlink: https://sg.run/qZwx semgrep.dev: rule: r_id: 20156 rv_id: 1409406 rule_id: YGUY4R version_id: 0bTG0WO url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos origin: community - id: ruby.rails.security.brakeman.check-before-filter.check-before-filter mode: search patterns: - pattern-either: - pattern: | skip_filter ..., :except => $ARGS - pattern: | skip_before_filter ..., :except => $ARGS - pattern: | skip_before_action ..., :except => $ARGS message: 'Disabled-by-default Rails controller checks make it much easier to introduce access control mistakes. Prefer an allowlist approach with `:only => [...]` rather than `except: => [...]`' languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_skip_before_filter.rb category: security cwe: - 'CWE-284: Improper Access Control' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - ruby - rails references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-before-filter.check-before-filter shortlink: https://sg.run/O4Zn semgrep.dev: rule: r_id: 20531 rv_id: 1263649 rule_id: wdUkBP version_id: 8KT5rDy url: https://semgrep.dev/playground/r/8KT5rDy/ruby.rails.security.brakeman.check-before-filter.check-before-filter origin: community - id: ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion mode: search patterns: - pattern: | if request.get? ... else ... end - pattern-not-inside: | if ... elsif ... ... end message: Found an improperly constructed control flow block with `request.get?`. Rails will route HEAD requests as GET requests but they will fail the `request.get?` check, potentially causing unexpected behavior unless an `elif` condition is used. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_verb_confusion.rb category: security cwe: - 'CWE-650: Trusting HTTP Permission Methods on the Server Side' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design technology: - ruby - rails references: - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/accounts_controller.rb subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion shortlink: https://sg.run/eJ6y semgrep.dev: rule: r_id: 20532 rv_id: 1263652 rule_id: x8UdDE version_id: 3ZT4X82 url: https://semgrep.dev/playground/r/3ZT4X82/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion origin: community - id: ruby.rails.security.brakeman.check-sql.check-sql mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sanitizers: - patterns: - pattern-either: - patterns: - pattern: $X - pattern-either: - pattern-inside: | :$KEY => $X - pattern-inside: | ["...",$X,...] - pattern: | params[...].to_i - pattern: | params[...].to_f - patterns: - pattern: | params[...] ? $A : $B - metavariable-pattern: metavariable: $A patterns: - pattern-not: | params[...] - metavariable-pattern: metavariable: $B patterns: - pattern-not: | params[...] pattern-sinks: - patterns: - pattern: $X - pattern-not-inside: | $P.where("...",...) - pattern-not-inside: | $P.where(:$KEY => $VAL,...) - pattern-either: - pattern-inside: | $P.$M(...) - pattern-inside: | $P.$M("...",...) - pattern-inside: | class $P < ActiveRecord::Base ... end - metavariable-regex: metavariable: $M regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) message: Found potential SQL injection due to unsafe SQL query construction via $X. Where possible, prefer parameterized queries. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://owasp.org/www-community/attacks/SQL_Injection - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql shortlink: https://sg.run/vpgb semgrep.dev: rule: r_id: 20533 rv_id: 1263661 rule_id: OrUv2z version_id: DkTRbE4 url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql origin: community - id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: $X - pattern-either: - pattern-inside: | $X. ... .to_proc - patterns: - pattern-inside: | $Y.method($Z) - focus-metavariable: $Z - patterns: - pattern-inside: | $Y.tap($Z) - focus-metavariable: $Z - patterns: - pattern-inside: | $Y.tap{ |$ANY| $Z } - focus-metavariable: $Z message: Found user-controllable input to a reflection method. This may allow a user to alter program behavior and potentially execute arbitrary instructions in the context of the process. Do not provide arbitrary user input to `tap`, `method`, or `to_proc` languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods shortlink: https://sg.run/dPYd semgrep.dev: rule: r_id: 20534 rv_id: 1263662 rule_id: eqUZ2Q version_id: WrTqKLA url: https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods origin: community - id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase message: Found the use of an hardcoded passphrase for RSA. The passphrase can be easily discovered, and therefore should not be stored in source-code. It is recommended to remove the passphrase from source-code, and use system environment variables or a restricted configuration file. languages: - ruby severity: WARNING metadata: technology: - ruby - secrets category: security references: - https://cwe.mitre.org/data/definitions/522.html cwe: - 'CWE-798: Use of Hard-coded Credentials' owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase shortlink: https://sg.run/xPEe semgrep.dev: rule: r_id: 20730 rv_id: 1263607 rule_id: bwULyN version_id: K3TKkEo url: https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase origin: community patterns: - pattern-either: - pattern: OpenSSL::PKey::RSA.new(..., '...') - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') - patterns: - pattern-inside: | $OPENSSL = OpenSSL::PKey::RSA.new(...) ... - pattern-either: - pattern: | $OPENSSL.export(...,'...') - pattern: | $OPENSSL.to_pem(...,'...') - patterns: - pattern-either: - patterns: - pattern-inside: | $ASSIGN = '...' ... - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = '...' ... end ... def $METHOD2(...) ... end - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) - patterns: - pattern-inside: | $ASSIGN = '...' ... def $METHOD(...) $OPENSSL = OpenSSL::PKey::RSA.new(...) ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $OPENSSL = OpenSSL::PKey::RSA.new(...) ... $ASSIGN = '...' ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = '...' ... end ... def $METHOD2(...) ... $OPENSSL = OpenSSL::PKey::RSA.new(...) ... end ... - pattern-either: - pattern: $OPENSSL.export(...,$ASSIGN) - pattern: $OPENSSL.to_pem(...,$ASSIGN) - id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended to use a key length of 2048 or higher. languages: - ruby severity: WARNING metadata: technology: - ruby category: security references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size shortlink: https://sg.run/O4Re semgrep.dev: rule: r_id: 20731 rv_id: 1263608 rule_id: NbUe4N version_id: qkTR76v url: https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size origin: community patterns: - pattern-either: - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) - patterns: - pattern-either: - patterns: - pattern-inside: | $ASSIGN = $SIZE ... - pattern-either: - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) - patterns: - pattern-inside: | def $METHOD1(...) ... $ASSIGN = $SIZE ... end ... - pattern-either: - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) - metavariable-comparison: metavariable: $SIZE comparison: $SIZE < 2048 - id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to mode: taint pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: cookies - pattern: request.env - pattern: url_for(params[...],...,:only_path => false,...) pattern-sanitizers: - patterns: - pattern-either: - patterns: - pattern: | $F(...) - metavariable-pattern: metavariable: $F patterns: - pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to) - pattern: | params.merge! :only_path => true ... - pattern: | params.slice(...) ... - pattern: | redirect_to [...] - patterns: - pattern: | $MODEL. ... .$M(...) ... - metavariable-regex: metavariable: $MODEL regex: '[A-Z]\w+' - metavariable-regex: metavariable: $M regex: (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take) - patterns: - pattern: | params.$UNSAFE_HASH.merge(...,:only_path => true,...) ... - metavariable-regex: metavariable: $UNSAFE_HASH regex: to_unsafe_h(ash)? - patterns: - pattern: params.permit(...,$X,...) - metavariable-pattern: metavariable: $X patterns: - pattern-not-regex: (host|port|(sub)?domain) pattern-sinks: - patterns: - pattern: $X - pattern-inside: | redirect_to $X, ... - pattern-not-regex: params\.\w+(? true` hash value. languages: - ruby severity: WARNING metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb category: security cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' technology: - ruby - rails references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to shortlink: https://sg.run/eJNX semgrep.dev: rule: r_id: 20732 rv_id: 1263657 rule_id: kxUOJ6 version_id: GxTke14 url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to origin: community - id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern: $X - pattern-either: - pattern-inside: | $X.constantize - pattern-inside: | $X. ... .safe_constantize - pattern-inside: | const_get(...) - pattern-inside: | qualified_const_get(...) message: Found user-controllable input to Ruby reflection functionality. This allows a remote user to influence runtime behavior, up to and including arbitrary remote code execution. Do not provide user-controllable input to reflection functionality. Do not call symbol conversion on user-controllable input. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection technology: - ruby - rails references: - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection shortlink: https://sg.run/vpEX semgrep.dev: rule: r_id: 20733 rv_id: 1263663 rule_id: wdUkYA version_id: 0bTKzn8 url: https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection origin: community - id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find mode: taint pattern-sources: - pattern-either: - pattern: | cookies[...] - patterns: - pattern: | cookies. ... .$PROPERTY[...] - metavariable-regex: metavariable: $PROPERTY regex: (?!signed|encrypted) - pattern: | params[...] - pattern: | request.env[...] pattern-sinks: - patterns: - pattern-either: - pattern: $MODEL.find(...) - pattern: $MODEL.find_by_id(...) - pattern: $MODEL.find_by_id!(...) - metavariable-regex: metavariable: $MODEL regex: '[A-Z]\S+' message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord model being searched against is sensitive, this may lead to Insecure Direct Object Reference (IDOR) behavior and allow users to read arbitrary records. Scope the find to the current user, e.g. `current_user.accounts.find(params[:id])`. languages: - ruby severity: WARNING metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb category: security cwe: - 'CWE-639: Authorization Bypass Through User-Controlled Key' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - ruby - rails references: - https://brakemanscanner.org/docs/warning_types/unscoped_find/ - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find shortlink: https://sg.run/dPbP semgrep.dev: rule: r_id: 20734 rv_id: 1263664 rule_id: x8Ud6d version_id: K3TKkxZ url: https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find origin: community - id: ruby.rails.security.brakeman.check-validation-regex.check-validation-regex mode: search patterns: - pattern-either: - pattern: | validates ..., :format => <... $V ...>,... - pattern: | validates_format_of ..., :with => <... $V ...>,... - metavariable-regex: metavariable: $V regex: /(.{2}(? ...`. Ruby regex behavior is multiline by default and lines should be terminated by `\A` for beginning of line and `\Z` for end of line, respectively. languages: - ruby severity: ERROR metadata: source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_validation_regex.rb category: security cwe: - 'CWE-185: Incorrect Regular Expression' owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control technology: - ruby - rails references: - https://brakemanscanner.org/docs/warning_types/format_validation/ - https://github.com/presidentbeef/brakeman/blob/aef6253a8b7bcb97116f2af1ed2a561a6ae35bd5/test/apps/rails3/app/models/account.rb - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/account.rb subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex shortlink: https://sg.run/ZPo7 semgrep.dev: rule: r_id: 20735 rv_id: 1263665 rule_id: OrUv1X version_id: qkTR7DG url: https://semgrep.dev/playground/r/qkTR7DG/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex origin: community - id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing message: 'Detected usage of ''http.FileServer'' as handler: this allows directory listing and an attacker could navigate through directories looking for sensitive files. Be sure to disable directory listing or restrict access to specific directories/files.' severity: WARNING languages: - go patterns: - pattern-either: - patterns: - pattern-inside: | $FS := http.FileServer(...) ... - pattern-either: - pattern: | http.ListenAndServe(..., $FS) - pattern: | http.ListenAndServeTLS(..., $FS) - pattern: | http.Handle(..., $FS) - pattern: | http.HandleFunc(..., $FS) - patterns: - pattern: | http.$FN(..., http.FileServer(...)) - metavariable-regex: metavariable: $FN regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc) metadata: category: security cwe: - 'CWE-548: Exposure of Information Through Directory Listing' owasp: - A06:2017 - Security Misconfiguration - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://github.com/OWASP/Go-SCP - https://cwe.mitre.org/data/definitions/548.html confidence: MEDIUM technology: - go subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing shortlink: https://sg.run/4R8x semgrep.dev: rule: r_id: 21300 rv_id: 1262944 rule_id: 5rU9JO version_id: QkTGqX0 url: https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing origin: community - id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object message: Detected DynamoDB query params that are tainted by `$EVENT` object. This could lead to NoSQL injection if the variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from `$EVENT` directly to DynamoDB client. metadata: cwe: - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' owasp: - A01:2017 - Injection category: security technology: - javascript - aws-lambda - dynamodb subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object shortlink: https://sg.run/X1e4 semgrep.dev: rule: r_id: 21320 rv_id: 945766 rule_id: 0oU1xk version_id: GxTP7gN url: https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern: $EVENT - pattern-either: - pattern-inside: | exports.handler = function ($EVENT, ...) { ... } - pattern-inside: | function $FUNC ($EVENT, ...) {...} ... exports.handler = $FUNC - pattern-inside: | $FUNC = function ($EVENT, ...) {...} ... exports.handler = $FUNC pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern: | $DC.$METHOD($SINK, ...) - metavariable-regex: metavariable: $METHOD regex: (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) - pattern-either: - pattern-inside: | $DC = new $AWS.DocumentClient(...); ... - pattern-inside: | $DC = new $AWS.DynamoDB(...); ... - pattern-inside: | $DC = new DynamoDBClient(...); ... - pattern-inside: | $DC = DynamoDBDocumentClient.from(...); ... pattern-sanitizers: - patterns: - pattern: | {...} - id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection mode: taint metadata: cwe: - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' owasp: - A01:2017 - Injection category: security technology: - python - boto3 - aws-lambda - dynamodb references: - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection shortlink: https://sg.run/jjrl semgrep.dev: rule: r_id: 21321 rv_id: 946088 rule_id: KxUJ2B version_id: 9lTy1rQ url: https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection origin: community message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This could lead to NoSQL injection if the variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from `$EVENT` directly to DynamoDB client. pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sanitizers: - patterns: - pattern: | {...} pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) - pattern-either: - patterns: - pattern-inside: | $TABLE = $DB.Table(...) ... - pattern-inside: | $DB = boto3.resource('dynamodb', ...) ... - pattern-inside: | $TABLE = boto3.client('dynamodb', ...) ... severity: ERROR languages: - python - id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default patterns: - pattern: pyramid.authentication.$FUNC($...PARAMS) - metavariable-pattern: metavariable: $FUNC pattern-either: - pattern: AuthTktCookieHelper - pattern: AuthTktAuthenticationPolicy - pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...) - pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...) - focus-metavariable: $...PARAMS fix: | $...PARAMS, httponly=True message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default shortlink: https://sg.run/EprB semgrep.dev: rule: r_id: 21437 rv_id: 1263557 rule_id: bwUXKB version_id: RGT0L7K url: https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default origin: community languages: - python severity: WARNING - id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value patterns: - pattern-either: - patterns: - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY, ...) - patterns: - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY, ...) - pattern: $HTTPONLY - metavariable-pattern: metavariable: $HTTPONLY pattern: | False fix: | True message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value shortlink: https://sg.run/7DgQ semgrep.dev: rule: r_id: 21438 rv_id: 1263558 rule_id: NbUq9e version_id: A8Tgd8N url: https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value origin: community languages: - python severity: WARNING - id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite patterns: - pattern-either: - pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE, ...) - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE, ...) - pattern: $SAMESITE - metavariable-regex: metavariable: $SAMESITE regex: (?!'Lax') fix: | 'Lax' message: Found a Pyramid Authentication Ticket without the samesite option correctly set. Pyramid cookies should be handled securely by setting samesite='Lax'. If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite shortlink: https://sg.run/LYrY semgrep.dev: rule: r_id: 21439 rv_id: 1263559 rule_id: kxUYjY version_id: BjTkZ51 url: https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite origin: community languages: - python severity: WARNING - id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default patterns: - pattern-either: - patterns: - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktCookieHelper(...) - patterns: - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...) fix-regex: regex: (.*)\) replacement: \1, secure=True) message: Found a Pyramid Authentication Ticket cookie using an unsafe default for the secure option. Pyramid cookies should be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default shortlink: https://sg.run/8WxQ semgrep.dev: rule: r_id: 21440 rv_id: 1263560 rule_id: wdUKzn version_id: DkTRbJn url: https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default origin: community languages: - python severity: WARNING - id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value patterns: - pattern-either: - patterns: - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) - patterns: - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) - pattern: $SECURE - metavariable-pattern: metavariable: $SECURE pattern: | False fix: | True message: Found a Pyramid Authentication Ticket cookie without the secure option correctly set. Pyramid cookies should be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value shortlink: https://sg.run/gjp5 semgrep.dev: rule: r_id: 21441 rv_id: 1263561 rule_id: x8UqAp version_id: WrTqK93 url: https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value origin: community languages: - python severity: WARNING - id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally patterns: - pattern-inside: | $CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...) - pattern: $CHECK_ORIGIN - metavariable-comparison: metavariable: $CHECK_ORIGIN comparison: $CHECK_ORIGIN == False message: Automatic check of the referrer for cross-site request forgery tokens has been explicitly disabled globally, which might leave views unprotected when an unsafe CSRF storage policy is used. Use 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)' to turn the automatic check for all unsafe methods (per RFC2616). languages: - python severity: ERROR fix: | True metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally shortlink: https://sg.run/3GeW semgrep.dev: rule: r_id: 21443 rv_id: 1263563 rule_id: eqU9Le version_id: K3TKkeo url: https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally origin: community - id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled message: Origin check for the CSRF token is disabled for this view. This might represent a security risk if the CSRF storage policy is not known to be secure. metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control asvs: section: V4 Access Control control_id: 4.2.2 CSRF control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control version: '4' category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled shortlink: https://sg.run/4RB9 semgrep.dev: rule: r_id: 21444 rv_id: 1263564 rule_id: v8UGpL version_id: qkTR7Gv url: https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled origin: community severity: WARNING languages: - python patterns: - pattern-inside: | from pyramid.view import view_config ... @view_config(..., check_origin=$CHECK_ORIGIN, ...) def $VIEW(...): ... - pattern: $CHECK_ORIGIN - metavariable-comparison: metavariable: $CHECK_ORIGIN comparison: $CHECK_ORIGIN == False fix: | True - id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(...) fix-regex: regex: (.*)\) replacement: \1, httponly=True) message: Found a Pyramid cookie using an unsafe default for the httponly option. Pyramid cookies should be handled securely by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default shortlink: https://sg.run/P19v semgrep.dev: rule: r_id: 21445 rv_id: 1263565 rule_id: d8UPQ7 version_id: l4TJRbo url: https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default origin: community languages: - python severity: WARNING - id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) - pattern: $HTTPONLY - metavariable-pattern: metavariable: $HTTPONLY pattern: | False fix: | True message: Found a Pyramid cookie without the httponly option correctly set. Pyramid cookies should be handled securely by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1004: Sensitive Cookie Without ''HttpOnly'' Flag' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://owasp.org/www-community/controls/SecureCookieAttribute - https://owasp.org/www-community/HttpOnly - https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute category: security technology: - pyramid subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value shortlink: https://sg.run/JbqP semgrep.dev: rule: r_id: 21446 rv_id: 1263566 rule_id: ZqU37W version_id: YDTZe54 url: https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value origin: community languages: - python severity: WARNING - id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(...) fix-regex: regex: (.*)\) replacement: \1, samesite='Lax') message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default shortlink: https://sg.run/5AWj semgrep.dev: rule: r_id: 21447 rv_id: 1263567 rule_id: nJUp80 version_id: 6xT293z url: https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default origin: community languages: - python severity: WARNING - id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) - pattern: $SAMESITE - metavariable-regex: metavariable: $SAMESITE regex: (?!'Lax') fix: | 'Lax' message: Found a Pyramid cookie without the samesite option correctly set. Pyramid cookies should be handled securely by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value shortlink: https://sg.run/GXR6 semgrep.dev: rule: r_id: 21448 rv_id: 1263568 rule_id: EwUgpY version_id: o5TbDv5 url: https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value origin: community languages: - python severity: WARNING - id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...) - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(...) fix-regex: regex: (.*)\) replacement: \1, secure=True) message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid cookies should be handled securely by setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default shortlink: https://sg.run/RbrN semgrep.dev: rule: r_id: 21449 rv_id: 1263569 rule_id: 7KUr15 version_id: zyTb2dX url: https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default origin: community languages: - python severity: WARNING - id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value patterns: - pattern-either: - pattern-inside: | @pyramid.view.view_config(...) def $VIEW($REQUEST): ... $RESPONSE = $REQUEST.response ... - pattern-inside: | def $VIEW(...): ... $RESPONSE = pyramid.httpexceptions.HTTPFound(...) ... - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) - pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...) - pattern: $SECURE - metavariable-pattern: metavariable: $SECURE pattern: | False fix: | True message: Found a Pyramid cookie without the secure option correctly set. Pyramid cookies should be handled securely by setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not properly protected and are at risk of being stolen by an attacker. metadata: cwe: - 'CWE-614: Sensitive Cookie in HTTPS Session Without ''Secure'' Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - pyramid references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value shortlink: https://sg.run/AzjB semgrep.dev: rule: r_id: 21450 rv_id: 1263570 rule_id: L1UX2J version_id: pZT03oJ url: https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value origin: community languages: - python severity: WARNING - id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally patterns: - pattern-inside: | $CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...) - pattern: $REQUIRE_CSRF - metavariable-comparison: metavariable: $REQUIRE_CSRF comparison: $REQUIRE_CSRF == False message: Automatic check of cross-site request forgery tokens has been explicitly disabled globally, which might leave views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)' to turn the automatic check for all unsafe methods (per RFC2616). languages: - python severity: ERROR fix: | True metadata: cwe: - 'CWE-352: Cross-Site Request Forgery (CSRF)' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - pyramid references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site Request Forgery (CSRF) source: https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally shortlink: https://sg.run/Bx2R semgrep.dev: rule: r_id: 21451 rv_id: 1263571 rule_id: 8GUKqP version_id: 2KTv2en url: https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally origin: community - id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response message: Detected data rendered directly to the end user via 'Response'. This bypasses Pyramid's built-in cross-site scripting (XSS) defenses and could result in an XSS vulnerability. Use Pyramid's template engines to safely render HTML. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security technology: - pyramid references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response shortlink: https://sg.run/DX8G semgrep.dev: rule: r_id: 21452 rv_id: 1263572 rule_id: gxUeA8 version_id: X0TzyEe url: https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response origin: community languages: - python severity: ERROR mode: taint pattern-sources: - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern: | pyramid.request.Response.text($SINK) - pattern: | pyramid.request.Response($SINK) - pattern: | $REQ.response.body = $SINK - pattern: | $REQ.response.text = $SINK - pattern: | $REQ.response.ubody = $SINK - pattern: | $REQ.response.unicode_body = $SINK - pattern: $SINK - id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. languages: - python severity: ERROR metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data technology: - pyramid cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection shortlink: https://sg.run/W7eE semgrep.dev: rule: r_id: 21453 rv_id: 1263573 rule_id: QrUZ7l version_id: jQTn5WA url: https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection origin: community mode: taint pattern-sources: - patterns: - pattern-inside: | from pyramid.view import view_config ... @view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-inside: | $QUERY = $REQ.dbsession.query(...) ... - pattern-either: - pattern: | $QUERY.$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) - pattern: | $QUERY.join(...).$SQLFUNC("...".$FORMATFUNC(..., $SINK, ...)) - pattern: $SINK - metavariable-regex: metavariable: $SQLFUNC regex: (group_by|order_by|distinct|having|filter) - metavariable-regex: metavariable: $FORMATFUNC regex: (?!bindparams) fix-regex: regex: format replacement: bindparams - id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint message: Use of angular.element can lead to XSS if user-input is treated as part of the HTML element within `$SINK`. It is recommended to contextually output encode user-input, before inserting into `$SINK`. If the HTML needs to be preserved it is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. metadata: confidence: MEDIUM cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' references: - https://docs.angularjs.org/api/ng/function/angular.element - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf category: security technology: - angularjs owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint shortlink: https://sg.run/5AQ0 semgrep.dev: rule: r_id: 21503 rv_id: 1263091 rule_id: GdUP71 version_id: 44TEj8L url: https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern: window.location.search - pattern: window.document.location.search - pattern: document.location.search - pattern: location.search - pattern: $location.search(...) - patterns: - pattern-either: - pattern: $DECODE(<... location.hash ...>) - pattern: $DECODE(<... window.location.hash ...>) - pattern: $DECODE(<... document.location.hash ...>) - pattern: $DECODE(<... location.href ...>) - pattern: $DECODE(<... window.location.href ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... document.URL ...>) - pattern: $DECODE(<... window.document.URL ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... document.location.href ...>) - pattern: $DECODE(<... $location.absUrl() ...>) - pattern: $DECODE(<... $location.url() ...>) - pattern: $DECODE(<... $location.hash() ...>) - metavariable-regex: metavariable: $DECODE regex: ^(unescape|decodeURI|decodeURIComponent)$ - patterns: - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|delete|head|jsonp|post|put|patch) - pattern: $RES.data pattern-sinks: - patterns: - pattern-either: - pattern-inside: | angular.element(...). ... .$SINK($QUERY) - pattern-inside: | $ANGULAR = angular.element(...) ... $ANGULAR. ... .$SINK($QUERY) - metavariable-regex: metavariable: $SINK regex: ^(after|append|html|prepend|replaceWith|wrap)$ - focus-metavariable: $QUERY pattern-sanitizers: - patterns: - pattern-either: - pattern: $sce.getTrustedHtml(...) - pattern: $sanitize(...) - pattern: DOMPurify.sanitize(...) - id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization mode: taint pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context): ... pattern-sinks: - patterns: - focus-metavariable: $SINK - pattern-either: - pattern: pickle.load($SINK,...) - pattern: pickle.loads($SINK,...) - pattern: _pickle.load($SINK,...) - pattern: _pickle.loads($SINK,...) - pattern: cPickle.load($SINK,...) - pattern: cPickle.loads($SINK,...) - pattern: dill.load($SINK,...) - pattern: dill.loads($SINK,...) - pattern: shelve.open($SINK,...) message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. metadata: owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://docs.python.org/3/library/pickle.html - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ category: security technology: - python - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization shortlink: https://sg.run/JbjW semgrep.dev: rule: r_id: 21602 rv_id: 1263345 rule_id: JDUDQg version_id: LjTkgd9 url: https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization origin: community languages: - python severity: WARNING - id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection mode: taint pattern-sources: - patterns: - focus-metavariable: $ARG - pattern-inside: | Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...}) pattern-sanitizers: - patterns: - pattern: | DB::raw("...",[...]) pattern-sinks: - patterns: - pattern: | DB::raw(...) message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL injection via string concatenation or unsafe interpolation. languages: - php severity: WARNING metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md technology: - php - laravel cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection shortlink: https://sg.run/x94g semgrep.dev: rule: r_id: 21674 rv_id: 1263305 rule_id: zdUln0 version_id: qkTR7A9 url: https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection origin: community - id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator mode: taint pattern-sources: - patterns: - pattern: | public function $F(...,Request $R,...){...} - focus-metavariable: $R - patterns: - pattern-either: - pattern: | $this->$PROPERTY - pattern: | $this->$PROPERTY->$GET - metavariable-pattern: metavariable: $PROPERTY patterns: - pattern-either: - pattern: query - pattern: request - pattern: headers - pattern: cookies - pattern: cookie - pattern: files - pattern: file - pattern: allFiles - pattern: input - pattern: all - pattern: post - pattern: json - pattern-either: - pattern-inside: | class $CL extends Illuminate\Http\Request {...} - pattern-inside: | class $CL extends Illuminate\Foundation\Http\FormRequest {...} pattern-sinks: - patterns: - pattern: | Illuminate\Validation\Rule::unique(...)->ignore(...,$IGNORE,...) - focus-metavariable: $IGNORE message: Found a request argument passed to an `ignore()` definition in a Rule constraint. This can lead to SQL injection. languages: - php severity: ERROR metadata: category: security cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - php - laravel references: - https://laravel.com/docs/9.x/validation#rule-unique cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator shortlink: https://sg.run/vkeb semgrep.dev: rule: r_id: 21677 rv_id: 1263314 rule_id: X5ULgE version_id: DkTRbBl url: https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator origin: community - id: java.spring.security.injection.tainted-file-path.tainted-file-path languages: - java severity: ERROR message: Detected user input controlling a file path. An attacker could control the location of this file, to include going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) to only retrieve the file name from the path. options: interfile: true metadata: cwe: - 'CWE-23: Relative Path Traversal' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/www-community/attacks/Path_Traversal category: security technology: - java - spring subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: HIGH interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path shortlink: https://sg.run/x9o0 semgrep.dev: rule: r_id: 22074 rv_id: 1263084 rule_id: lBUxok version_id: ExTEx6Y url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE pattern-sinks: - patterns: - pattern-either: - pattern: new File(...) - pattern: new java.io.File(...) - pattern: new FileReader(...) - pattern: new java.io.FileReader(...) - pattern: new FileInputStream(...) - pattern: new java.io.FileInputStream(...) - pattern: (Paths $PATHS).get(...) - patterns: - pattern: | $CLASS.$FUNC(...) - metavariable-regex: metavariable: $FUNC regex: ^(getResourceAsStream|getResource)$ - patterns: - pattern-either: - pattern: new ClassPathResource($FILE, ...) - pattern: ResourceUtils.getFile($FILE, ...) - pattern: new FileOutputStream($FILE, ...) - pattern: new java.io.FileOutputStream($FILE, ...) - pattern: new StreamSource($FILE, ...) - pattern: new javax.xml.transform.StreamSource($FILE, ...) - pattern: FileUtils.openOutputStream($FILE, ...) - focus-metavariable: $FILE pattern-sanitizers: - pattern: org.apache.commons.io.FilenameUtils.getName(...) - id: java.spring.security.injection.tainted-html-string.tainted-html-string languages: - java severity: ERROR message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered safely. You can use the OWASP ESAPI encoder if you must render user data. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html category: security technology: - java - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string shortlink: https://sg.run/ObdR semgrep.dev: rule: r_id: 22075 rv_id: 1409395 rule_id: YGUvkL version_id: 3ZT2598 url: https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string origin: community mode: taint pattern-sources: - label: INPUT patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE - label: CONCAT by-side-effect: true requires: INPUT patterns: - pattern-either: - pattern: | "$HTMLSTR" + ... - pattern: | "$HTMLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$HTMLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$HTMLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$HTMLSTR", ...) - patterns: - pattern-inside: | String $VAR = "$HTMLSTR"; ... - pattern: String.format($VAR, ...) - metavariable-regex: metavariable: $HTMLSTR regex: ^<\w+ pattern-propagators: - pattern: (StringBuilder $SB).append($...TAINTED) from: $...TAINTED to: $SB - pattern: $VAR += $...TAINTED from: $...TAINTED to: $VAR pattern-sinks: - requires: CONCAT patterns: - pattern-either: - pattern: new ResponseEntity<>($PAYLOAD, ...) - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) - pattern: ResponseEntity. ... .body($PAYLOAD) - patterns: - pattern: | ResponseEntity.$RESPFUNC($PAYLOAD). ... - metavariable-regex: metavariable: $RESPFUNC regex: ^(ok|of)$ - focus-metavariable: $PAYLOAD pattern-sanitizers: - pattern-either: - pattern: Encode.forHtml(...) - pattern: (PolicyFactory $POLICY).sanitize(...) - pattern: (AntiSamy $AS).scan(...) - pattern: JSoup.clean(...) - id: java.spring.security.injection.tainted-system-command.tainted-system-command languages: - java severity: ERROR mode: taint pattern-propagators: - pattern: (StringBuilder $STRB).append($INPUT) from: $INPUT to: $STRB label: CONCAT requires: INPUT pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE label: INPUT - patterns: - pattern-either: - pattern: $X + $SOURCE - pattern: $SOURCE + $Y - pattern: String.format("...", ..., $SOURCE, ...) - pattern: String.join("...", ..., $SOURCE, ...) - pattern: (String $STR).concat($SOURCE) - pattern: $SOURCE.concat(...) - pattern: $X += $SOURCE - pattern: $SOURCE += $X label: CONCAT requires: INPUT pattern-sinks: - patterns: - pattern-either: - pattern: | (Process $P) = new Process(...); - pattern: | (ProcessBuilder $PB).command(...); - patterns: - pattern-either: - pattern: | (Runtime $R).$EXEC(...); - pattern: | Runtime.getRuntime(...).$EXEC(...); - metavariable-regex: metavariable: $EXEC regex: (exec|loadLibrary|load) - patterns: - pattern: | (ProcessBuilder $PB).command(...).$ADD(...); - metavariable-regex: metavariable: $ADD regex: (add|addAll) - patterns: - pattern-either: - patterns: - pattern-inside: | $BUILDER = new ProcessBuilder(...); ... - pattern: $BUILDER.start(...) - pattern: | new ProcessBuilder(...). ... .start(...); requires: CONCAT message: 'Detected user input entering a method which executes a system command. This could result in a command injection vulnerability, which allows an attacker to inject an arbitrary system command onto the server. The attacker could download malware onto or steal data from the server. Instead, use ProcessBuilder, separating the command into individual arguments, like this: `new ProcessBuilder("ls", "-al", targetDirectory)`. Further, make sure you hardcode or allowlist the actual command so that attackers can''t run arbitrary commands.' metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - java - spring confidence: HIGH references: - https://www.stackhawk.com/blog/command-injection-java/ - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command shortlink: https://sg.run/epY0 semgrep.dev: rule: r_id: 22076 rv_id: 1263087 rule_id: 6JUxGN version_id: 8KT5rnP url: https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command origin: community - id: java.spring.security.injection.tainted-url-host.tainted-url-host languages: - java severity: ERROR message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, hardcode the correct host, or ensure that the user data can only affect the path or parameters. options: interfile: true metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - java - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/vkYn semgrep.dev: rule: r_id: 22077 rv_id: 1263088 rule_id: oqUZo8 version_id: gETB708 url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) - focus-metavariable: $SOURCE pattern-sinks: - pattern-either: - pattern: new URL($ONEARG) - patterns: - pattern-either: - pattern: | "$URLSTR" + ... - pattern: | "$URLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$URLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$URLSTR"; ... - pattern: $VAR += ... - patterns: - pattern: String.format("$URLSTR", ...) - pattern-not: String.format("$URLSTR", "...", ...) - patterns: - pattern-inside: | String $VAR = "$URLSTR"; ... - pattern: String.format($VAR, ...) - metavariable-regex: metavariable: $URLSTR regex: http(s?)://%(v|s|q).* - id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization mode: taint languages: - ruby message: Deserialization of a string tainted by `event` object found. Objects in Ruby can be serialized into strings, then later loaded from strings. However, uses of `load` can cause remote code execution. Loading user input with MARSHAL, YAML or CSV can potentially be dangerous. If you need to deserialize untrusted data, you should use JSON as it is only capable of returning 'primitive' types such as strings, arrays, hashes, numbers and nil. metadata: references: - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb category: security owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-502: Deserialization of Untrusted Data' technology: - ruby - aws-lambda cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization shortlink: https://sg.run/dplX semgrep.dev: rule: r_id: 22078 rv_id: 1263585 rule_id: zdUlNJ version_id: vdT06gR url: https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization origin: community pattern-sinks: - patterns: - pattern: $SINK - pattern-either: - pattern-inside: | YAML.load($SINK,...) - pattern-inside: | CSV.load($SINK,...) - pattern-inside: | Marshal.load($SINK,...) - pattern-inside: | Marshal.restore($SINK,...) pattern-sources: - patterns: - pattern: event - pattern-inside: | def $HANDLER(event, context) ... end severity: WARNING - id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent message: The libxml library processes user-input with the `noent` attribute is set to `true` which can lead to being vulnerable to XML External Entities (XXE) type attacks. It is recommended to set `noent` to `false` when using this feature to ensure you are protected. options: interfile: true metadata: interfile: true references: - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html technology: - express category: security cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent shortlink: https://sg.run/Z75x semgrep.dev: rule: r_id: 22079 rv_id: 1263138 rule_id: pKUNeD version_id: d6TyxpX url: https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $XML = require('$IMPORT') ... - pattern-inside: | import $XML from '$IMPORT' ... - pattern-inside: | import * as $XML from '$IMPORT' ... - metavariable-regex: metavariable: $IMPORT regex: ^(libxmljs|libxmljs2)$ - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) - metavariable-regex: metavariable: $FUNC regex: ^(parseXmlString|parseXml)$ - focus-metavariable: $QUERY - id: javascript.express.security.audit.express-open-redirect.express-open-redirect message: The application redirects to a URL specified by user-supplied input `$REQ` that is not validated. This could redirect users to malicious locations. Consider using an allow-list approach to validate URLs, or warn users they are being redirected to a third-party website. metadata: technology: - express references: - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' category: security owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect shortlink: https://sg.run/EpoP semgrep.dev: rule: r_id: 22081 rv_id: 1263140 rule_id: X5ULkq version_id: nWT2L0v url: https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect origin: community languages: - javascript - typescript severity: WARNING options: taint_unify_mvars: true symbolic_propagation: true mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) - metavariable-regex: metavariable: $HTTP regex: ^https?:\/\/$ - pattern-either: - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern: $RES.redirect($REQ. ... .$VALUE) - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern: $RES.redirect($REQ.$VALUE['...']) - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) - pattern: $REQ.$VALUE - patterns: - pattern-either: - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = $REQ.$VALUE['...'] ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE + $...A ... - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" - pattern-inside: | $ASSIGN = `${$REQ. ... .$VALUE}...` ... - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" - pattern-either: - pattern: $RES.redirect($ASSIGN) - pattern: $RES.redirect($ASSIGN + $...FOO) - pattern: $RES.redirect(`${$ASSIGN}...`) - focus-metavariable: $ASSIGN - id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile message: The application processes user-input, this is passed to res.sendFile which can allow an attacker to arbitrarily read files on the system through path traversal. It is recommended to perform input validation in addition to canonicalizing the path. This allows you to validate the path against the intended directory it should be accessing. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html technology: - express category: security cwe: - 'CWE-73: External Control of File Name or Path' owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Path Traversal source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile shortlink: https://sg.run/7DJk semgrep.dev: rule: r_id: 22082 rv_id: 1263142 rule_id: j2UzDx version_id: 7ZTE3X9 url: https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - patterns: - pattern-either: - patterns: - pattern-either: - pattern-inside: | function ... (...,$REQ: $TYPE, ...) {...} - metavariable-regex: metavariable: $TYPE regex: ^(string|String) pattern-sinks: - patterns: - pattern-either: - pattern: $RES.$METH($QUERY,...) - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) - metavariable-regex: metavariable: $METH regex: ^(sendfile|sendFile)$ - focus-metavariable: $QUERY - id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). options: interfile: true metadata: interfile: true cwe: - 'CWE-798: Use of Hard-coded Credentials' references: - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures category: security technology: - express - secrets cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Hard-coded Secrets source: https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret shortlink: https://sg.run/LYvG semgrep.dev: rule: r_id: 22083 rv_id: 1263143 rule_id: 10Uo39 version_id: LjTkgle url: https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern-inside: | $SESSION = require('express-session'); ... - pattern-inside: | import $SESSION from 'express-session' ... - pattern-inside: | import {..., $SESSION, ...} from 'express-session' ... - pattern-inside: | import * as $SESSION from 'express-session' ... - patterns: - pattern-either: - pattern-inside: $APP.use($SESSION({...})) - pattern: | $SECRET = $VALUE ... $APP.use($SESSION($SECRET)) - pattern: | secret: '$Y' - id: javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization message: The following function call $SER.$FUNC accepts user controlled data which can result in Remote Code Execution (RCE) through Object Deserialization. It is recommended to use secure data processing alternatives such as JSON.parse() and Buffer.from(). options: interfile: true metadata: interfile: true technology: - express category: security cwe: - 'CWE-502: Deserialization of Untrusted Data' references: - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html source_rule_url: - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization shortlink: https://sg.run/8W5j semgrep.dev: rule: r_id: 22084 rv_id: 1263145 rule_id: 9AUyqj version_id: gETB7nD url: https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization origin: community languages: - javascript - typescript severity: WARNING mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern-inside: | $SER = require('$IMPORT') ... - pattern-inside: | import $SER from '$IMPORT' ... - pattern-inside: | import * as $SER from '$IMPORT' ... - metavariable-regex: metavariable: $IMPORT regex: ^(node-serialize|serialize-to-js)$ - pattern: $SER.$FUNC(...) - metavariable-regex: metavariable: $FUNC regex: ^(unserialize|deserialize)$ - id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection message: Detected a sequelize statement that is tainted by user-input. This could lead to SQL injection if the variable is user-controlled and is not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared statements. options: interfile: true metadata: interfile: true references: - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements category: security technology: - express cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection shortlink: https://sg.run/gjoe semgrep.dev: rule: r_id: 22085 rv_id: 1263241 rule_id: yyU0GX version_id: nWT2Llx url: https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection origin: community languages: - javascript - typescript severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, $RES) {...} - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} - patterns: - pattern-either: - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|head|delete|options)$ - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - pattern: $REQ.files.$ANYTHING.data.toString('utf8') - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...} - pattern-inside: | ({ $REQ }: Request,$RES: Response) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body - pattern: files.$ANYTHING.data.toString('utf8') - pattern: files.$ANYTHING['data'].toString('utf8') pattern-sinks: - pattern-either: - patterns: - pattern-either: - pattern: sequelize.query($QUERY,...) - pattern: $DB.sequelize.query($QUERY,...) - focus-metavariable: $QUERY pattern-sanitizers: - pattern-either: - pattern: parseInt(...) - pattern: $FUNC. ... .hash(...) - id: javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing message: Directory listing/indexing is enabled, which may lead to disclosure of sensitive directories and files. It is recommended to disable directory listing unless it is a public resource. If you need directory listing, ensure that sensitive files are inaccessible when querying the resource. options: interfile: true metadata: interfile: true cwe: - 'CWE-548: Exposure of Information Through Directory Listing' owasp: - A06:2017 - Security Misconfiguration - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control category: security technology: - express references: - https://www.npmjs.com/package/serve-index - https://www.acunetix.com/blog/articles/directory-listing-information-disclosure/ subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing shortlink: https://sg.run/DX2G semgrep.dev: rule: r_id: 22552 rv_id: 1263129 rule_id: x8UqEb version_id: rxTAKGb url: https://semgrep.dev/playground/r/rxTAKGb/javascript.express.security.audit.express-check-directory-listing.express-check-directory-listing origin: community languages: - javascript - typescript severity: WARNING patterns: - pattern-either: - pattern: | $APP.use(require('serve-index')(...)) - patterns: - pattern-either: - pattern-inside: | $SERVEINDEX = require('serve-index') ... - pattern-inside: | import $SERVEINDEX from 'serve-index' ... - pattern-inside: | import * as $SERVEINDEX from 'serve-index' ... - pattern-either: - patterns: - pattern-inside: | $VALUE = $SERVEINDEX(...) ... - pattern: | $VALUE(...) - pattern: | $APP.use(..., $SERVEINDEX(...), ...) - id: javascript.express.security.audit.express-ssrf.express-ssrf message: 'The following request $REQUEST.$METHOD() was found to be crafted from user-input `$REQ` which can lead to Server-Side Request Forgery (SSRF) vulnerabilities. It is recommended where possible to not allow user-input to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommeneded to follow OWASP best practices to prevent abuse. ' metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' technology: - express category: security owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf shortlink: https://sg.run/0PNw semgrep.dev: rule: r_id: 22554 rv_id: 1263144 rule_id: eqU9l2 version_id: 8KT5rBr url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf origin: community languages: - javascript - typescript severity: WARNING mode: taint options: taint_unify_mvars: true pattern-sources: - patterns: - pattern-either: - pattern-inside: function ... ($REQ, ...) {...} - pattern-either: - pattern: $REQ.query - pattern: $REQ.body - pattern: $REQ.params - pattern: $REQ.cookies - pattern: $REQ.headers - patterns: - pattern-either: - pattern-inside: | ({ $REQ }: Request,...) => {...} - pattern-inside: | ({ $REQ }: $EXPRESS.Request,...) => {...} - focus-metavariable: $REQ - pattern-either: - pattern: params - pattern: query - pattern: cookies - pattern: headers - pattern: body pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern-either: - pattern: $REQ. ... .$VALUE - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) - pattern: $REQ. ... .$VALUE - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) - pattern: $REQ.$VALUE - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - patterns: - pattern-either: - pattern-inside: | $REQUEST = require('request') ... - pattern-inside: | import * as $REQUEST from 'request' ... - pattern-inside: | import $REQUEST from 'request' ... - pattern-either: - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE['...'] ... - pattern-inside: | $ASSIGN = $REQ. ... .$VALUE + $...A ... - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" - pattern-inside: | $ASSIGN = `${$REQ. ... .$VALUE}...` ... - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" - patterns: - pattern-either: - pattern-inside: | $ASSIGN = "$HTTP"+ $REQ. ... .$VALUE ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ. ... .$VALUE + $...A ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ.$VALUE[...] ... - pattern-inside: | $ASSIGN = "$HTTP"+$REQ.$VALUE[...] + $...A ... - pattern-inside: | $ASSIGN = `$HTTP${$REQ.$VALUE[...]}...` ... - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern-either: - pattern: $REQUEST.$METHOD($ASSIGN,...) - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) - patterns: - pattern-either: - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) - metavariable-regex: metavariable: $HTTP regex: ^(https?:\/\/|//)$ - pattern: $ASSIGN - metavariable-regex: metavariable: $METHOD regex: ^(get|post|put|patch|del|head|delete)$ - id: terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled message: Ensure that App service enables detailed error messages patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... logs { ... detailed_error_messages_enabled = true ... } ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... } metadata: owasp: - A10:2017 - Insufficient Logging & Monitoring - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled shortlink: https://sg.run/pA1g semgrep.dev: rule: r_id: 23962 rv_id: 1263762 rule_id: bwU1Eg version_id: DkTRbr5 url: https://semgrep.dev/playground/r/DkTRbr5/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only message: Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service Slot patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... https_only = true ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only shortlink: https://sg.run/1g9w semgrep.dev: rule: r_id: 23966 rv_id: 1263766 rule_id: x8UZRP version_id: qkTR78q url: https://semgrep.dev/playground/r/qkTR78q/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version message: Ensure web app is using the latest version of TLS encryption patterns: - pattern-either: - pattern: | "1.0" - pattern: | "1.1" - pattern-inside: min_tls_version = ... - pattern-inside: | $RESOURCE "azurerm_app_service" "..." { ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version shortlink: https://sg.run/rDwn semgrep.dev: rule: r_id: 23969 rv_id: 1263769 rule_id: v8UNL7 version_id: 6xT29gv url: https://semgrep.dev/playground/r/6xT29gv/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date message: Ensure that the expiration date is set on all keys patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_key_vault_key" "..." { ... expiration_date = "..." ... } - pattern-inside: | resource "azurerm_key_vault_key" "..." { ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date shortlink: https://sg.run/J1vw semgrep.dev: rule: r_id: 23990 rv_id: 946834 rule_id: 0oUlgp version_id: pZTNGkl url: https://semgrep.dev/playground/r/pZTNGkl/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version message: Ensure MSSQL is using the latest version of TLS encryption patterns: - pattern-either: - pattern: | "1.0" - pattern: | "1.1" - pattern-inside: minimum_tls_version = ... - pattern-inside: | $RESOURCE "azurerm_mssql_server" "..." { ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version shortlink: https://sg.run/B1lW semgrep.dev: rule: r_id: 23995 rv_id: 1263784 rule_id: 6JUJG8 version_id: xyTjzeR url: https://semgrep.dev/playground/r/xyTjzeR/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled message: Ensure that MySQL server enables infrastructure encryption patterns: - pattern: resource - pattern-inside: | resource "azurerm_mysql_server" "..." { ... } - pattern-not-inside: | resource "azurerm_mysql_server" "..." { ... infrastructure_encryption_enabled = true ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure cwe: - 'CWE-320: CWE CATEGORY: Key Management Errors' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled shortlink: https://sg.run/Dd6Y semgrep.dev: rule: r_id: 23996 rv_id: 946840 rule_id: oqUloL version_id: yeT0vBn url: https://semgrep.dev/playground/r/yeT0vBn/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled origin: community languages: - hcl severity: WARNING - id: terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version message: Ensure MySQL is using the latest version of TLS encryption patterns: - pattern-either: - pattern: | "TLS1_0" - pattern: | "TLS1_1" - pattern-inside: ssl_minimal_tls_version_enforced = ... - pattern-inside: | $RESOURCE "azurerm_mysql_server" "..." { ... } metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version shortlink: https://sg.run/WR44 semgrep.dev: rule: r_id: 23997 rv_id: 1263785 rule_id: zdU8NN version_id: O9TpxWE url: https://semgrep.dev/playground/r/O9TpxWE/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version origin: community languages: - hcl severity: WARNING - id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage message: Detected usage of dangerous method $METHOD which does not escape inputs (see link in references). If the argument is user-controlled, this can lead to SQL injection. When using $METHOD function, do not trust user-submitted data and only allow approved list of input (possibly, use an allowlist approach). severity: WARNING languages: - go mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | ($REQUEST : http.Request).$ANYTHING - pattern: | ($REQUEST : *http.Request).$ANYTHING - metavariable-regex: metavariable: $ANYTHING regex: ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ pattern-sinks: - patterns: - pattern-inside: | import ("gorm.io/gorm") ... - patterns: - pattern-inside: | func $VAL(..., $GORM *gorm.DB,... ) { ... } - pattern-either: - pattern: | $GORM. ... .$METHOD($VALUE) - pattern: | $DB := $GORM. ... .$ANYTHING(...) ... $DB. ... .$METHOD($VALUE) - focus-metavariable: $VALUE - metavariable-regex: metavariable: $METHOD regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ pattern-sanitizers: - pattern-either: - pattern: strconv.Atoi(...) - pattern: | ($X: bool) options: interfile: true metadata: category: security technology: - gorm cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://gorm.io/docs/security.html#SQL-injection-Methods - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage shortlink: https://sg.run/R4qg semgrep.dev: rule: r_id: 24693 rv_id: 1262915 rule_id: AbU5o3 version_id: l4TJRJK url: https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage origin: community - id: yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value patterns: - pattern-either: - pattern: | spec: ... securityContext: ... runAsNonRoot: $VALUE - patterns: - pattern-inside: | containers: ... - pattern: | image: ... ... securityContext: ... runAsNonRoot: $VALUE - metavariable-pattern: metavariable: $VALUE pattern: | false - focus-metavariable: $VALUE fix: | true message: When running containers in Kubernetes, it's important to ensure that they are properly secured to prevent privilege escalation attacks. One potential vulnerability is when a container is allowed to run applications as the root user, which could allow an attacker to gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container, with the parameter `runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root user, limiting the damage that could be caused by any potential attacks. By adding a `securityContext` to the container in your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: references: - https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/ - https://kubernetes.io/docs/concepts/policy/pod-security-policy/ - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - kubernetes subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value shortlink: https://sg.run/D9No semgrep.dev: rule: r_id: 26096 rv_id: 1263939 rule_id: L1UAxy version_id: NdTzyj8 url: https://semgrep.dev/playground/r/NdTzyj8/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value origin: community languages: - yaml severity: INFO - id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization message: Anonymous access shouldn't be allowed unless explicit by design. Access control checks are missing and potentially can be bypassed. This finding violates the principle of least privilege or deny by default, where access should only be permitted for a specific set of roles or conforms to a custom policy or users. severity: INFO metadata: likelihood: LOW impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-862: Missing Authorization' cwe2021-top25: true cwe2022-top25: true cwe2023-top25: true owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control - https://cwe.mitre.org/data/definitions/862.html - https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0 subcategory: - vuln technology: - .net - mvc license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization shortlink: https://sg.run/Z8GA semgrep.dev: rule: r_id: 26335 rv_id: 1262615 rule_id: eqU32Y version_id: o5TbD41 url: https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization origin: community languages: - csharp patterns: - pattern: | public class $CLASS : Controller { ... } - pattern-inside: | using Microsoft.AspNetCore.Mvc; ... - pattern-not: | [AllowAnonymous] public class $CLASS : Controller { ... } - pattern-not: | [Authorize] public class $CLASS : Controller { ... } - pattern-not: | [Authorize(Roles = ...)] public class $CLASS : Controller { ... } - pattern-not: | [Authorize(Policy = ...)] public class $CLASS : Controller { ... } - id: csharp.dotnet.security.audit.open-directory-listing.open-directory-listing message: An open directory listing is potentially exposed, potentially revealing sensitive information to attackers. severity: INFO metadata: likelihood: LOW impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-548: Exposure of Information Through Directory Listing' owasp: - A06:2017 - Security Misconfiguration - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://cwe.mitre.org/data/definitions/548.html - https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ - https://docs.microsoft.com/en-us/aspnet/core/fundamentals/static-files?view=aspnetcore-7.0#directory-browsing subcategory: - vuln technology: - .net - mvc license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing shortlink: https://sg.run/n0y1 semgrep.dev: rule: r_id: 26336 rv_id: 1262616 rule_id: v8U8Ab version_id: zyTb2Y2 url: https://semgrep.dev/playground/r/zyTb2Y2/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing origin: community languages: - csharp patterns: - pattern-either: - pattern: (IApplicationBuilder $APP).UseDirectoryBrowser(...); - pattern: $BUILDER.Services.AddDirectoryBrowser(...); - pattern-inside: | public void Configure(...) { ... } - id: csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token patterns: - pattern: RequireSignedTokens = false - pattern-inside: | new TokenValidationParameters { ... } fix: RequireSignedTokens = true message: Accepting unsigned security tokens as valid security tokens allows an attacker to remove its signature and potentially forge an identity. As a fix, set RequireSignedTokens to be true. metadata: category: security technology: - csharp owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-347: Improper Verification of Cryptographic Signature' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ - https://cwe.mitre.org/data/definitions/347 subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token shortlink: https://sg.run/pqzN semgrep.dev: rule: r_id: 26718 rv_id: 1262631 rule_id: KxUGLw version_id: e1Tyjrz url: https://semgrep.dev/playground/r/e1Tyjrz/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token origin: community languages: - csharp severity: ERROR - id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure patterns: - pattern: $APP.UseDeveloperExceptionPage(...); - pattern-not-inside: | if ($ENV.IsDevelopment(...)) { ... } - pattern-not-inside: | if ($ENV.EnvironmentName == "Development") { ... } message: Stacktrace information is displayed in a non-Development environment. Accidentally disclosing sensitive stack trace information in a production environment aids an attacker in reconnaissance and information gathering. metadata: category: security technology: - csharp owasp: - A06:2017 - Security Misconfiguration - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-209: Generation of Error Message Containing Sensitive Information' references: - https://cwe.mitre.org/data/definitions/209.html - https://owasp.org/Top10/A04_2021-Insecure_Design/ subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure shortlink: https://sg.run/XvkA semgrep.dev: rule: r_id: 26720 rv_id: 1262653 rule_id: lBU6Dv version_id: 0bTKzrB url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure origin: community languages: - csharp severity: WARNING - id: csharp.dotnet.security.audit.mass-assignment.mass-assignment message: Mass assignment or Autobinding vulnerability in code allows an attacker to execute over-posting attacks, which could create a new parameter in the binding request and manipulate the underlying object in the application. severity: WARNING metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures references: - https://cwe.mitre.org/data/definitions/915.html - https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mass Assignment source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment shortlink: https://sg.run/7B3e semgrep.dev: rule: r_id: 26838 rv_id: 1262613 rule_id: x8Up5B version_id: YDTZeD9 url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment origin: community languages: - csharp mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | public IActionResult $METHOD(..., $TYPE $ARG, ...){ ... } - pattern: | public ActionResult $METHOD(..., $TYPE $ARG, ...){ ... } - pattern-inside: | using Microsoft.AspNetCore.Mvc; ... - pattern-not: | public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ ... } - pattern-not: | public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){ ... } - focus-metavariable: $ARG pattern-sinks: - pattern: View(...) - id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - pattern-either: - patterns: - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...) - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...) - pattern: $LOOP.subprocess_exec(...) - patterns: - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c",...) - patterns: - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...], ...) - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", ...], ...) message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled data. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec - https://docs.python.org/3/library/shlex.html - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args shortlink: https://sg.run/Apjp semgrep.dev: rule: r_id: 27250 rv_id: 1263460 rule_id: 7KUE1E version_id: WrTqKXz url: https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD) - pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...) - pattern-inside: asyncio.create_subprocess_shell($CMD, ...) - focus-metavariable: $CMD - pattern-not-inside: | $CMD = "..." ... - pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...") - pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...) - pattern-not: asyncio.create_subprocess_shell("...", ...) message: Detected asyncio subprocess function with user controlled data. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://docs.python.org/3/library/asyncio-subprocess.html - https://docs.python.org/3/library/shlex.html - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args shortlink: https://sg.run/Dx8Y semgrep.dev: rule: r_id: 27252 rv_id: 1263462 rule_id: 8GU5q3 version_id: K3TKkDn url: https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $X = code.InteractiveConsole(...) ... - pattern-inside: | $X = code.InteractiveInterpreter(...) ... - pattern-either: - pattern-inside: | $X.push($PAYLOAD,...) - pattern-inside: | $X.runsource($PAYLOAD,...) - pattern-inside: | $X.runcode(code.compile_command($PAYLOAD),...) - pattern-inside: | $PL = code.compile_command($PAYLOAD,...) ... $X.runcode($PL,...) - pattern: $PAYLOAD - pattern-not: | $X.push("...",...) - pattern-not: | $X.runsource("...",...) - pattern-not: | $X.runcode(code.compile_command("..."),...) - pattern-not: | $PL = code.compile_command("...",...) ... $X.runcode($PL,...) message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if external data can reach this function call because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args shortlink: https://sg.run/0Bgv semgrep.dev: rule: r_id: 27254 rv_id: 1263464 rule_id: QrUG72 version_id: l4TJRK9 url: https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args origin: community severity: WARNING languages: - python - id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD("...", ...) - pattern: os.$METHOD(...) - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) - patterns: - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execv|execve|execvp|execvpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' confidence: MEDIUM category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args shortlink: https://sg.run/qL6z semgrep.dev: rule: r_id: 27256 rv_id: 1263466 rule_id: 4bUEAY version_id: 6xT29l6 url: https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD($MODE, "...", ...) - pattern-inside: os.$METHOD($MODE, $CMD, ...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) - patterns: - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args shortlink: https://sg.run/Y3Ke semgrep.dev: rule: r_id: 27258 rv_id: 1263468 rule_id: JDUz34 version_id: zyTb2wn url: https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-inside: | _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) - pattern-not: | _xxsubinterpreters.run_string($ID, "...", ...) - pattern: $PAYLOAD message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://bugs.python.org/issue43472 - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args shortlink: https://sg.run/oLl9 semgrep.dev: rule: r_id: 27260 rv_id: 1409404 rule_id: GdUkxO version_id: DkTwBzO url: https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args origin: community severity: WARNING languages: - python - id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sanitizers: - pattern: shlex.quote(...) pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...",...], ...) - pattern-not: subprocess.$FUNC(("...",...), ...) - pattern-not: subprocess.CalledProcessError(...) - pattern-not: subprocess.SubprocessError(...) - pattern: subprocess.$FUNC($CMD, ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) - pattern: subprocess.$FUNC("=~/(python)/", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) - focus-metavariable: $CMD message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.quote()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess - https://docs.python.org/3/library/subprocess.html - https://docs.python.org/3/library/shlex.html - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args shortlink: https://sg.run/pLGg semgrep.dev: rule: r_id: 27262 rv_id: 1263472 rule_id: AbUgrZ version_id: jQTn54Y url: https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-not: os.$W("...", ...) - pattern-either: - pattern: os.system(...) - pattern: | $X = __import__("os") ... $X.system(...) - pattern: | $X = __import__("os") ... getattr($X, "system")(...) - pattern: | $X = getattr(os, "system") ... $X(...) - pattern: | $X = __import__("os") ... $Y = getattr($X, "system") ... $Y(...) - pattern: os.popen(...) - pattern: os.popen2(...) - pattern: os.popen3(...) - pattern: os.popen4(...) message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection vulnerability. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args shortlink: https://sg.run/XR2K semgrep.dev: rule: r_id: 27264 rv_id: 1263474 rule_id: DbUR9g version_id: 9lT4bG4 url: https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args origin: community languages: - python severity: ERROR - id: python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: os.environ - pattern: os.environ.get('$FOO', ...) - pattern: os.environb - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv - pattern: sys.orig_argv - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - pattern-inside: | _testcapi.run_in_subinterp($PAYLOAD, ...) - pattern-inside: | test.support.run_in_subinterp($PAYLOAD, ...) - pattern: $PAYLOAD - pattern-not: | _testcapi.run_in_subinterp("...", ...) - pattern-not: | test.support.run_in_subinterp("...", ...) message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args shortlink: https://sg.run/1DLw semgrep.dev: rule: r_id: 27266 rv_id: 1263476 rule_id: 0oUK7N version_id: rxTAKpn url: https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args origin: community severity: WARNING languages: - python - id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern-inside: | $X = code.InteractiveConsole(...) ... - pattern-inside: | $X = code.InteractiveInterpreter(...) ... - pattern-either: - pattern: | $X.push($PAYLOAD,...) - pattern: | $X.runsource($PAYLOAD,...) - pattern: | $X.runcode(code.compile_command($PAYLOAD),...) - pattern: | $PL = code.compile_command($PAYLOAD,...) ... $X.runcode($PL,...) - focus-metavariable: $PAYLOAD - pattern-not: | $X.push("...",...) - pattern-not: | $X.runsource("...",...) - pattern-not: | $X.runcode(code.compile_command("..."),...) - pattern-not: | $PL = code.compile_command("...",...) ... $X.runcode($PL,...) message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if external data can reach this function call because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run shortlink: https://sg.run/9pRY semgrep.dev: rule: r_id: 27267 rv_id: 1263521 rule_id: KxUKzx version_id: l4TJRgo url: https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run origin: community severity: WARNING languages: - python - id: python.lang.security.dangerous-os-exec.dangerous-os-exec mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD("...", ...) - pattern: os.$METHOD(...) - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) - patterns: - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execv|execve|execvp|execvpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (execl|execle|execlp|execlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' confidence: MEDIUM category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec shortlink: https://sg.run/yL9x semgrep.dev: rule: r_id: 27268 rv_id: 1263523 rule_id: qNUR13 version_id: 6xT29rz url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - pattern: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession - patterns: - pattern-either: - pattern: os.environ['$ANYTHING'] - pattern: os.environ.get('$FOO', ...) - pattern: os.environb['$ANYTHING'] - pattern: os.environb.get('$FOO', ...) - pattern: os.getenv('$ANYTHING', ...) - pattern: os.getenvb('$ANYTHING', ...) - patterns: - pattern-either: - patterns: - pattern-either: - pattern: sys.argv[...] - pattern: sys.orig_argv[...] - patterns: - pattern-inside: | $PARSER = argparse.ArgumentParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-inside: | $PARSER = optparse.OptionParser(...) ... - pattern-inside: | $ARGS = $PARSER.parse_args() - pattern: <... $ARGS ...> - patterns: - pattern-either: - pattern-inside: | $OPTS, $ARGS = getopt.getopt(...) ... - pattern-inside: | $OPTS, $ARGS = getopt.gnu_getopt(...) ... - pattern-either: - patterns: - pattern-inside: | for $O, $A in $OPTS: ... - pattern: $A - pattern: $ARGS pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: os.$METHOD($MODE, "...", ...) - pattern-inside: os.$METHOD($MODE, $CMD, ...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) - patterns: - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) - patterns: - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) - pattern: $CMD - metavariable-regex: metavariable: $METHOD regex: (spawnl|spawnle|spawnlp|spawnlpe) - metavariable-regex: metavariable: $BASH regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor to execute commands. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process shortlink: https://sg.run/r8Zn semgrep.dev: rule: r_id: 27269 rv_id: 1263524 rule_id: lBUJrn version_id: o5TbDO5 url: https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern: | _xxsubinterpreters.run_string($ID, $PAYLOAD, ...) - pattern-not: | _xxsubinterpreters.run_string($ID, "...", ...) - focus-metavariable: $PAYLOAD message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://bugs.python.org/issue43472 - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string shortlink: https://sg.run/bPop semgrep.dev: rule: r_id: 27270 rv_id: 1263525 rule_id: PeURWr version_id: zyTb2OX url: https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string origin: community severity: WARNING languages: - python - id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...",...], ...) - pattern-not: subprocess.$FUNC(("...",...), ...) - pattern-not: subprocess.CalledProcessError(...) - pattern-not: subprocess.SubprocessError(...) - pattern: subprocess.$FUNC($CMD, ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) - patterns: - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) - pattern: subprocess.$FUNC("=~/(python)/", $CMD) - patterns: - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) - pattern-either: - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) - focus-metavariable: $CMD message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.escape()'. metadata: owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.3.8 OS Command Injection control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements version: '4' references: - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess - https://docs.python.org/3/library/subprocess.html - https://docs.python.org/3/library/shlex.html - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use shortlink: https://sg.run/NWxp semgrep.dev: rule: r_id: 27271 rv_id: 1263526 rule_id: JDUz3R version_id: pZT038J url: https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-system-call.dangerous-system-call mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-not: os.$W("...", ...) - pattern-either: - pattern: os.system(...) - pattern: getattr(os, "system")(...) - pattern: __import__("os").system(...) - pattern: getattr(__import__("os"), "system")(...) - pattern: | $X = __import__("os") ... $X.system(...) - pattern: | $X = __import__("os") ... getattr($X, "system")(...) - pattern: | $X = getattr(os, "system") ... $X(...) - pattern: | $X = __import__("os") ... $Y = getattr($X, "system") ... $Y(...) - pattern: os.popen(...) - pattern: os.popen2(...) - pattern: os.popen3(...) - pattern: os.popen4(...) message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection vulnerability. metadata: source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ asvs: section: 'V5: Validation, Sanitization and Encoding Verification Requirements' control_id: 5.2.4 Dyanmic Code Execution Features control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements version: '4' category: security technology: - python confidence: MEDIUM cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call shortlink: https://sg.run/k0W7 semgrep.dev: rule: r_id: 27272 rv_id: 1263527 rule_id: 5rUoP1 version_id: 2KTv2Zn url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call origin: community languages: - python severity: ERROR - id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route(...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR - patterns: - pattern-inside: | def $FUNC(request, ...): ... - pattern-either: - pattern: request.$PROPERTY.get(...) - pattern: request.$PROPERTY[...] - patterns: - pattern-either: - pattern-inside: | @rest_framework.decorators.api_view(...) def $FUNC($REQ, ...): ... - patterns: - pattern-either: - pattern-inside: | class $VIEW(..., rest_framework.views.APIView, ...): ... - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \n" - pattern-inside: | def $METHOD(self, $REQ, ...): ... - metavariable-regex: metavariable: $METHOD regex: (get|post|put|patch|delete|head) - pattern-either: - pattern: $REQ.POST.get(...) - pattern: $REQ.POST[...] - pattern: $REQ.FILES.get(...) - pattern: $REQ.FILES[...] - pattern: $REQ.DATA.get(...) - pattern: $REQ.DATA[...] - pattern: $REQ.QUERY_PARAMS.get(...) - pattern: $REQ.QUERY_PARAMS[...] - pattern: $REQ.data.get(...) - pattern: $REQ.data[...] - pattern: $REQ.query_params.get(...) - pattern: $REQ.query_params[...] - pattern: $REQ.content_type - pattern: $REQ.content_type - pattern: $REQ.stream - pattern: $REQ.stream - patterns: - pattern-either: - pattern-inside: | class $SERVER(..., http.server.BaseHTTPRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.StreamRequestHandler, ...): ... - pattern-inside: | class $SERVER(..., http.server.DatagramRequestHandler, ...): ... - pattern-either: - pattern: self.requestline - pattern: self.path - pattern: self.headers[...] - pattern: self.headers.get(...) - pattern: self.rfile - patterns: - pattern-inside: | @pyramid.view.view_config( ... ) def $VIEW($REQ): ... - pattern: $REQ.$ANYTHING - pattern-not: $REQ.dbsession pattern-sinks: - patterns: - pattern-either: - pattern: | _testcapi.run_in_subinterp($PAYLOAD, ...) - pattern: | test.support.run_in_subinterp($PAYLOAD, ...) - focus-metavariable: $PAYLOAD - pattern-not: | _testcapi.run_in_subinterp("...", ...) - pattern-not: | test.support.run_in_subinterp("...", ...) message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to run arbitrary Python code. metadata: cwe: - 'CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (''Eval Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ category: security technology: - python confidence: MEDIUM subcategory: - vuln likelihood: HIGH impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp shortlink: https://sg.run/wLpY semgrep.dev: rule: r_id: 27273 rv_id: 1263528 rule_id: GdUkxR version_id: X0Tzy1e url: https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp origin: community severity: WARNING languages: - python - id: csharp.dotnet.security.audit.xpath-injection.xpath-injection message: XPath queries are constructed dynamically on user-controlled input. This vulnerability in code could lead to an XPath Injection exploitation. severity: ERROR metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-643: Improper Neutralization of Data within XPath Expressions (''XPath Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection/ - https://cwe.mitre.org/data/definitions/643.html subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XPath Injection source: https://semgrep.dev/r/csharp.dotnet.security.audit.xpath-injection.xpath-injection shortlink: https://sg.run/4KP7 semgrep.dev: rule: r_id: 27400 rv_id: 1262618 rule_id: x8Uj2k version_id: 2KTv2Pq url: https://semgrep.dev/playground/r/2KTv2Pq/csharp.dotnet.security.audit.xpath-injection.xpath-injection origin: community languages: - csharp mode: taint pattern-sources: - pattern-either: - pattern: $T $M($INPUT,...) {...} - pattern: | $T $M(...) { ... string $INPUT; } pattern-sinks: - pattern-either: - pattern: XPathExpression $EXPR = $NAV.Compile("..." + $INPUT + "..."); - pattern: var $EXPR = $NAV.Compile("..." + $INPUT + "..."); - pattern: XPathNodeIterator $NODE = $NAV.Select("..." + $INPUT + "..."); - pattern: var $NODE = $NAV.Select("..." + $INPUT + "..."); - pattern: Object $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); - pattern: var $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); - id: csharp.dotnet.security.audit.ldap-injection.ldap-injection message: LDAP queries are constructed dynamically on user-controlled input. This vulnerability in code could lead to an arbitrary LDAP query execution. severity: ERROR metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (''LDAP Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection/ - https://cwe.mitre.org/data/definitions/90 - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#safe-c-sharp-net-tba-example subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - LDAP Injection source: https://semgrep.dev/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection shortlink: https://sg.run/GJ9z semgrep.dev: rule: r_id: 27692 rv_id: 1262612 rule_id: 2ZUv3R version_id: l4TJR8G url: https://semgrep.dev/playground/r/l4TJR8G/csharp.dotnet.security.audit.ldap-injection.ldap-injection origin: community languages: - csharp mode: taint options: taint_unify_mvars: true pattern-sources: - patterns: - focus-metavariable: $INPUT - pattern-inside: $T $M(...,$INPUT,...) {...} pattern-sinks: - patterns: - pattern-either: - pattern: $S.Filter = ... + $INPUT + ... - pattern: $S.Filter = String.Format(...,$INPUT) - pattern: $S.Filter = String.Concat(...,$INPUT) pattern-sanitizers: - pattern-either: - pattern: Regex.Replace($INPUT, ...) - pattern: $ENCODER.LdapFilterEncode($INPUT) - pattern: $ENCODER.LdapDistinguishedNameEncode($INPUT) - id: csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation patterns: - pattern-either: - patterns: - pattern: $LIFETIME = $FALSE - pattern-inside: new TokenValidationParameters {...} - patterns: - pattern: | (TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE - metavariable-regex: metavariable: $LIFETIME regex: (RequireExpirationTime|ValidateLifetime) - metavariable-regex: metavariable: $FALSE regex: (false) - focus-metavariable: $FALSE fix: | true message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the JWT tokens lifetime is not validated. This can lead to an JWT token being used after it has expired, which has security implications. It is recommended to validate the JWT lifetime to ensure only valid tokens are used. metadata: category: security technology: - csharp owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-613: Insufficient Session Expiration' references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ - https://cwe.mitre.org/data/definitions/613.html - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation shortlink: https://sg.run/KA0d semgrep.dev: rule: r_id: 28955 rv_id: 1262628 rule_id: bwU5kK version_id: w8TRolJ url: https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation origin: community languages: - csharp severity: WARNING - id: java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml patterns: - pattern-inside: | management: ... endpoints: ... web: ... exposure: ... - pattern: | include: "*" message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints such as /actuator/env, /actuator/logfile, /actuator/heapdump and others. Unless you have Spring Security enabled or another means to protect these endpoints, this functionality is available without authentication, causing a severe security risk. severity: WARNING languages: - yaml metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators category: security technology: - spring cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml shortlink: https://sg.run/1Bzw semgrep.dev: rule: r_id: 29422 rv_id: 1263076 rule_id: eqUerQ version_id: w8TRo5n url: https://semgrep.dev/playground/r/w8TRo5n/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml origin: community - id: python.django.security.injection.command.subprocess-injection.subprocess-injection languages: - python mode: taint options: symbolic_propagation: true pattern-sources: - patterns: - pattern-inside: | def $FUNC(..., $REQUEST, ...): ... - focus-metavariable: $REQUEST - metavariable-pattern: metavariable: $REQUEST patterns: - pattern: request - pattern-not-inside: request.build_absolute_uri pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: subprocess.$FUNC(...) - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...", ...], ...) - pattern-not-inside: | $CMD = ["...", ...] ... subprocess.$FUNC($CMD, ...) - patterns: - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) - metavariable-regex: metavariable: $SHELL regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ - patterns: - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) - metavariable-regex: metavariable: $INTERPRETER regex: ^(python|python\d)$ pattern-sanitizers: - patterns: - pattern: $DICT[$KEY] - focus-metavariable: $KEY severity: ERROR message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. metadata: category: security technology: - flask owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection shortlink: https://sg.run/49BE semgrep.dev: rule: r_id: 31144 rv_id: 1263388 rule_id: EwUepx version_id: 7ZTE3qK url: https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection origin: community - id: python.django.security.injection.csv-writer-injection.csv-writer-injection languages: - python message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. metadata: category: security confidence: MEDIUM cwe: - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/raphaelm/defusedcsv - https://owasp.org/www-community/attacks/CSV_Injection - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities technology: - django - python subcategory: - vuln impact: MEDIUM likelihood: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection shortlink: https://sg.run/Pw9q semgrep.dev: rule: r_id: 31145 rv_id: 1263389 rule_id: 7KUK1y version_id: LjTkgD9 url: https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection origin: community mode: taint pattern-sinks: - patterns: - pattern-inside: | $WRITER = csv.writer(...) ... $WRITER.$WRITE(...) - pattern: $WRITER.$WRITE(...) - metavariable-regex: metavariable: $WRITE regex: ^(writerow|writerows|writeheader)$ pattern-sources: - patterns: - pattern-inside: | def $FUNC(..., $REQUEST, ...): ... - focus-metavariable: $REQUEST - metavariable-pattern: metavariable: $REQUEST patterns: - pattern: request - pattern-not-inside: request.build_absolute_uri severity: ERROR - id: python.flask.security.injection.csv-writer-injection.csv-writer-injection languages: - python message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. metadata: category: security confidence: MEDIUM cwe: - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://github.com/raphaelm/defusedcsv - https://owasp.org/www-community/attacks/CSV_Injection - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities technology: - python - flask subcategory: - vuln impact: MEDIUM likelihood: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection shortlink: https://sg.run/JzqQ semgrep.dev: rule: r_id: 31146 rv_id: 1263428 rule_id: L1UR2K version_id: jQTn50Y url: https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection origin: community mode: taint pattern-sinks: - patterns: - pattern-inside: | $WRITER = csv.writer(...) ... $WRITER.$WRITE(...) - pattern: $WRITER.$WRITE(...) - metavariable-regex: metavariable: $WRITE regex: ^(writerow|writerows|writeheader)$ pattern-sources: - patterns: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR severity: ERROR - id: python.flask.security.injection.subprocess-injection.subprocess-injection languages: - python mode: taint options: symbolic_propagation: true pattern-sources: - pattern-either: - patterns: - pattern-either: - pattern: flask.request.form.get(...) - pattern: flask.request.form[...] - pattern: flask.request.args.get(...) - pattern: flask.request.args[...] - pattern: flask.request.values.get(...) - pattern: flask.request.values[...] - pattern: flask.request.cookies.get(...) - pattern: flask.request.cookies[...] - pattern: flask.request.stream - pattern: flask.request.headers.get(...) - pattern: flask.request.headers[...] - pattern: flask.request.data - pattern: flask.request.full_path - pattern: flask.request.url - pattern: flask.request.json - pattern: flask.request.get_json() - pattern: flask.request.view_args.get(...) - pattern: flask.request.view_args[...] - patterns: - pattern-inside: | @$APP.route($ROUTE, ...) def $FUNC(..., $ROUTEVAR, ...): ... - focus-metavariable: $ROUTEVAR pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: subprocess.$FUNC(...) - pattern-not: subprocess.$FUNC("...", ...) - pattern-not: subprocess.$FUNC(["...", ...], ...) - pattern-not-inside: | $CMD = ["...", ...] ... subprocess.$FUNC($CMD, ...) - patterns: - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) - metavariable-regex: metavariable: $SHELL regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ - patterns: - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) - metavariable-regex: metavariable: $INTERPRETER regex: ^(python|python\d)$ pattern-sanitizers: - patterns: - pattern: $DICT[$KEY] - focus-metavariable: $KEY severity: ERROR message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. metadata: category: security technology: - flask owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' references: - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ confidence: HIGH cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection shortlink: https://sg.run/5gW3 semgrep.dev: rule: r_id: 31147 rv_id: 1263433 rule_id: 8GU3qp version_id: bZT53gQ url: https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection origin: community - id: yaml.github-actions.security.github-script-injection.github-script-injection languages: - yaml message: 'Using variable interpolation `${{...}}` with `github` context data in a `actions/github-script`''s `script:` step could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment variable, like this: "$ENVVAR".' metadata: category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections - https://securitylab.github.com/research/github-actions-untrusted-input/ - https://github.com/actions/github-script technology: - github-actions cwe2022-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection shortlink: https://sg.run/g1G0 semgrep.dev: rule: r_id: 31441 rv_id: 1423394 rule_id: OrUQvK version_id: 5PT7Zyw url: https://semgrep.dev/playground/r/5PT7Zyw/yaml.github-actions.security.github-script-injection.github-script-injection origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | uses: $ACTION ... - pattern-inside: | with: ... script: ... ... - pattern: 'script: $SHELL' - metavariable-regex: metavariable: $ACTION regex: actions/github-script@.* - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ ... github.event.issue.title ... }} - pattern: ${{ ... github.event.issue.body ... }} - pattern: ${{ ... github.event.pull_request.title ... }} - pattern: ${{ ... github.event.pull_request.body ... }} - pattern: ${{ ... github.event.comment.body ... }} - pattern: ${{ ... github.event.review.body ... }} - pattern: ${{ ... github.event.review_comment.body ... }} - pattern: ${{ ... github.event.pages ... .page_name ... }} - pattern: ${{ ... github.event.head_commit.message ... }} - pattern: ${{ ... github.event.head_commit.author.email ... }} - pattern: ${{ ... github.event.head_commit.author.name ... }} - pattern: ${{ ... github.event.commits ... .author.email ... }} - pattern: ${{ ... github.event.commits ... .author.name ... }} - pattern: ${{ ... github.event.commits ... .message ... }} - pattern: ${{ ... github.event.pull_request.head.ref ... }} - pattern: ${{ ... github.event.pull_request.head.label ... }} - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} - pattern: ${{ ... github.ref ... }} - pattern: ${{ ... github.base_ref ... }} - pattern: ${{ ... github.head_ref ... }} - pattern: ${{ ... github.ref_name ... }} - pattern: ${{ ... github.workflow ... }} - pattern: ${{ ... github.event.inputs ... }} - pattern: ${{ ... github.event.discussion.title ... }} - pattern: ${{ ... github.event.discussion.body ... }} - pattern: ${{ ... github.event.workflow_run.head_branch ... }} - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} - pattern: ${{ ... github.event.milestone.title ... }} - pattern: ${{ ... github.event.milestone.description ... }} - pattern: ${{ ... github.event.project_card.note ... }} - pattern: ${{ ... github.event.project.name ... }} - pattern: ${{ ... github.event.project_column.name ... }} - pattern: ${{ ... github.event.release.name ... }} - pattern: ${{ ... github.event.release.body ... }} - pattern: ${{ ... github.event.deployment.ref ... }} - pattern: ${{ ... inputs ... }} - pattern-not: ${{ ... github.event.issue.title && ... }} - pattern-not: ${{ ... github.event.issue.body && ... }} - pattern-not: ${{ ... github.event.pull_request.title && ... }} - pattern-not: ${{ ... github.event.pull_request.body && ... }} - pattern-not: ${{ ... github.event.comment.body && ... }} - pattern-not: ${{ ... github.event.review.body && ... }} - pattern-not: ${{ ... github.event.review_comment.body && ... }} - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} - pattern-not: ${{ ... github.event.head_commit.message && ... }} - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} - pattern-not: ${{ ... github.event.commits ... .message && ... }} - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} - pattern-not: ${{ ... github.ref && ... }} - pattern-not: ${{ ... github.base_ref && ... }} - pattern-not: ${{ ... github.head_ref && ... }} - pattern-not: ${{ ... github.ref_name && ... }} - pattern-not: ${{ ... github.workflow && ... }} - pattern-not: ${{ ... github.event.inputs && ... }} - pattern-not: ${{ ... github.event.discussion.title && ... }} - pattern-not: ${{ ... github.event.discussion.body && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} - pattern-not: ${{ ... github.event.milestone.title && ... }} - pattern-not: ${{ ... github.event.milestone.description && ... }} - pattern-not: ${{ ... github.event.project_card.note && ... }} - pattern-not: ${{ ... github.event.project.name && ... }} - pattern-not: ${{ ... github.event.project_column.name && ... }} - pattern-not: ${{ ... github.event.release.name && ... }} - pattern-not: ${{ ... github.event.release.body && ... }} - pattern-not: ${{ ... github.event.deployment.ref && ... }} severity: ERROR - id: php.lang.security.injection.echoed-request.echoed-request mode: taint message: '`Echo`ing user input risks cross-site scripting vulnerability. You should use `htmlentities()` when showing data to users.' languages: - php severity: ERROR pattern-sources: - pattern: $_REQUEST - pattern: $_GET - pattern: $_POST pattern-sinks: - pattern: echo $...VARS; pattern-sanitizers: - pattern: htmlentities(...) - pattern: htmlspecialchars(...) - pattern: strip_tags(...) - pattern: isset(...) - pattern: empty(...) - pattern: esc_html(...) - pattern: esc_attr(...) - pattern: wp_kses(...) - pattern: e(...) - pattern: twig_escape_filter(...) - pattern: xss_clean(...) - pattern: html_escape(...) - pattern: Html::escape(...) - pattern: Xss::filter(...) - pattern: escapeHtml(...) - pattern: escapeHtml(...) - pattern: escapeHtmlAttr(...) fix: echo htmlentities($...VARS); metadata: technology: - php cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security references: - https://www.php.net/manual/en/function.htmlentities.php - https://www.php.net/manual/en/reserved.variables.request.php - https://www.php.net/manual/en/reserved.variables.post.php - https://www.php.net/manual/en/reserved.variables.get.php - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request shortlink: https://sg.run/Bqqb semgrep.dev: rule: r_id: 31707 rv_id: 1263283 rule_id: BYUyyg version_id: d6TyxE9 url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request origin: community - id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' languages: - python severity: ERROR metadata: category: security technology: - cryptography cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication shortlink: https://sg.run/N9JL semgrep.dev: rule: r_id: 31871 rv_id: 1263357 rule_id: lBUpNZ version_id: BjTkZj5 url: https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication origin: community patterns: - pattern-either: - patterns: - pattern: | Cipher(..., $HAZMAT_MODE(...),...) - pattern-not-inside: | Cipher(..., $HAZMAT_MODE(...),...) ... HMAC(...) - pattern-not-inside: | Cipher(..., $HAZMAT_MODE(...),...) ... hmac.HMAC(...) - metavariable-pattern: metavariable: $HAZMAT_MODE patterns: - pattern-either: - pattern: modes.CTR - pattern: modes.CBC - pattern: modes.CFB - pattern: modes.OFB - id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' languages: - python severity: ERROR metadata: category: security technology: - cryptography cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication shortlink: https://sg.run/k1K1 semgrep.dev: rule: r_id: 31872 rv_id: 1263556 rule_id: YGUw8w version_id: GxTkeyz url: https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication origin: community patterns: - pattern-either: - patterns: - pattern-either: - pattern: | AES.new(..., $PYCRYPTODOME_MODE) - pattern-not-inside: | AES.new(..., $PYCRYPTODOME_MODE) ... HMAC.new - metavariable-pattern: metavariable: $PYCRYPTODOME_MODE patterns: - pattern-either: - pattern: AES.MODE_CBC - pattern: AES.MODE_CTR - pattern: AES.MODE_CFB - pattern: AES.MODE_OFB - id: java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml patterns: - pattern-inside: | management: ... endpoints: ... web: ... exposure: ... include: ... - pattern: | include: [..., $ACTUATOR, ...] - metavariable-comparison: metavariable: $ACTUATOR comparison: not str($ACTUATOR) in ["health","*"] message: Spring Boot Actuator "$ACTUATOR" is enabled. Depending on the actuator, this can pose a significant security risk. Please double-check if the actuator is needed and properly secured. severity: WARNING languages: - yaml metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators category: security technology: - spring cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml shortlink: https://sg.run/JzKQ semgrep.dev: rule: r_id: 32290 rv_id: 1263078 rule_id: kxUWpX version_id: O9TpxBp url: https://semgrep.dev/playground/r/O9TpxBp/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml origin: community - id: java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled patterns: - pattern: management.endpoints.web.exposure.include=$...ACTUATORS - metavariable-comparison: metavariable: $...ACTUATORS comparison: not str($...ACTUATORS) in ["health","*"] message: Spring Boot Actuators "$...ACTUATORS" are enabled. Depending on the actuators, this can pose a significant security risk. Please double-check if the actuators are needed and properly secured. severity: WARNING languages: - generic options: generic_ellipsis_max_span: 0 metadata: cwe: - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators category: security technology: - spring cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled shortlink: https://sg.run/5g23 semgrep.dev: rule: r_id: 32291 rv_id: 1263079 rule_id: wdUWrZ version_id: e1Tyjqe url: https://semgrep.dev/playground/r/e1Tyjqe/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled origin: community - id: terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging patterns: - pattern: | resource "google_storage_bucket" $ANYTHING { ... } - pattern-not-inside: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n logging {\n log_bucket = ...\n } \n ...\n}\n" message: Ensure bucket logs access. languages: - hcl severity: WARNING metadata: owasp: - A10:2017 - Insufficient Logging & Monitoring - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' technology: - terraform - gcp category: security references: - https://docs.bridgecrew.io/docs/google-cloud-policy-index subcategory: - vuln likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging shortlink: https://sg.run/5g5D semgrep.dev: rule: r_id: 32303 rv_id: 1263813 rule_id: gxUrdg version_id: JdTzxRN url: https://semgrep.dev/playground/r/JdTzxRN/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging origin: community - id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial stream output. Its use is strongly discouraged. ARC4 does not use mode constructions. Use a strong symmetric cipher such as EAS instead. With the `cryptography` package it is recommended to use the `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 shortlink: https://sg.run/xoZL semgrep.dev: rule: r_id: 33630 rv_id: 1263348 rule_id: KxU8gK version_id: QkTGq3Q url: https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) - metavariable-regex: metavariable: $ARC4 regex: ^(ARC4)$ - focus-metavariable: $ARC4 fix: AES - id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish message: Blowfish is a block cipher developed by Bruce Schneier. It is known to be susceptible to attacks when using weak keys. The author has recommended that users of Blowfish move to newer algorithms such as AES. With the `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers - https://tools.ietf.org/html/rfc5469 category: security technology: - cryptography subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish shortlink: https://sg.run/OdzL semgrep.dev: rule: r_id: 33631 rv_id: 1263349 rule_id: qNULvO version_id: 3ZT4XK7 url: https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) - metavariable-regex: metavariable: $BLOWFISH regex: ^(Blowfish)$ - focus-metavariable: $BLOWFISH fix: AES - id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B303 references: - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - cryptography subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM functional-categories: - crypto::search::symmetric-algorithm::cryptography license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 shortlink: https://sg.run/eY88 semgrep.dev: rule: r_id: 33632 rv_id: 1263352 rule_id: lBUopp version_id: JdTzxww url: https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 origin: community severity: WARNING languages: - python patterns: - pattern: cryptography.hazmat.primitives.hashes.$MD5() - metavariable-regex: metavariable: $MD5 regex: ^(MD5)$ - focus-metavariable: $MD5 fix: SHA256 - id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 patterns: - pattern: hashlib.md5(...) - pattern-not: hashlib.md5(..., usedforsecurity=False, ...) message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B303 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.2 Insecure Custom Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - python subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 shortlink: https://sg.run/vYrY semgrep.dev: rule: r_id: 33633 rv_id: 1263536 rule_id: PeU2e2 version_id: kbTzGE1 url: https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 origin: community severity: WARNING languages: - python - id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish shortlink: https://sg.run/dlOE semgrep.dev: rule: r_id: 33634 rv_id: 1263545 rule_id: JDUGnK version_id: ExTExln url: https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.Blowfish.new(...) - pattern: Crypto.Cipher.Blowfish.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des message: Detected DES cipher or Triple DES algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use a secure symmetric cipher from the cryptodome package instead. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des shortlink: https://sg.run/Z5bw semgrep.dev: rule: r_id: 33635 rv_id: 1263546 rule_id: 5rUr73 version_id: 7ZTE3G7 url: https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.DES.new(...) - pattern: Crypto.Cipher.DES.new(...) - pattern: Cryptodome.Cipher.DES3.new(...) - pattern: Crypto.Cipher.DES3.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 message: Detected RC2 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 shortlink: https://sg.run/nAbY semgrep.dev: rule: r_id: 33636 rv_id: 1263547 rule_id: GdUYlW version_id: LjTkgn6 url: https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.ARC2.new(...) - pattern: Crypto.Cipher.ARC2.new(...) - id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, such as GCM. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures bandit-code: B304 references: - https://cwe.mitre.org/data/definitions/326.html - https://www.pycryptodome.org/src/cipher/cipher category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::symmetric-algorithm::pycryptodome - crypto::search::symmetric-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 shortlink: https://sg.run/Eo6N semgrep.dev: rule: r_id: 33637 rv_id: 1263548 rule_id: ReUnEB version_id: 8KT5rXY url: https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 origin: community severity: WARNING languages: - python pattern-either: - pattern: Cryptodome.Cipher.ARC4.new(...) - pattern: Crypto.Cipher.ARC4.new(...) - id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 shortlink: https://sg.run/7JP2 semgrep.dev: rule: r_id: 33638 rv_id: 1263550 rule_id: AbU0Ex version_id: QkTGqD8 url: https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD2.new(...) - pattern: Cryptodome.Hash.MD2.new (...) - id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 shortlink: https://sg.run/Lve6 semgrep.dev: rule: r_id: 33639 rv_id: 1263551 rule_id: BYUJy4 version_id: 3ZT4Xnp url: https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD4.new(...) - pattern: Cryptodome.Hash.MD4.new (...) - id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. metadata: source-rule-url: https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability - http://2012.sharcs.org/slides/stevens.pdf - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html category: security technology: - pycryptodome subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH functional-categories: - crypto::search::hash-algorithm::pycryptodome - crypto::search::hash-algorithm::pycryptodomex license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 shortlink: https://sg.run/85JN semgrep.dev: rule: r_id: 33640 rv_id: 1263552 rule_id: DbUXwo version_id: 44TEjpk url: https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 origin: community options: symbolic_propagation: true severity: WARNING languages: - python pattern-either: - pattern: Crypto.Hash.MD5.new(...) - pattern: Cryptodome.Hash.MD5.new (...) - id: terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 patterns: - pattern: resource - pattern-inside: | resource "google_dns_managed_zone" "..." { ... dnssec_config { ... default_key_specs { ... algorithm = "rsasha1" key_type = "zoneSigning" ... } ... } ... } - pattern-inside: | resource "google_dns_managed_zone" "..." { ... dnssec_config { ... default_key_specs { ... algorithm = "rsasha1" key_type = "keySigning" ... } ... } ... } message: "Ensure that RSASHA1 is not used for the zone-signing and key-signing keys in Cloud DNS DNSSEC\t" metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 shortlink: https://sg.run/bKKW semgrep.dev: rule: r_id: 33670 rv_id: 1263837 rule_id: 7KUZZb version_id: bZT53oD url: https://semgrep.dev/playground/r/bZT53oD/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 origin: community languages: - hcl severity: WARNING - id: terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl patterns: - pattern: resource - pattern-inside: | resource "google_sql_database_instance" "..." { ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... require_ssl = true ... } ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = ... ... } ... } message: Ensure all Cloud SQL database instance requires all incoming connections to use SSL metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl shortlink: https://sg.run/W4Yg semgrep.dev: rule: r_id: 33709 rv_id: 1263873 rule_id: v8Uod5 version_id: pZT033e url: https://semgrep.dev/playground/r/pZT033e/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl origin: community languages: - hcl severity: WARNING - id: terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database patterns: - pattern: resource - pattern-either: - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... authorized_networks { ... value = "0.0.0.0/0" ... } ... } ... } - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... dynamic "authorized_networks" { ... content { ... value = "0.0.0.0/0" ... } ... } ... } ... } message: Ensure that Cloud SQL database Instances are not open to the world metadata: owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' category: security technology: - terraform - gcp references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database shortlink: https://sg.run/0Xv5 semgrep.dev: rule: r_id: 33710 rv_id: 1263876 rule_id: d8U7Ll version_id: jQTn559 url: https://semgrep.dev/playground/r/jQTn559/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database origin: community languages: - hcl severity: WARNING - id: csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding message: You are using the outdated PKCS#1 v1.5 encryption padding for your RSA key. Use the OAEP padding instead. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-780: Use of RSA Algorithm without OAEP' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangeformatter - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangeformatter - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangedeformatter - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangedeformatter subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding shortlink: https://sg.run/GoJ1 semgrep.dev: rule: r_id: 35492 rv_id: 1262625 rule_id: QrU2G5 version_id: bZT53zb url: https://semgrep.dev/playground/r/bZT53zb/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding origin: community languages: - csharp pattern-either: - pattern: (RSAPKCS1KeyExchangeFormatter $FORMATER).CreateKeyExchange(...); - pattern: (RSAPKCS1KeyExchangeDeformatter $DEFORMATER).DecryptKeyExchange(...); - id: php.lang.security.redirect-to-request-uri.redirect-to-request-uri patterns: - pattern-either: - pattern: | header('$LOCATION' . $_SERVER['REQUEST_URI']); - pattern: | header('$LOCATION' . $_SERVER['REQUEST_URI'] . $MORE); - metavariable-regex: metavariable: $LOCATION regex: ^(?i)location:\s*$ message: Redirecting to the current request URL may redirect to another domain, if the current path starts with two slashes. E.g. in https://www.example.com//attacker.com, the value of REQUEST_URI is //attacker.com, and redirecting to it will redirect to that domain. metadata: references: - https://www.php.net/manual/en/reserved.variables.server.php - https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html category: security technology: - php owasp: - A05:2017 - Broken Access Control - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-601: URL Redirection to Untrusted Site (''Open Redirect'')' likelihood: MEDIUM impact: LOW confidence: MEDIUM subcategory: - vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Open Redirect source: https://semgrep.dev/r/php.lang.security.redirect-to-request-uri.redirect-to-request-uri shortlink: https://sg.run/RWl2 semgrep.dev: rule: r_id: 35493 rv_id: 1263299 rule_id: 3qUb4n version_id: A8Tgdvq url: https://semgrep.dev/playground/r/A8Tgdvq/php.lang.security.redirect-to-request-uri.redirect-to-request-uri origin: community languages: - php severity: WARNING - id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout languages: - yaml message: This GitHub Actions workflow file uses `workflow_run` and checks out code from the incoming pull request. When using `workflow_run`, the Action runs in the context of the target repository, which includes access to all repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to make sure no code from the incoming PR is executed. Please see https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. metadata: category: security owasp: A01:2017 - Injection cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM subcategory: - vuln references: - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability technology: - github-actions license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout shortlink: https://sg.run/A0p6 semgrep.dev: rule: r_id: 35494 rv_id: 947046 rule_id: 4bU8E4 version_id: kbTYRwl url: https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout origin: community patterns: - pattern-inside: | on: ... workflow_run: ... ... ... - pattern-inside: | jobs: ... $JOBNAME: ... steps: ... - pattern: | ... uses: "$ACTION" with: ... ref: $EXPR - metavariable-regex: metavariable: $ACTION regex: actions/checkout@.* - metavariable-pattern: language: generic metavariable: $EXPR patterns: - pattern: ${{ github.event.workflow_run ... }} severity: WARNING - id: csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm message: Usage of deprecated cipher algorithm detected. Use Aes or ChaCha20Poly1305 instead. severity: ERROR metadata: likelihood: HIGH impact: MEDIUM confidence: MEDIUM category: security cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.des?view=net-6.0#remarks - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rc2?view=net-6.0#remarks - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aes?view=net-6.0 - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm shortlink: https://sg.run/k8Qo semgrep.dev: rule: r_id: 36772 rv_id: 1262622 rule_id: WAUJr0 version_id: 9lT4bRK url: https://semgrep.dev/playground/r/9lT4bRK/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm origin: community languages: - csharp patterns: - pattern: $KEYTYPE.Create(...); - metavariable-pattern: metavariable: $KEYTYPE pattern-either: - pattern: DES - pattern: RC2 - id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode message: Usage of the insecure ECB mode detected. You should use an authenticated encryption mode instead, which is implemented by the classes AesGcm or ChaCha20Poly1305. severity: WARNING metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode shortlink: https://sg.run/wj9n semgrep.dev: rule: r_id: 36773 rv_id: 1262623 rule_id: 0oUqWP version_id: yeTxpPw url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode origin: community languages: - csharp patterns: - pattern-either: - pattern: ($KEYTYPE $KEY).EncryptEcb(...); - pattern: ($KEYTYPE $KEY).DecryptEcb(...); - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; - metavariable-pattern: metavariable: $KEYTYPE pattern-either: - pattern: SymmetricAlgorithm - pattern: Aes - pattern: Rijndael - pattern: DES - pattern: TripleDES - pattern: RC2 - id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration message: You are using an insecure random number generator (RNG) to create a cryptographic key. System.Random must never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator instead. severity: ERROR metadata: likelihood: HIGH impact: MEDIUM confidence: HIGH category: security cwe: - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key subcategory: - vuln technology: - .net license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration shortlink: https://sg.run/xjrA semgrep.dev: rule: r_id: 36774 rv_id: 1262624 rule_id: KxU3Nq version_id: rxTAK2O url: https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration origin: community languages: - csharp mode: taint pattern-sources: - patterns: - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... - pattern: $KEY pattern-sinks: - pattern-either: - patterns: - pattern: ($KEYTYPE $CIPHER).Key = $SINK; - focus-metavariable: $SINK - metavariable-pattern: metavariable: $KEYTYPE pattern-either: - pattern: SymmetricAlgorithm - pattern: Aes - pattern: Rijndael - pattern: DES - pattern: TripleDES - pattern: RC2 - pattern: new AesGcm(...) - pattern: new AesCcm(...) - pattern: new ChaCha20Poly1305(...) - id: html.security.plaintext-http-link.plaintext-http-link metadata: category: security technology: - html cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures confidence: HIGH subcategory: - vuln references: - https://cwe.mitre.org/data/definitions/319.html likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link shortlink: https://sg.run/RA5q semgrep.dev: rule: r_id: 39193 rv_id: 1262976 rule_id: AbUnNo version_id: xyTjzRL url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link origin: community patterns: - pattern: ... - metavariable-regex: metavariable: $URL regex: ^(?i)http:// message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL if possible. severity: WARNING languages: - html - id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not suitable as a cryptographic signature. Use HMAC instead. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::org.apache.commons owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils shortlink: https://sg.run/AWL2 semgrep.dev: rule: r_id: 39194 rv_id: 1263012 rule_id: BYUGK0 version_id: WrTqK7K url: https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils origin: community patterns: - pattern: | $DU.$GET_ALGO().digest(...) - metavariable-pattern: metavariable: $GET_ALGO pattern: getMd5Digest - metavariable-pattern: metavariable: $DU pattern: DigestUtils - focus-metavariable: $GET_ALGO fix: | getSha512Digest - id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection message: Using input or workflow parameters in here-scripts can lead to command injection or code injection. Convert the parameters to env variables instead. languages: - yaml metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - "A03:2021 \u2013 Injection" confidence: MEDIUM likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://github.com/argoproj/argo-workflows/issues/5061 - https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370 technology: - ci - argo license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection - Command Injection source: https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection shortlink: https://sg.run/yqeZ semgrep.dev: rule: r_id: 40768 rv_id: 1151472 rule_id: 10U0zW version_id: xyTp17z url: https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection origin: community severity: ERROR patterns: - pattern-inside: | apiVersion: $VERSION ... - metavariable-regex: metavariable: $VERSION regex: (argoproj.io.*) - pattern-either: - patterns: - pattern-inside: | command: ... - $LANG ... ... source: $SCRIPT - metavariable-regex: metavariable: $LANG regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* - metavariable-pattern: metavariable: $SCRIPT pattern-either: - pattern-regex: (.*{{.*inputs.parameters.*}}.*) - pattern-regex: (.*{{.*workflow.parameters.*}}.*) - focus-metavariable: $SCRIPT - patterns: - pattern-either: - pattern-inside: | container: ... command: $LANG ... args: $PARAM - pattern-inside: | containerSet: ... containers: - ... command: $LANG ... args: $PARAM - metavariable-regex: metavariable: $LANG regex: .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* - metavariable-pattern: metavariable: $PARAM pattern-either: - pattern-regex: (.*{{.*inputs.parameters.*}}.*) - pattern-regex: (.*{{.*workflow.parameters.*}}.*) - focus-metavariable: $PARAM - id: python.cryptography.security.empty-aes-key.empty-aes-key message: Potential empty AES encryption key. Using an empty key in AES encryption can result in weak encryption and may allow attackers to easily decrypt sensitive data. Ensure that a strong, non-empty key is used for AES encryption. patterns: - pattern: AES.new("",...) languages: - python severity: WARNING metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' - 'CWE-310: Cryptographic Issues' references: - https://cwe.mitre.org/data/definitions/327.html - https://cwe.mitre.org/data/definitions/310.html category: security subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM owasp: A6:2017 misconfiguration functional-categories: - crypto::search::key-length::pycrypto - crypto::search::key-length::pycryptodome technology: - python - pycrypto - pycryptodome license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key shortlink: https://sg.run/zQ9G semgrep.dev: rule: r_id: 44817 rv_id: 946105 rule_id: OrUADK version_id: 8KTKjRg url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key origin: community - id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint patterns: - pattern: | ENTRYPOINT $...VARS - pattern-not-inside: | USER $USER ... fix: | USER non-root ENTRYPOINT $...VARS message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. severity: ERROR languages: - dockerfile metadata: cwe: - 'CWE-269: Improper Privilege Management' category: security technology: - dockerfile confidence: MEDIUM owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://owasp.org/Top10/A04_2021-Insecure_Design subcategory: - audit likelihood: LOW impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint shortlink: https://sg.run/k281 semgrep.dev: rule: r_id: 47272 rv_id: 1262659 rule_id: ReUW9E version_id: o5TbD21 url: https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint origin: community - id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions pattern-either: - pattern: | resource "aws_config_configuration_aggregator" $ANYTHING { ... account_aggregation_source { ... regions = ... ... } ... } - pattern: | resource "aws_config_configuration_aggregator" $ANYTHING { ... organization_aggregation_source { ... regions = ... ... } ... } message: The AWS configuration aggregator does not aggregate all AWS Config region. This may result in unmonitored configuration in regions that are thought to be unused. Configure the aggregator with all_regions for the source. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ subcategory: - audit likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions shortlink: https://sg.run/O6A7 semgrep.dev: rule: r_id: 47275 rv_id: 1263703 rule_id: DbUo7v version_id: A8Tgdwv url: https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions origin: community - id: yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext patterns: - pattern-inside: | containers: ... - pattern-inside: | - $NAME: $CONTAINER ... - pattern: | image: ... ... - pattern-not: | image: ... ... securityContext: ... - metavariable-regex: metavariable: $NAME regex: name - focus-metavariable: $NAME fix: | securityContext: allowPrivilegeEscalation: false $NAME message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. By adding a `securityContext` to your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext shortlink: https://sg.run/eleR semgrep.dev: rule: r_id: 47276 rv_id: 1263931 rule_id: WAU5J6 version_id: 2KTv2j8 url: https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext origin: community languages: - yaml severity: WARNING - id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true patterns: - pattern-inside: | containers: ... - pattern-inside: | - name: $CONTAINER ... - pattern-inside: | image: ... ... - pattern-inside: | securityContext: ... - pattern: | allowPrivilegeEscalation: $TRUE - metavariable-pattern: metavariable: $TRUE pattern: | true - focus-metavariable: $TRUE fix: | false message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. In the container `$CONTAINER` this parameter is set to `true` which makes this container much more vulnerable to privelege escalation attacks. metadata: cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag category: security technology: - kubernetes cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true shortlink: https://sg.run/vw3W semgrep.dev: rule: r_id: 47277 rv_id: 1263932 rule_id: 0oUkqQ version_id: X0Tzyqr url: https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true origin: community languages: - yaml severity: WARNING - id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled patterns: - pattern: | resource "aws_docdb_cluster" $ANYTHING { ... } - pattern-not-inside: | resource "aws_docdb_cluster" $ANYTHING { ... enabled_cloudwatch_logs_exports = [..., "audit", ...] ... } message: Auditing is not enabled for DocumentDB. To ensure that you are able to accurately audit the usage of your DocumentDB cluster, you should enable auditing and export logs to CloudWatch. languages: - hcl severity: INFO metadata: category: security technology: - terraform - aws owasp: - A09:2021 - Security Logging and Monitoring Failures - A09:2025 - Security Logging & Alerting Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled shortlink: https://sg.run/xJYP semgrep.dev: rule: r_id: 48630 rv_id: 1263705 rule_id: AbU1WN version_id: DkTRbA4 url: https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled origin: community - id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags patterns: - pattern: | resource "aws_ecr_repository" $ANYTHING { ... } - pattern-not-inside: | resource "aws_ecr_repository" $ANYTHING { ... image_tag_mutability = "IMMUTABLE" ... } message: The ECR repository allows tag mutability. Image tags could be overwritten with compromised images. ECR images should be set to IMMUTABLE to prevent code injection through image mutation. This can be done by setting `image_tag_mutability` to IMMUTABLE. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software or Data Integrity Failures cwe: - 'CWE-345: Insufficient Verification of Data Authenticity' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags shortlink: https://sg.run/ZEeL semgrep.dev: rule: r_id: 48635 rv_id: 1263716 rule_id: KxUB4o version_id: A8Tgdwd url: https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags origin: community - id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal patterns: - pattern-inside: | resource "aws_ecr_repository_policy" $ANYTHING { ... } - pattern-either: - patterns: - pattern: policy = "$JSONPOLICY" - metavariable-pattern: metavariable: $JSONPOLICY language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], ...} - pattern: | {..., "Principal": { "AWS": "*" }, ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, ...} - patterns: - pattern-inside: policy = jsonencode(...) - pattern-not-inside: | {..., Effect = "Deny", ...} - pattern-either: - pattern: | {..., Principal = "*", ...} - pattern: | {..., Principal = [..., "*", ...], ...} - pattern: | {..., Principal = { AWS = "*" }, ...} - pattern: | {..., Principal = { AWS = [..., "*", ...] }, ...} message: Detected wildcard access granted in your ECR repository policy principal. This grants access to all users, including anonymous users (public access). Instead, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy - https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html - https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html - https://cwe.mitre.org/data/definitions/732.html cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal shortlink: https://sg.run/nzqb semgrep.dev: rule: r_id: 48636 rv_id: 1263717 rule_id: qNUzov version_id: BjTkZ6A url: https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal origin: community languages: - hcl severity: WARNING - id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb pattern: $CIPHER.getInstance("=~/AES/ECB.*/") metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb shortlink: https://sg.run/dB2Y semgrep.dev: rule: r_id: 48734 rv_id: 1263009 rule_id: WAU2yA version_id: A8TgdEo url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb origin: community message: 'Use of AES with ECB mode detected. ECB doesn''t provide message confidentiality and is not semantically secure so should not be used. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish pattern: $CIPHER.getInstance("Blowfish") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish shortlink: https://sg.run/ZE4n semgrep.dev: rule: r_id: 48735 rv_id: 1263010 rule_id: 0oUR28 version_id: BjTkZy0 url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish origin: community message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes it vulnerable to birthday attacks, and is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes pattern-either: - patterns: - pattern-either: - pattern-inside: | import javax; ... - pattern-either: - pattern: javax.crypto.Cipher.getInstance("AES") - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") - patterns: - pattern-either: - pattern-inside: | import javax.*; ... - pattern-inside: | import javax.crypto; ... - pattern-either: - pattern: crypto.Cipher.getInstance("AES") - pattern: (crypto.Cipher $CIPHER).getInstance("AES") - patterns: - pattern-either: - pattern-inside: | import javax.crypto.*; ... - pattern-inside: | import javax.crypto.Cipher; ... - pattern-either: - pattern: Cipher.getInstance("AES") - pattern: (Cipher $CIPHER).getInstance("AES") metadata: functional-categories: - crypto::search::mode::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes shortlink: https://sg.run/nzKO semgrep.dev: rule: r_id: 48736 rv_id: 1263011 rule_id: KxUB7Z version_id: DkTRbwy url: https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes origin: community message: 'Use of AES with no settings detected. By default, java.crypto.Cipher uses ECB mode. ECB doesn''t provide message confidentiality and is not semantically secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 pattern: $CIPHER.getInstance("RC2") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 shortlink: https://sg.run/EEvA semgrep.dev: rule: r_id: 48737 rv_id: 1263014 rule_id: qNUzXG version_id: K3TKkg0 url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 origin: community message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 pattern: $CIPHER.getInstance("RC4") metadata: functional-categories: - crypto::search::symmetric-algorithm::javax.crypto cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security technology: - java references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 shortlink: https://sg.run/7OYR semgrep.dev: rule: r_id: 48738 rv_id: 1263015 rule_id: lBUw8k version_id: qkTR7vk url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 origin: community message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including stream cipher attacks and bit flipping attacks. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' severity: WARNING languages: - java - id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request message: Detected an HTTP request sent via HttpGet. This could lead to sensitive information being sent over an insecure channel. Instead, it is recommended to send requests over HTTPS. severity: WARNING metadata: likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM category: security cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' owasp: A03:2017 - Sensitive Data Exposure references: - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection() subcategory: - vuln technology: - java vulnerability: Insecure Transport license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request shortlink: https://sg.run/QE2q semgrep.dev: rule: r_id: 48942 rv_id: 946061 rule_id: 6JUOJ2 version_id: WrTEo9G url: https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request origin: community languages: - java fix-regex: regex: '[Hh][Tt][Tt][Pp]://' replacement: https:// count: 1 patterns: - pattern: | "=~/[Hh][Tt][Tt][Pp]://.*/" - pattern-inside: | $R = new HttpGet("=~/[Hh][Tt][Tt][Pp]://.*/"); ... $CLIENT. ... .execute($R, ...); - id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted patterns: - pattern: | resource "aws_ebs_volume" $ANYTHING { ... } - pattern-not: | resource "aws_ebs_volume" $ANYTHING { ... encrypted = true ... } message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived snapshots could be read if compromised. Volumes should be encrypted to ensure sensitive data is stored securely. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted shortlink: https://sg.run/6ZbY semgrep.dev: rule: r_id: 50759 rv_id: 1263708 rule_id: YGUKl1 version_id: K3TKk1Z url: https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted origin: community - id: terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled patterns: - pattern: | resource "aws_launch_template" $ANYTHING { ... } - pattern-not-inside: | resource "aws_launch_template" $ANYTHING { ... metadata_options { ... http_endpoint = "disabled" ... } ... } - pattern-not-inside: | resource "aws_launch_template" $ANYTHING { ... metadata_options { ... http_tokens = "required" ... } ... } message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1) enabled. IMDSv2 introduced session authentication tokens which improve security when talking to IMDS. You should either disable IMDS or require the use of IMDSv2. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe: - 'CWE-1390: Weak Authentication' references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled shortlink: https://sg.run/pg9J semgrep.dev: rule: r_id: 50762 rv_id: 1263712 rule_id: zdU0Wo version_id: JdTzx88 url: https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled origin: community - id: terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address patterns: - pattern-either: - pattern: | resource "aws_subnet" $ANYTHING { ... map_public_ip_on_launch = true ... } - pattern: | resource "aws_default_subnet" $ANYTHING { ... } - pattern-not: | resource "aws_default_subnet" $ANYTHING { ... map_public_ip_on_launch = false ... } message: Resources in the AWS subnet are assigned a public IP address. Resources should not be exposed on the public internet, but should have access limited to consumers required for the function of your application. Set `map_public_ip_on_launch` to false so that resources are not publicly-accessible. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#concepts-public-addresses subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address shortlink: https://sg.run/XJZw semgrep.dev: rule: r_id: 50764 rv_id: 1263744 rule_id: 2ZUo79 version_id: d6Tyxdb url: https://semgrep.dev/playground/r/d6Tyxdb/terraform.aws.security.aws-subnet-has-public-ip-address.aws-subnet-has-public-ip-address origin: community - id: clojure.lang.security.use-of-md5.use-of-md5 languages: - clojure severity: WARNING message: MD5 hash algorithm detected. This is not collision resistant and leads to easily-cracked password hashes. Replace with current recommended hashing algorithms. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html technology: - clojure source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' author: Gabriel Marquet category: security subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 shortlink: https://sg.run/BgPx semgrep.dev: rule: r_id: 52195 rv_id: 1262609 rule_id: nJU1ep version_id: 0bTKz2B url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 origin: community pattern-either: - pattern: (MessageDigest/getInstance "MD5") - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) - pattern: (java.security.MessageDigest/getInstance "MD5") - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) - id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak patterns: - pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$ message: Detects potential Google Maps API keys in code languages: - generic severity: WARNING metadata: description: Detects potential Google Maps API keys in code severity: MEDIUM category: security confidence: MEDIUM impact: HIGH likelihood: MEDIUM subcategory: - audit owasp: - A3:2017 Sensitive Data Exposure references: - https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e cwe: - 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory' technology: - Google Maps license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak shortlink: https://sg.run/DL5d semgrep.dev: rule: r_id: 52196 rv_id: 945530 rule_id: EwU3kN version_id: NdTqkGz url: https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak origin: community - id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted patterns: - pattern: | resource "aws_kinesis_stream" $ANYTHING { ... } - pattern-not: | resource "aws_kinesis_stream" $ANYTHING { ... encryption_type = "KMS" ... } message: The AWS Kinesis stream does not encrypt data at rest. The data could be read if the Kinesis stream storage layer is compromised. Enable Kinesis stream server-side encryption. languages: - hcl severity: WARNING metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design cwe: - 'CWE-311: Missing Encryption of Sensitive Data' references: - https://owasp.org/Top10/A04_2021-Insecure_Design - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type - https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted shortlink: https://sg.run/KZ0L semgrep.dev: rule: r_id: 52199 rv_id: 1263728 rule_id: 8GU72N version_id: pZT037O url: https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted origin: community - id: terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal patterns: - pattern-either: - pattern-inside: | resource "aws_sqs_queue_policy" $ANYTHING { ... } - pattern-inside: | resource "aws_sqs_queue" $ANYTHING { ... } - pattern-either: - patterns: - pattern: policy = "$JSONPOLICY" - metavariable-pattern: metavariable: $JSONPOLICY language: json patterns: - pattern-not-inside: | {..., "Effect": "Deny", ...} - pattern-either: - pattern: | {..., "Principal": "*", ...} - pattern: | {..., "Principal": [..., "*", ...], ...} - pattern: | {..., "Principal": { "AWS": "*" }, ...} - pattern: | {..., "Principal": { "AWS": [..., "*", ...] }, ...} - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnNotLike\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnLike\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"ArnEquals\": {\n \"aws:SourceArn\": ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \n\"Condition\": {\n \"StringNotLike\": {\n \ \"aws:PrincipalARN\": ...\n }\n},\n...}\n" - patterns: - pattern-inside: policy = jsonencode(...) - pattern-not-inside: | {..., Effect = "Deny", ...} - pattern-not-inside: "{..., \nCondition = {\n ArnNotLike = {\n \"aws:SourceArn\" = ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n ArnLike = {\n \"aws:SourceArn\" = ...\n }\n},\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n ArnEquals = {\n \"aws:SourceArn\" = ...\n }\n}\n...}\n" - pattern-not-inside: "{..., \nCondition = {\n StringNotLike = {\n \"aws:PrincipalARN\" = ...\n }\n},\n...}\n" - pattern-either: - pattern: | {..., Principal = "*", ...} - pattern: | {..., Principal = [..., "*", ...], ...} - pattern: | {..., Principal = { AWS = "*" }, ...} - pattern: | {..., Principal = { AWS = [..., "*", ...] }, ...} message: Wildcard used in your SQS queue policy principal. This grants access to all users, including anonymous users (public access). Unless you explicitly require anyone on the internet to be able to read or write to your queue, limit principals, actions and resources to what you need according to least privilege. metadata: category: security technology: - aws - terraform owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sqs_queue_policy - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-security-best-practices.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM rule-origin-note: published from /src/aws-sqs-queue-policy-wildcard-principal.yml in None license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal shortlink: https://sg.run/z3eW semgrep.dev: rule: r_id: 53517 rv_id: 1263741 rule_id: PeUl9d version_id: O9TpxgE url: https://semgrep.dev/playground/r/O9TpxgE/terraform.aws.security.aws-sqs-queue-policy-wildcard-principal.aws-sqs-queue-policy-wildcard-principal origin: community languages: - hcl severity: ERROR - id: terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn patterns: - pattern: | resource "aws_lambda_permission" $ANYTHING { ... principal = "$PRINCIPAL" ... } - pattern-not: | resource "aws_lambda_permission" $ANYTHING { ... source_arn = ... ... } - metavariable-regex: metavariable: $PRINCIPAL regex: .*[.]amazonaws[.]com$ message: The AWS Lambda permission has an AWS service principal but does not specify a source ARN. If you grant permission to a service principal without specifying the source, other accounts could potentially configure resources in their account to invoke your Lambda function. Set the source_arn value to the ARN of the AWS resource that invokes the function, eg. an S3 bucket, CloudWatch Events Rule, API Gateway, or SNS topic. languages: - hcl severity: ERROR metadata: category: security technology: - terraform - aws owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' references: - https://cwe.mitre.org/data/definitions/732.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-lambda-permission.html subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn shortlink: https://sg.run/kOP7 semgrep.dev: rule: r_id: 54772 rv_id: 1263732 rule_id: OrU9Ox version_id: 1QTypq5 url: https://semgrep.dev/playground/r/1QTypq5/terraform.aws.security.aws-lambda-permission-unrestricted-source-arn.aws-lambda-permission-unrestricted-source-arn origin: community - id: terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active patterns: - pattern: | resource "aws_lambda_function" $ANYTHING { ... } - pattern-not: | resource "aws_lambda_function" $ANYTHING { ... tracing_config { ... mode = "Active" ... } ... } message: The AWS Lambda function does not have active X-Ray tracing enabled. X-Ray tracing enables end-to-end debugging and analysis of all function activity. This makes it easier to trace the flow of logs and identify bottlenecks, slow downs and timeouts. languages: - hcl severity: INFO metadata: category: security technology: - aws - terraform owasp: - A09:2021 Security Logging and Monitoring Failures cwe: - 'CWE-778: Insufficient Logging' references: - https://cwe.mitre.org/data/definitions/778.html - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function#mode - https://docs.aws.amazon.com/lambda/latest/dg/services-xray.html subcategory: - audit likelihood: LOW impact: LOW confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insufficient Logging source: https://semgrep.dev/r/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active shortlink: https://sg.run/wO2Y semgrep.dev: rule: r_id: 54773 rv_id: 946713 rule_id: eqUl1O version_id: QkTZ6vk url: https://semgrep.dev/playground/r/QkTZ6vk/terraform.aws.security.aws-lambda-x-ray-tracing-not-active.aws-lambda-x-ray-tracing-not-active origin: community - id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization patterns: - pattern-either: - patterns: - pattern-inside: | ObjectMapper $OM = new ObjectMapper(...); ... - pattern-inside: | $OM.enableDefaultTyping(); ... - pattern: $OM.readValue($JSON, ...); - patterns: - pattern-inside: | class $CLASS { ... @JsonTypeInfo(use = Id.CLASS,...) $TYPE $VAR; ... } - metavariable-regex: metavariable: $TYPE regex: (Object|Serializable|Comparable) - pattern: $OM.readValue($JSON, $CLASS.class); - patterns: - pattern-inside: | class $CLASS { ... ObjectMapper $OM; ... $INITMETHODTYPE $INITMETHOD(...) { ... $OM = new ObjectMapper(); ... $OM.enableDefaultTyping(); ... } ... } - pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n" - pattern: $OM.readValue($JSON, ...); message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling default typing is dangerous and can lead to RCE. If an attacker can control `$JSON` it might be possible to provide a malicious JSON which can be used to exploit unsecure deserialization. In order to prevent this issue, avoid to enable default typing (globally or by using "Per-class" annotations) and avoid using `Object` and other dangerous types for member variable declaration which creating classes for Jackson based deserialization. languages: - java severity: WARNING metadata: category: security subcategory: - audit cwe: - 'CWE-502: Deserialization of Untrusted Data' confidence: MEDIUM likelihood: LOW impact: HIGH owasp: - A8:2017 Insecure Deserialization - A8:2021 Software and Data Integrity Failures references: - https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038 - https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 - https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/ technology: - jackson license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization shortlink: https://sg.run/GDop semgrep.dev: rule: r_id: 56948 rv_id: 945724 rule_id: QrUD20 version_id: 2KTYbA9 url: https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization origin: community - id: java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing shortlink: https://sg.run/Gj32 semgrep.dev: rule: r_id: 59048 rv_id: 1263061 rule_id: j2Udpk version_id: YDTZeko url: https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing origin: community message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable to XML external entity attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features `http://xml.org/sax/features/external-general-entities` and `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - The previous links are not meant to be clicked. They are the literal config key values that are supposed to be used to disable these features. For more information, see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = SAXParserFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = SAXParserFactory.newInstance(); static { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newSAXParser(); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); - pattern: | $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); ... $FACTORY.setFeature("http://xml.org/sax/features/external-general-entities",false); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); $FACTORY.newSAXParser(); languages: - java - id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://blog.sonarsource.com/secure-xml-processor - https://xerces.apache.org/xerces2-j/features.html category: security technology: - java - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled shortlink: https://sg.run/1wyQ semgrep.dev: rule: r_id: 59622 rv_id: 1263062 rule_id: v8UeQ1 version_id: 6xT29GK url: https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled origin: community message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable to XML external entity attacks. Disable this by setting the attributes "accessExternalDTD" and "accessExternalStylesheet" to "". mode: taint pattern-sources: - by-side-effect: true patterns: - pattern-either: - pattern: | $FACTORY = TransformerFactory.newInstance(); - patterns: - pattern: $FACTORY - pattern-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... } ... } - pattern-not-inside: | class $C { ... $V $FACTORY = TransformerFactory.newInstance(); static { ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... } ... } pattern-sinks: - patterns: - pattern: $FACTORY.newTransformer(...); pattern-sanitizers: - by-side-effect: true pattern-either: - patterns: - pattern-either: - pattern: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); - pattern: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); - pattern: | $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); - pattern: | $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); - focus-metavariable: $FACTORY - patterns: - pattern-either: - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); ... $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... } ... } - pattern-inside: | class $C { ... $T $M(...) { ... $FACTORY.setAttribute("=~/.*accessExternalDTD.*/", ""); ... $FACTORY.setAttribute("=~/.*accessExternalStylesheet.*/", ""); ... } ... } - pattern: $M($X) - focus-metavariable: $X fix: | $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, ""); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, ""); $FACTORY.newTransformer(...); languages: - java - id: java.android.security.exported_activity.exported_activity patterns: - pattern-not-inside: - pattern-inside: " \n" - pattern-either: - pattern: | - pattern: | ... /> message: The application exports an activity. Any application on the device can launch the exported activity which may compromise the integrity of your application or its data. Ensure that any exported activities do not have privileged access to your application's control plane. languages: - generic severity: WARNING paths: exclude: - sources/ - classes3.dex - '*.so' include: - '*AndroidManifest.xml' metadata: category: security subcategory: - vuln cwe: - 'CWE-926: Improper Export of Android Application Components' confidence: MEDIUM likelihood: MEDIUM impact: MEDIUM owasp: - A5:2021 Security Misconfiguration technology: - Android references: - https://cwe.mitre.org/data/definitions/926.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity shortlink: https://sg.run/eNGZ semgrep.dev: rule: r_id: 60632 rv_id: 945629 rule_id: v8Ul0r version_id: rxT6rGR url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity origin: community - id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile patterns: - pattern: | RUN sudo ... message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can help reduce the potential impact of configuration errors and security vulnerabilities. metadata: category: security technology: - dockerfile cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://cwe.mitre.org/data/definitions/250.html - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile shortlink: https://sg.run/80Q7 semgrep.dev: rule: r_id: 66384 rv_id: 1262661 rule_id: kxUlx1 version_id: pZT03zY url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile origin: community languages: - dockerfile severity: WARNING - id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults message: Potentially sensitive data was observed to be stored in UserDefaults, which is not adequate protection of sensitive information. For data of a sensitive nature, applications should leverage the Keychain. severity: WARNING metadata: likelihood: LOW impact: HIGH confidence: MEDIUM category: security cwe: - 'CWE-311: Missing Encryption of Sensitive Data' masvs: - 'MASVS-STORAGE-1: The app securely stores sensitive data' owasp: - A03:2017 - Sensitive Data Exposure - A04:2021 - Insecure Design - A06:2025 - Insecure Design references: - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html - https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/ subcategory: - vuln technology: - ios - macos license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults shortlink: https://sg.run/qvoO semgrep.dev: rule: r_id: 66512 rv_id: 1263696 rule_id: KxUqoZ version_id: 3ZT4Xy2 url: https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults origin: community languages: - swift options: symbolic_propagation: true patterns: - pattern-either: - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(api_key|apikey)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(api_key|apikey)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ - focus-metavariable: $KEY - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $VALUE regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ - focus-metavariable: $VALUE - patterns: - pattern-either: - pattern: | UserDefaults.standard.set("$VALUE", forKey: "$KEY") - pattern: | UserDefaults.standard.set("$VALUE", forKey: $KEY) - pattern: | UserDefaults.standard.set($VALUE, forKey: "$KEY") - pattern: | UserDefaults.standard.set($VALUE, forKey: $KEY) - metavariable-regex: metavariable: $KEY regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ - focus-metavariable: $KEY - id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request message: Detected input from a HTTPServletRequest going into the environment variables of an 'exec' command. Instead, call the command with user-supplied arguments by using the overloaded method with one String array as the argument. `exec({"command", "arg1", "arg2"})`. languages: - java severity: ERROR mode: taint pattern-sources: - patterns: - pattern-either: - pattern: | (HttpServletRequest $REQ) - patterns: - pattern-inside: | (javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...); ... for (javax.servlet.http.Cookie $COOKIE: $COOKIES) { ... } - pattern: | $COOKIE.getValue(...) pattern-sinks: - patterns: - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); - focus-metavariable: $ENV_ARGS metadata: category: security technology: - java cwe: - 'CWE-454: External Initialization of Trusted Variables or Data Stores' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: false cwe2021-top25: false subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request shortlink: https://sg.run/EJAB semgrep.dev: rule: r_id: 70981 rv_id: 1409391 rule_id: nJULjy version_id: LjTRL6W url: https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request origin: community - patterns: - pattern-either: - pattern: | provisioner "remote-exec" { ... } - pattern: | provisioner "local-exec" { ... } - pattern-inside: | resource "aws_instance" "..." { ... } id: terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec message: Provisioners are a tool of last resort and should be avoided where possible. Provisioner behavior cannot be mapped by Terraform as part of a plan, and execute arbitrary shell commands by design. languages: - terraform severity: WARNING metadata: category: security owasp: - A03:2021 - Injection - A01:2017 - Injection - A05:2025 - Injection cwe: - 'CWE-77: Improper Neutralization of Special Elements used in a Command (''Command Injection'')' - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' subcategory: - audit confidence: HIGH likelihood: HIGH impact: MEDIUM technology: - terraform references: - https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec - https://developer.hashicorp.com/terraform/language/resources/provisioners/local-exec license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection - Other source: https://semgrep.dev/r/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec shortlink: https://sg.run/7EjQ semgrep.dev: rule: r_id: 70982 rv_id: 1263736 rule_id: EwUxO1 version_id: bZT53j1 url: https://semgrep.dev/playground/r/bZT53j1/terraform.aws.security.aws-provisioner-exec.aws-provisioner-exec origin: community - id: terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy metadata: category: security subcategory: - audit likelihood: MEDIUM impact: HIGH confidence: MEDIUM technology: - terraform - aws owasp: - A05:2017 - Sensitive Data Exposure - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control cwe: - 'CWE-1220: Insufficient Granularity of Access Control' references: - https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy - https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy shortlink: https://sg.run/LWlY semgrep.dev: rule: r_id: 70983 rv_id: 1263748 rule_id: 7KU3dr version_id: 7ZTE346 url: https://semgrep.dev/playground/r/7ZTE346/terraform.aws.security.unrestricted-github-oidc-policy.unrestricted-github-oidc-policy origin: community message: '`$POLICY` is missing a `condition` block which scopes users of this policy to specific GitHub repositories. Without this, `$POLICY` is open to all users on GitHub. Add a `condition` block on the variable `token.actions.githubusercontent.com:sub` which scopes it to prevent this.' languages: - hcl severity: WARNING match: where: - metavariable: $IDENTIFIER regex: .*oidc-provider/token\.actions\.githubusercontent\.com all: - inside: | data "aws_iam_policy_document" $POLICY { ... } - | statement { ... principals { ... type = "Federated" identifiers = [..., $IDENTIFIER, ...] } } - not: | statement { ... condition { ... variable = "token.actions.githubusercontent.com:sub" } } - id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe languages: - clojure severity: ERROR metadata: cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration asvs: section: V5 Validation, Sanitization and Encoding control_id: 5.5.2 Insecue XML Deserialization control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention version: '4' references: - https://semgrep.dev/blog/2022/xml-security-in-java - https://semgrep.dev/docs/cheat-sheets/java-xxe/ - https://xerces.apache.org/xerces2-j/features.html source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml category: security technology: - clojure - xml cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe shortlink: https://sg.run/v7An semgrep.dev: rule: r_id: 71533 rv_id: 1262608 rule_id: bwU3Gj version_id: WrTqKyD url: https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe origin: community message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. Without prohibiting external entity declarations, this is vulnerable to XML external entity attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by setting the features "http://xml.org/sax/features/external-general-entities" and "http://xml.org/sax/features/external-parameter-entities" to false. patterns: - pattern-inside: | (ns ... (:require [clojure.xml :as ...])) ... - pattern-either: - pattern-inside: | (def ... ... ( ... )) - pattern-inside: | (defn ... ... ( ... )) - pattern-either: - pattern: (clojure.xml/parse $INPUT) - patterns: - pattern-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ...) - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" false) - pattern-not-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ... (.setFeature "http://xml.org/sax/features/external-general-entities" false) ... (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) ...) - pattern-not-inside: | (doto (javax.xml.parsers.SAXParserFactory/newInstance) ... (.setFeature "http://xml.org/sax/features/external-parameter-entities" false) ... (.setFeature "http://xml.org/sax/features/external-general-entities" false) ...) - id: clojure.lang.security.use-of-sha1.use-of-sha1 languages: - clojure severity: WARNING message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other hash function applications. metadata: references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html technology: - clojure owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' - 'CWE-328: Use of Weak Hash' category: security subcategory: - vuln confidence: HIGH likelihood: MEDIUM impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Insecure Hashing Algorithm source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 shortlink: https://sg.run/dvwX semgrep.dev: rule: r_id: 71534 rv_id: 1262610 rule_id: NbUy12 version_id: K3TKk7E url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 origin: community patterns: - pattern-either: - pattern: (MessageDigest/getInstance $ALGO) - pattern: (java.security.MessageDigest/getInstance $ALGO) - metavariable-regex: metavariable: $ALGO regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) - id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs languages: - generic severity: WARNING message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose your application and its users to compromised code. SRIs allow you to consume specific versions of content where if even a single byte is compromised, the resource will not be loaded. Add an integrity attribute to your - pattern-not: paths: include: - '*.component' - '*.page' - id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute languages: - generic severity: INFO message: Visualforce Pages must have the cspHeader attribute set to true. This attribute is available in API version 55 or higher. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 category: security subcategory: - vuln technology: - salesforce - visualforce cwe2022-top25: true cwe2021-top25: true likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute shortlink: https://sg.run/yoj8 semgrep.dev: rule: r_id: 72424 rv_id: 1262907 rule_id: DbUj7d version_id: RGT0L0r url: https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute origin: community patterns: - pattern: ... - pattern-not: ... - pattern-not: ...... - pattern-not: ...... paths: include: - '*.page' - id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version languages: - generic severity: WARNING message: Visualforce Pages must use API version 55 or higher for required use of the cspHeader attribute set to true. metadata: cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection references: - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm category: security subcategory: - vuln technology: - salesforce - visualforce cwe2022-top25: true cwe2021-top25: true likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version shortlink: https://sg.run/rWr6 semgrep.dev: rule: r_id: 72425 rv_id: 1262908 rule_id: WAUwJW version_id: A8Tgdgn url: https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version origin: community patterns: - pattern-inside: - pattern-either: - pattern-regex: '[>][0-9].[0-9][<]' - pattern-regex: '[>][1-4][0-9].[0-9][<]' - pattern-regex: '[>][5][0-4].[0-9][<]' paths: include: - '*.page-meta.xml' - id: python.django.security.hashids-with-django-secret.hashids-with-django-secret languages: - python message: The Django secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient HashIDs, the salt used to construct them can be recovered. This means the Django secret key can be obtained by attackers, through the HashIDs. metadata: category: security subcategory: - vuln cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - "A02:2021 \u2013 Cryptographic Failures" references: - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY - http://carnage.github.io/2015/08/cryptanalysis-of-hashids technology: - django likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret shortlink: https://sg.run/bxeZ semgrep.dev: rule: r_id: 72426 rv_id: 946163 rule_id: 0oUXqy version_id: 0bT15nn url: https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret origin: community pattern-either: - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) severity: ERROR - id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret languages: - python message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient HashIDs, the salt used to construct them can be recovered. This means the Flask secret key can be obtained by attackers, through the HashIDs. metadata: category: security subcategory: - vuln cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - "A02:2021 \u2013 Cryptographic Failures" references: - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY - http://carnage.github.io/2015/08/cryptanalysis-of-hashids technology: - flask likelihood: LOW impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret shortlink: https://sg.run/N0Rx semgrep.dev: rule: r_id: 72427 rv_id: 946220 rule_id: KxUX3z version_id: 0bT15Px url: https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret origin: community pattern-either: - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) - patterns: - pattern-inside: | $APP = flask.Flask(...) ... - pattern-either: - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) severity: ERROR - id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse metadata: owasp: - A04:2017 - XML External Entities (XXE) - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration cwe: - 'CWE-611: Improper Restriction of XML External Entity Reference' references: - https://docs.python.org/3/library/xml.html - https://github.com/tiran/defusedxml - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing category: security technology: - python cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - XML Injection source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse shortlink: https://sg.run/n3jG semgrep.dev: rule: r_id: 72436 rv_id: 1263541 rule_id: X5Uqnx version_id: vdT06ER url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse origin: community message: The native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and "XML bombs" can cause denial of service. Do not use this library to parse untrusted input. Instead the Python documentation recommends using `defusedxml`. languages: - python severity: ERROR patterns: - pattern: xml.etree.ElementTree.parse($...ARGS) - pattern-not: xml.etree.ElementTree.parse("...") fix: defusedxml.etree.ElementTree.parse($...ARGS) - id: php.lang.security.tainted-exec.tainted-exec mode: taint pattern-sources: - pattern: $_REQUEST - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE pattern-sinks: - pattern: exec(...) - pattern: system(...) - pattern: popen(...) - pattern: passthru(...) - pattern: shell_exec(...) - pattern: pcntl_exec(...) - pattern: proc_open(...) pattern-sanitizers: - pattern: escapeshellarg(...) message: Executing non-constant commands. This can lead to command injection. You should use `escapeshellarg()` when using command. metadata: cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' references: - https://www.stackhawk.com/blog/php-command-injection/ - https://brightsec.com/blog/code-injection-php/ - https://www.acunetix.com/websitesecurity/php-security-2/ category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection cwe2022-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec shortlink: https://sg.run/JAkP semgrep.dev: rule: r_id: 73146 rv_id: 1263300 rule_id: 9AUw06 version_id: BjTkZ4y url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec origin: community languages: - php severity: ERROR - id: php.lang.security.injection.tainted-session.tainted-session severity: WARNING message: Session key based on user input risks session poisoning. The user can determine the key used for the session, and thus write any session variable. Session variables are typically trusted to be set only by the application, and manipulating the session can result in access control issues. metadata: technology: - php category: security cwe: - 'CWE-284: Improper Access Control' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://en.wikipedia.org/wiki/Session_poisoning cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session shortlink: https://sg.run/bxNp semgrep.dev: rule: r_id: 73470 rv_id: 1263289 rule_id: 4bUdoP version_id: 8KT5rPE url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sanitizers: - patterns: - pattern-either: - pattern: $A . $B - pattern: bin2hex(...) - pattern: crc32(...) - pattern: crypt(...) - pattern: filter_input(...) - pattern: filter_var(...) - pattern: hash(...) - pattern: md5(...) - pattern: preg_filter(...) - pattern: preg_grep(...) - pattern: preg_match_all(...) - pattern: sha1(...) - pattern: sprintf(...) - pattern: str_contains(...) - pattern: str_ends_with(...) - pattern: str_starts_with(...) - pattern: strcasecmp(...) - pattern: strchr(...) - pattern: stripos(...) - pattern: stristr(...) - pattern: strnatcasecmp(...) - pattern: strnatcmp(...) - pattern: strncmp(...) - pattern: strpbrk(...) - pattern: strpos(...) - pattern: strripos(...) - pattern: strrpos(...) - pattern: strspn(...) - pattern: strstr(...) - pattern: strtok(...) - pattern: substr_compare(...) - pattern: substr_count(...) - pattern: vsprintf(...) pattern-sinks: - patterns: - pattern-inside: $_SESSION[$KEY] = $VAL; - pattern: $KEY - id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions patterns: - pattern: | "*" - pattern-inside: | resources: $A ... - pattern-inside: | verbs: $A ... - pattern-inside: | - apiGroups: [""] ... - pattern-inside: | apiVersion: rbac.authorization.k8s.io/v1 ... - pattern-inside: | kind: ClusterRole ... message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. Attaching excessive permissions to a ClusterRole associated with the core namespace allows the V1 API to perform arbitrary actions on arbitrary resources attached to the cluster. Prefer explicit allowlists of verbs/resources when configuring the core API namespace. ' languages: - yaml severity: WARNING metadata: cwe: - 'CWE-269: Improper Privilege Management' owasp: - A05:2021 - Security Misconfiguration - A06:2017 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups category: security technology: - kubernetes cwe2021-top25: false subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions shortlink: https://sg.run/x6Dz semgrep.dev: rule: r_id: 73474 rv_id: 1263935 rule_id: GdUR2A version_id: 9lT4bw7 url: https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions origin: community - id: python.fastapi.security.wildcard-cors.wildcard-cors languages: - python message: CORS policy allows any origin (using wildcard '*'). This is insecure and should be avoided. mode: taint pattern-sources: - pattern: '[..., "*", ...]' pattern-sinks: - patterns: - pattern: | $APP.add_middleware( CORSMiddleware, allow_origins=$ORIGIN, ...); - focus-metavariable: $ORIGIN severity: WARNING metadata: cwe: - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration category: security technology: - python - fastapi references: - https://owasp.org/Top10/A05_2021-Security_Misconfiguration - https://cwe.mitre.org/data/definitions/942.html likelihood: HIGH impact: LOW confidence: MEDIUM vulnerability_class: - Configuration subcategory: - vuln license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors shortlink: https://sg.run/KxApY semgrep.dev: rule: r_id: 112311 rv_id: 1263413 rule_id: lBU4JQ3 version_id: A8Tgd1R url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors origin: community - id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Set 'verify' to `true` before using the token. severity: ERROR metadata: owasp: - A05:2021 - Security Misconfiguration - A07:2021 - Identification and Authentication Failures - A02:2025 - Security Misconfiguration - A07:2025 - Authentication Failures cwe: - 'CWE-287: Improper Authentication' - 'CWE-345: Insufficient Verification of Data Authenticity' - 'CWE-347: Improper Verification of Cryptographic Signature' category: security subcategory: - vuln technology: - jwt-simple - jwt confidence: HIGH likelihood: MEDIUM impact: HIGH references: - https://www.npmjs.com/package/jwt-simple - https://cwe.mitre.org/data/definitions/287 - https://cwe.mitre.org/data/definitions/345 - https://cwe.mitre.org/data/definitions/347 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Improper Authentication source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify shortlink: https://sg.run/zdjod semgrep.dev: rule: r_id: 120561 rv_id: 1263191 rule_id: r6UyNLy version_id: 3ZT4Xxv url: https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify origin: community languages: - javascript - typescript patterns: - pattern-inside: | $JWT = require('jwt-simple'); ... - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) - metavariable-pattern: metavariable: $NOVERIFY patterns: - pattern-either: - pattern: | true - pattern: | "..." - id: php.lang.security.injection.printed-request.printed-request mode: taint message: '`Printing user input risks cross-site scripting vulnerability. You should use `htmlentities()` when showing data to users.' languages: - php severity: ERROR pattern-sources: - pattern: $_REQUEST - pattern: $_GET - pattern: $_POST pattern-sinks: - pattern: print($...VARS); pattern-sanitizers: - pattern: htmlentities(...) - pattern: htmlspecialchars(...) - pattern: strip_tags(...) - pattern: isset(...) - pattern: empty(...) - pattern: esc_html(...) - pattern: esc_attr(...) - pattern: wp_kses(...) - pattern: e(...) - pattern: twig_escape_filter(...) - pattern: xss_clean(...) - pattern: html_escape(...) - pattern: Html::escape(...) - pattern: Xss::filter(...) - pattern: escapeHtml(...) - pattern: escapeHtml(...) - pattern: escapeHtmlAttr(...) fix: print(htmlentities($...VARS)); metadata: technology: - php cwe: - 'CWE-79: Improper Neutralization of Input During Web Page Generation (''Cross-site Scripting'')' owasp: - A07:2017 - Cross-Site Scripting (XSS) - A03:2021 - Injection - A05:2025 - Injection category: security references: - https://www.php.net/manual/en/function.htmlentities.php - https://www.php.net/manual/en/reserved.variables.request.php - https://www.php.net/manual/en/reserved.variables.post.php - https://www.php.net/manual/en/reserved.variables.get.php - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cross-Site-Scripting (XSS) source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request shortlink: https://sg.run/QrxEJ semgrep.dev: rule: r_id: 128886 rv_id: 1263284 rule_id: KxUvRBw version_id: ZRTKAk4 url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request origin: community - id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone patterns: - pattern-inside: | &sessions.Options{ ..., SameSite: http.SameSiteNoneMode, ..., } - pattern: | &sessions.Options{ ..., } message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting SameSite to Lax, Strict or Default for enhanced security. metadata: cwe: - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' owasp: - A05:2021 - Security Misconfiguration - A02:2025 - Security Misconfiguration references: - https://pkg.go.dev/github.com/gorilla/sessions#Options category: security technology: - gorilla confidence: MEDIUM subcategory: - audit likelihood: LOW impact: LOW license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cookie Security source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone shortlink: https://sg.run/x8Nwj semgrep.dev: rule: r_id: 133074 rv_id: 1262913 rule_id: YGUpGd4 version_id: K3TKkKB url: https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone origin: community fix-regex: regex: (SameSite\s*:\s+)http.SameSiteNoneMode replacement: \1http.SameSiteDefaultMode severity: WARNING languages: - go - id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx languages: - solidity message: Missing check for 'from' and 'to' being the same before updating balances could lead to incorrect balance manipulation on self-transfers. Include a check to ensure 'from' and 'to' are not the same before updating balances to prevent balance manipulation during self-transfers. severity: ERROR metadata: category: security technology: - blockchain - solidity cwe: 'CWE-682: Incorrect Calculation' subcategory: - vuln confidence: HIGH likelihood: HIGH impact: HIGH owasp: - A7:2021 Identification and Authentication Failures references: - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities - https://x.com/shoucccc/status/1757777764646859121 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx shortlink: https://sg.run/Or6X7 semgrep.dev: rule: r_id: 133075 rv_id: 946620 rule_id: 6JUv7Nz version_id: A8TJzYz url: https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx origin: community patterns: - pattern-either: - pattern: | _balances[$FROM] = $FROM_BALANCE - value; - pattern: | _balances[$TO] = $TO_BALANCE + value; - pattern-not-inside: | if ($FROM != $TO) { ... _balances[$FROM] = $FROM_BALANCE - value; ... _balances[$TO] = $TO_BALANCE + value; ... } - pattern-inside: | function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual { ... } - id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication languages: - yaml message: Basic authentication is considered weak and should be avoided. Use a different authentication scheme, such of OAuth2, OpenID Connect, or mTLS. severity: ERROR patterns: - pattern-inside: | openapi: $VERSION ... components: ... securitySchemes: ... $SCHEME: ... - metavariable-regex: metavariable: $VERSION regex: 3.* - pattern: | type: http ... scheme: basic metadata: category: security subcategory: - vuln technology: - openapi likelihood: MEDIUM impact: HIGH confidence: HIGH cwe: 'CWE-287: Improper Authentication' owasp: - A04:2021 Insecure Design - A07:2021 Identification and Authentication Failures references: - https://cwe.mitre.org/data/definitions/287.html - https://owasp.org/Top10/A04_2021-Insecure_Design/ - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication shortlink: https://sg.run/v8wNW semgrep.dev: rule: r_id: 133077 rv_id: 947072 rule_id: zdUKgEX version_id: 0bT1ErG url: https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication origin: community - id: python.twilio.security.twiml-injection.twiml-injection languages: - python severity: WARNING message: Using non-constant TwiML (Twilio Markup Language) argument when creating a Twilio conversation could allow the injection of additional TwiML commands metadata: cwe: - 'CWE-91: XML Injection' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - python - twilio - twiml confidence: MEDIUM likelihood: HIGH impact: MEDIUM subcategory: - vuln references: - https://codeberg.org/fennix/funjection license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection shortlink: https://sg.run/GdEEy semgrep.dev: rule: r_id: 134692 rv_id: 1263580 rule_id: oqUgjj2 version_id: kbTzGp1 url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection origin: community mode: taint pattern-sources: - pattern: | f"..." - pattern: | "..." % ... - pattern: | "...".format(...) - patterns: - pattern: $ARG - pattern-inside: | def $F(..., $ARG, ...): ... pattern-sanitizers: - pattern: xml.sax.saxutils.escape(...) - pattern: html.escape(...) pattern-sinks: - patterns: - pattern: | $CLIENT.calls.create(..., twiml=$SINK, ...) - focus-metavariable: $SINK - id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded message: A secret is hard-coded in the application. Secrets stored in source code, such as credentials, identifiers, and other types of sensitive data, can be leaked and used by internal or external malicious actors. It is recommended to rotate the secret and retrieve them from a secure secret vault or Hardware Security Module (HSM), alternatively environment variables can be used if allowed by your company policy. severity: WARNING metadata: likelihood: LOW impact: HIGH confidence: MEDIUM category: security subcategory: - vuln cwe: - 'CWE-798: Use of Hard-coded Credentials' cwe2020-top25: true cwe2021-top25: true cwe2022-top25: true owasp: - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures technology: - secrets vulnerability_class: - Hard-coded Secrets source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded shortlink: https://sg.run/qN29x semgrep.dev: rule: r_id: 137856 rv_id: 1263257 rule_id: ReUD6Kg version_id: DkTRbLX url: https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded origin: community languages: - kotlin options: symbolic_propagation: true patterns: - pattern-either: - pattern: '$PASS = env[...] ?: $VALUE' - metavariable-regex: metavariable: $PASS regex: (password|pass|passwd|loginPassword) - metavariable-pattern: language: generic metavariable: $VALUE patterns: - pattern-either: - pattern-regex: ^[A-Za-z0-9/+=]+$ paths: include: - '*build.gradle.kts' - id: php.lang.security.injection.tainted-callable.tainted-callable severity: WARNING message: Callable based on user input risks remote code execution. metadata: technology: - php category: security cwe: - 'CWE-94: Improper Control of Generation of Code (''Code Injection'')' owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://www.php.net/manual/en/language.types.callable.php subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Code Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable shortlink: https://sg.run/YGb33 semgrep.dev: rule: r_id: 141958 rv_id: 1263285 rule_id: 0oULBKK version_id: nWT2L5x url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable origin: community languages: - php mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: file_get_contents('php://input') pattern-sinks: - patterns: - pattern: $CALLABLE - pattern-either: - pattern-inside: $ARRAYITERATOR->uasort($CALLABLE) - pattern-inside: $ARRAYITERATOR->uksort($CALLABLE) - pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...) - pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...) - pattern-inside: $EVLOOP->fork($CALLABLE, ...) - pattern-inside: $EVLOOP->idle($CALLABLE, ...) - pattern-inside: $EVLOOP->prepare($CALLABLE, ...) - pattern-inside: $EVWATCHER->setCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE) - pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE) - pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE) - pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE) - pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE) - pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE) - pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE) - pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE) - pattern-inside: $SQLITE3->setAuthorizer($CALLABLE) - pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE) - pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE) - pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...) - pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...) - pattern-inside: apcu_entry($KEY, $CALLABLE, ...) - pattern-inside: array_filter($ARRAY, $CALLABLE, ...) - pattern-inside: array_map($CALLABLE, ...) - pattern-inside: array_reduce($ARRAY, $CALLABLE, ...) - pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...) - pattern-inside: array_walk($ARRAY, $CALLABLE, ...) - pattern-inside: call_user_func_array($CALLABLE, ...) - pattern-inside: call_user_func($CALLABLE, ...) - pattern-inside: Closure::fromCallable($CALLABLE) - pattern-inside: createCollation($NAME, $CALLABLE) - pattern-inside: eio_grp($CALLABLE, ...) - pattern-inside: eio_nop($PRI, $CALLABLE, ...) - pattern-inside: eio_sync($PRI, $CALLABLE, ...) - pattern-inside: EvPrepare::createStopped($CALLABLE, ...) - pattern-inside: fann_set_callback($ANN, $CALLABLE) - pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...) - pattern-inside: forward_static_call_array($CALLABLE, ...) - pattern-inside: forward_static_call($CALLABLE, ...) - pattern-inside: header_register_callback($CALLABLE) - pattern-inside: ibase_set_event_handler($CALLABLE, ...) - pattern-inside: IntlChar::enumCharTypes($CALLABLE) - pattern-inside: iterator_apply($ITERATOR, $CALLABLE) - pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE) - pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...) - pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE) - pattern-inside: new EvCheck($CALLABLE, ...) - pattern-inside: new EventHttpRequest($CALLABLE, ...) - pattern-inside: new EvFork($CALLABLE, ...) - pattern-inside: new EvIdle($CALLABLE, ...) - pattern-inside: new Fiber($CALLABLE) - pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...) - pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE) - pattern-inside: new Zookeeper($HOST, $CALLABLE, ...) - pattern-inside: ob_start($CALLABLE, ...) - pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE) - pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE) - pattern-inside: readline_completion_function($CALLABLE) - pattern-inside: register_shutdown_function($CALLABLE, ...) - pattern-inside: register_tick_function($CALLABLE, ...) - pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE) - pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...) - pattern-inside: set_error_handler($CALLABLE, ...) - pattern-inside: set_exception_handler($CALLABLE) - pattern-inside: setAuthorizer($CALLABLE) - pattern-inside: spl_autoload_register($CALLABLE, ...) - pattern-inside: uasort($ARRAY, $CALLABLE) - pattern-inside: uksort($ARRAY, $CALLABLE) - pattern-inside: usort($ARRAY, $CALLABLE) - pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE) - pattern-inside: xml_set_default_handler($PARSER, $CALLABLE) - pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE) - pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE) - pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...) - id: javascript.node-crypto.security.aead-no-final.aead-no-final message: The 'final' call of a Decipher object checks the authentication tag in a mode for authenticated encryption. Failing to call 'final' will invalidate all integrity guarantees of the released ciphertext. metadata: cwe: - 'CWE-310: CWE CATEGORY: Cryptographic Issues' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security subcategory: - vuln technology: - node-crypto likelihood: HIGH impact: MEDIUM confidence: HIGH references: - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final shortlink: https://sg.run/r6EEA semgrep.dev: rule: r_id: 146569 rv_id: 1263222 rule_id: 2ZUz884 version_id: zyTb2X0 url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern: | $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) ... $DECIPHER.update(...) - pattern-not-inside: | $DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...) ... $DECIPHER.final(...) - metavariable-regex: metavariable: $ALGO regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ - id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode of operation is missing an expected authentication tag length. If the expected authentication tag length is not specified or otherwise checked, the application might be tricked into verifying a shorter-than-expected authentication tag. This can be abused by an attacker to spoof ciphertexts or recover the implicit authentication key of GCM, allowing arbitrary forgeries. metadata: cwe: - 'CWE-310: CWE CATEGORY: Cryptographic Issues' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures category: security subcategory: - vuln technology: - node-crypto likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM references: - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length shortlink: https://sg.run/NbGG1 semgrep.dev: rule: r_id: 146571 rv_id: 1263223 rule_id: j2UgPP3 version_id: pZT03qd url: https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length origin: community languages: - javascript - typescript severity: ERROR patterns: - pattern: | $CRYPTO.createDecipheriv('$ALGO', $KEY, $IV) - metavariable-regex: metavariable: $ALGO regex: .*(-gcm)$ - id: php.lang.security.injection.tainted-exec.tainted-exec languages: - php severity: WARNING message: User input is passed to a function that executes a shell command. This can lead to remote code execution. metadata: cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' category: security technology: - php owasp: - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/Top10/A03_2021-Injection subcategory: - vuln impact: HIGH likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec shortlink: https://sg.run/kxEEz semgrep.dev: rule: r_id: 146572 rv_id: 1263286 rule_id: 10UOGG5 version_id: ExTExyR url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST - pattern: file_get_contents('php://input') pattern-sanitizers: - patterns: - pattern-either: - pattern: escapeshellcmd(...) - pattern: escapeshellarg(...) pattern-sinks: - patterns: - pattern-either: - pattern: exec(...) - pattern: system(...) - pattern: passthru(...) - patterns: - pattern: proc_open(...) - pattern-not: proc_open([...], ...) - pattern: popen(...) - pattern: expect_popen(...) - pattern: shell_exec(...) - pattern: | `...` - id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false languages: - yaml message: 'Found ''x-openai-isConsequential: false'' in a state-changing HTTP method: $METHOD $PATH. This Action configuration will enable the ''Always Allow'' option for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk of a user selecting the ''Always Allow'' button is that the agent could perform unintended actions on behalf of the user. When working with sensitive functionality, it is always best to include a Human In The Loop (HITL) type of control. Consider the trade-off between security and user friction and then make a risk-based decision about this function.' severity: WARNING pattern-either: - pattern-inside: | post: ... x-openai-isConsequential: false - pattern-inside: | put: ... x-openai-isConsequential: false - pattern-inside: | patch: ... x-openai-isConsequential: false - pattern-inside: | delete: ... x-openai-isConsequential: false metadata: category: security subcategory: - audit technology: - openapi - openai likelihood: HIGH impact: HIGH confidence: HIGH cwe: 'CWE-441: Unintended Proxy or Intermediary (''Confused Deputy'')' owasp: - A04:2021 Insecure Design - LLM08:2023 - Excessive Agency references: - https://platform.openai.com/docs/actions/consequential-flag - https://owasp.org/Top10/A04_2021-Insecure_Design/ - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false shortlink: https://sg.run/x8EEP semgrep.dev: rule: r_id: 146574 rv_id: 947071 rule_id: yyURooD version_id: WrTEZN8 url: https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false origin: community - id: python.lang.security.insecure-uuid-version.insecure-uuid-version patterns: - pattern: uuid.uuid1(...) message: Using UUID version 1 for UUID generation can lead to predictable UUIDs based on system information (e.g., MAC address, timestamp). This may lead to security risks such as the sandwich attack. Consider using `uuid.uuid4()` instead for better randomness and security. metadata: references: - https://www.landh.tech/blog/20230811-sandwich-attack/ cwe: - 'CWE-330: Use of Insufficiently Random Values' owasp: - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.3.2 Insecure UUID Generation control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values version: '4' category: security technology: - python subcategory: - audit likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version shortlink: https://sg.run/BYBgW semgrep.dev: rule: r_id: 148295 rv_id: 1263539 rule_id: kxUd1yD version_id: O9Tpx97 url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version origin: community languages: - python severity: WARNING fix-regex: regex: uuid1 replacement: uuid4 - id: go.lang.security.audit.crypto.sha224-hash.sha224-hash pattern-either: - patterns: - pattern-inside: | import "crypto/sha256" ... - pattern-either: - pattern: | sha256.New224() - pattern: | sha256.Sum224(...) - patterns: - pattern-inside: | import "golang.org/x/crypto/sha3" ... - pattern-either: - pattern: | sha3.New224() - pattern: | sha3.Sum224(...) message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. languages: - go severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' category: security technology: - go references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash shortlink: https://sg.run/ReJwY semgrep.dev: rule: r_id: 151749 rv_id: 1262925 rule_id: GdUvElR version_id: 9lT4b4w url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash origin: community - id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. languages: - java severity: WARNING metadata: functional-categories: - crypto::search::hash-algorithm::javax.crypto owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-328: Use of Weak Hash' asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - java references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 shortlink: https://sg.run/Ab2KQ semgrep.dev: rule: r_id: 151750 rv_id: 1263017 rule_id: ReUDGEz version_id: YDTZewo url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 origin: community pattern-either: - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) - pattern: new org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) - patterns: - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); - metavariable-regex: metavariable: $ALGO regex: .*224 - id: php.lang.security.audit.sha224-hash.sha224-hash pattern-either: - pattern: hash('sha224', ...); - pattern: hash('sha512/224', ...); - pattern: hash('sha3-224', ...); - pattern: hash_hmac('sha224', ...); - pattern: hash_hmac('sha512/224', ...); - pattern: hash_hmac('sha3-224', ...); message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - php owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - audit likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/BYXqv semgrep.dev: rule: r_id: 151751 rv_id: 1263275 rule_id: AbU97EA version_id: bZT53Jo url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash origin: community languages: - php severity: WARNING - id: python.lang.security.audit.sha224-hash.sha224-hash message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - python subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/Db1Yv semgrep.dev: rule: r_id: 151752 rv_id: 1263511 rule_id: BYUX0y9 version_id: 5PTo1QL url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash origin: community severity: WARNING languages: - python pattern-either: - pattern: hashlib.sha224(...) - pattern: hashlib.sha3_224(...) - id: ruby.lang.security.audit.sha224-hash.sha224-hash message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. metadata: cwe: - 'CWE-328: Use of Weak Hash' references: - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography category: security technology: - ruby owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Insecure Hashing Algorithm source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash shortlink: https://sg.run/WABbo semgrep.dev: rule: r_id: 151753 rv_id: 1263592 rule_id: DbU60wQ version_id: 8KT5rRY url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash origin: community languages: - ruby severity: WARNING pattern-either: - pattern: Digest::SHA224.$FUNC - pattern: OpenSSL::Digest::SHA224.$FUNC - pattern: SHA3::Digest::SHA224(...) - patterns: - pattern-either: - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) - pattern: OpenSSL::HMAC.digest("$ALGO", ...) - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") - pattern: OpenSSL::Digest.digest("$ALGO", ...) - pattern: OpenSSL::Digest.new("$ALGO", ...) - metavariable-regex: metavariable: $ALGO regex: .*224 - id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql patterns: - pattern-inside: | resource "google_sql_database_instance" "..." { ... database_version = "$DB" ... } - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = $VALUE ... } ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" ... } ... } - metavariable-regex: metavariable: $DB regex: .*(MYSQL|POSTGRES).* - focus-metavariable: $VALUE fix: | "TRUSTED_CLIENT_CERTIFICATE_REQUIRED" message: Ensure all Cloud SQL database instance require incoming connections to use SSL. To enable this for PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql shortlink: https://sg.run/WANR2 semgrep.dev: rule: r_id: 153509 rv_id: 1263874 rule_id: 5rUdGAz version_id: 2KTv22E url: https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql origin: community languages: - hcl severity: WARNING - id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver patterns: - pattern-inside: | resource "google_sql_database_instance" "..." { ... database_version = "$DB" ... } - pattern-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = $VALUE ... } ... } - pattern-not-inside: | resource "google_sql_database_instance" "..." { ... ip_configuration { ... ssl_mode = "ENCRYPTED_ONLY" ... } ... } - metavariable-regex: metavariable: $DB regex: .*(SQLSERVER).* - focus-metavariable: $VALUE fix: | "ENCRYPTED_ONLY" message: Ensure all Cloud SQL database instance require incoming connections to use SSL. For SQL Server, `ssl_mode="ENCRYPTED_ONLY"` is the most secure value that is supported. metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - gcp references: - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver shortlink: https://sg.run/0o92j semgrep.dev: rule: r_id: 153510 rv_id: 1263875 rule_id: GdUvX6A version_id: X0Tzyyl url: https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver origin: community languages: - hcl severity: WARNING - id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true message: Function `flask.url_for` with `_external=True` argument will generate URLs using the `Host` header of the HTTP request, which may lead to security risks such as Host header injection metadata: cwe: - 'CWE-673: External Influence of Sphere Definition' owasp: - A03:2021 - Injection - A05:2025 - Injection category: security technology: - flask references: - https://flask.palletsprojects.com/en/latest/api/#flask.url_for - https://portswigger.net/kb/issues/00500300_host-header-injection subcategory: - audit likelihood: MEDIUM impact: LOW confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Other source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true shortlink: https://sg.run/gEGeR semgrep.dev: rule: r_id: 191541 rv_id: 1263418 rule_id: JDU5oql version_id: K3TKk6n url: https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true origin: community languages: - python severity: WARNING patterns: - pattern-not: flask.url_for(..., _external=False, ...) - pattern-not: url_for(..., _external=False, ...) - pattern-either: - pattern: flask.url_for(..., _external=$VAR, ...) - pattern: url_for(..., _external=$VAR, ...) - id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit languages: - php severity: WARNING message: Detected usage of vulnerable functions with user input, which could lead to SSRF vulnerabilities. mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET[...] - pattern: $_POST[...] - pattern: $_REQUEST[...] - pattern: get_option(...) - pattern: get_user_meta(...) - pattern: get_query_var(...) pattern-sinks: - patterns: - focus-metavariable: $URL - pattern-either: - pattern: wp_remote_get($URL, ...) - pattern: wp_safe_remote_get($URL, ...) - pattern: wp_safe_remote_request($URL, ...) - pattern: wp_safe_remote_head($URL, ...) - pattern: wp_oembed_get($URL, ...) - pattern: vip_safe_wp_remote_get($URL, ...) - pattern: wp_safe_remote_post($URL, ...) paths: include: - '**/wp-content/plugins/**/*.php' metadata: cwe: 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: A10:2021 - Server-Side Request Forgery (SSRF) category: security confidence: MEDIUM likelihood: MEDIUM impact: HIGH subcategory: - audit technology: - Wordpress Plugins references: - https://developer.wordpress.org/reference/functions/wp_safe_remote_get/ - https://developer.wordpress.org/reference/functions/wp_remote_get/ - https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/ vulnerability_class: - Server-Side Request Forgery (SSRF) license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit shortlink: https://sg.run/K3y06 semgrep.dev: rule: r_id: 191611 rv_id: 1039233 rule_id: 6JUZyKX version_id: JdTp6rq url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit origin: community - id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor languages: - yaml message: The Shai-hulud backdoor creates a purposefully vulnerable github action with the name `discussion.yaml`. paths: include: - '**/.github/workflows/discussion.yaml' metadata: category: security cwe: - 'CWE-509: Replicating Malicious Code (Virus or Worm)' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection technology: - github-actions cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack references: - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor shortlink: https://sg.run/JdYPZ semgrep.dev: rule: r_id: 238946 rv_id: 1263927 rule_id: 7KUDRPj version_id: 6xT29ol url: https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: generic metavariable: $SHELL patterns: - pattern-either: - pattern: ${{ github.event.issue.title }} - pattern: ${{ github.event.issue.body }} - pattern: ${{ github.event.pull_request.title }} - pattern: ${{ github.event.pull_request.body }} - pattern: ${{ github.event.comment.body }} - pattern: ${{ github.event.review.body }} - pattern: ${{ github.event.review_comment.body }} - pattern: ${{ github.event.pages. ... .page_name}} - pattern: ${{ github.event.head_commit.message }} - pattern: ${{ github.event.head_commit.author.email }} - pattern: ${{ github.event.head_commit.author.name }} - pattern: ${{ github.event.commits ... .author.email }} - pattern: ${{ github.event.commits ... .author.name }} - pattern: ${{ github.event.pull_request.head.ref }} - pattern: ${{ github.event.pull_request.head.label }} - pattern: ${{ github.event.pull_request.head.repo.default_branch }} - pattern: ${{ github.head_ref }} - pattern: ${{ github.event.inputs ... }} - pattern: ${{ github.event.discussion.title }} - pattern: ${{ github.event.discussion.body }} - pattern: ${{ inputs ... }} severity: ERROR - id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface languages: - go message: Deserializing into `interface{}` allows arbitrary data structures and types, which can lead to security vulnerabilities (CWE-502). Use a concrete struct type instead. severity: WARNING metadata: cwe: - 'CWE-502: Deserialization of Untrusted Data' owasp: - A08:2017 - Insecure Deserialization - A08:2021 - Software and Data Integrity Failures category: security technology: - go confidence: HIGH likelihood: MEDIUM impact: HIGH subcategory: - vuln references: - https://cwe.mitre.org/data/definitions/502.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - 'Insecure Deserialization ' source: https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface shortlink: https://sg.run/6WbKL semgrep.dev: rule: r_id: 274359 rv_id: 1409387 rule_id: 4bUAQDG version_id: ZRTDkjk url: https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface origin: community patterns: - pattern-either: - pattern: | var $VAR interface{} ... json.Unmarshal($DATA, &$VAR) - pattern: | var $VAR interface{} ... yaml.Unmarshal($DATA, &$VAR) - pattern: | var $VAR interface{} ... xml.Unmarshal($DATA, &$VAR) - id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag message: "GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by the action owner, enabling supply-chain attacks \u2014 as seen in the trivy-action and kics-github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`." severity: WARNING languages: - yaml metadata: category: security cwe: - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' - 'CWE-353: Missing Support for Integrity Check' owasp: - A08:2021 - Software and Data Integrity Failures - A08:2025 - Software and Data Integrity Failures references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues - Other source: https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag shortlink: https://sg.run/2LgAL semgrep.dev: rule: r_id: 288863 rv_id: 1413422 rule_id: GdUxYDx version_id: xyTRDAd url: https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag origin: community patterns: - pattern-inside: '{steps: ...}' - pattern: | uses: "$ACTION" - metavariable-pattern: metavariable: $ACTION language: generic patterns: - pattern-not-regex: ^\./ - pattern-not-regex: ^docker:// - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' - id: yaml.github-actions.security.secrets-inherit.secrets-inherit languages: - yaml severity: ERROR message: 'This workflow uses `secrets: inherit` to pass all of the calling workflow''s secrets to a reusable workflow. This violates the principle of least privilege because the called workflow receives access to every secret in the repository, not just the ones it needs. If the called workflow is compromised or sourced from a third party, an attacker gains access to all repository secrets. Instead, explicitly pass only the secrets that the called workflow requires using the `secrets:` map, e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`.' metadata: category: security cwe: - 'CWE-250: Execution with Unnecessary Privileges' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions technology: - github-actions subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit shortlink: https://sg.run/X2PZB semgrep.dev: rule: r_id: 288864 rv_id: 1413424 rule_id: ReUQnKg version_id: e1T42L1 url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit origin: community patterns: - pattern-inside: | jobs: ... - pattern: 'secrets: inherit' - id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age pattern-either: - patterns: - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) - metavariable-regex: metavariable: $TARGET regex: ^(?![\s\S]*minimumReleaseAge) - focus-metavariable: $TARGET - patterns: - pattern-regex: minimumReleaseAge\s*=\s*\d+ - pattern-regex: =\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 604800 - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ message: 'This bunfig.toml does not set a minimum release age or sets it too low. Newly published packages can be malicious or unstable. Add `minimumReleaseAge = 604800` under the `[install]` section to wait 7 days before resolving newly published package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' languages: - generic severity: MEDIUM paths: include: - '**/bunfig.toml' - '**/.bunfig.toml' metadata: category: security technology: - bun - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://bun.sh/docs/runtime/bunfig license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age shortlink: https://sg.run/JqPrR semgrep.dev: rule: r_id: 291646 rv_id: 1423385 rule_id: oqUyJOb version_id: BjTyRe5 url: https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age origin: community - id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown pattern-either: - patterns: - pattern-inside: | updates: ... - pattern: | - package-ecosystem: $ECOSYSTEM ... - pattern-not: | - package-ecosystem: $ECOSYSTEM ... cooldown: ... ... - patterns: - pattern-inside: | updates: ... - pattern-regex: default-days\s*:\s*(?P\d+) - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-inside: | updates: ... - pattern: | cooldown: default-days: $DAYS - metavariable-regex: metavariable: $DAYS regex: ^\D - focus-metavariable: $DAYS message: 'This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' languages: - yaml severity: MEDIUM paths: include: - '**/.github/dependabot.yml' - '**/.github/dependabot.yaml' metadata: category: security technology: - dependabot cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown shortlink: https://sg.run/5WvGK semgrep.dev: rule: r_id: 291647 rv_id: 1423386 rule_id: zdUArOL version_id: DkTwEGl url: https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown origin: community - id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age pattern-either: - patterns: - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) - pattern-not-regex: min-release-age - focus-metavariable: $TARGET - patterns: - pattern-regex: min-release-age\s*=\s*\d+ - pattern-regex: =\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 7 - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)min-release-age\s*=\s*$ message: 'This .npmrc does not set a minimum release age or sets it too low. Newly published packages can be malicious or unstable. Add `min-release-age = 7` to wait 7 days before resolving newly published package versions. Added in: v11.10 Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' languages: - generic severity: MEDIUM paths: include: - '**/.npmrc' metadata: category: security technology: - npm - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ - https://github.com/npm/cli/pull/8965 license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age shortlink: https://sg.run/GRo1z semgrep.dev: rule: r_id: 291648 rv_id: 1423387 rule_id: pKU6A82 version_id: WrT7LdL url: https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age origin: community - id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` to transitive dependencies from being installed from untrusted sources. Added in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern: | blockExoticSubdeps: $VAL - metavariable-regex: metavariable: $VAL regex: ^(?!true$).+ - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#blockexoticsubdeps license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies shortlink: https://sg.run/RrWRv semgrep.dev: rule: r_id: 291649 rv_id: 1423388 rule_id: 2ZUQEZ5 version_id: 0bTGnwj url: https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies origin: community - id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age message: 'This pnpm workspace configuration does not set a minimum release age. Newly published packages can be malicious or unstable. Add `minimumReleaseAge: 10080` (minutes) to wait at least seven days before installing newly published package versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 10080 - focus-metavariable: $AGE - patterns: - pattern: | minimumReleaseAge: $AGE - metavariable-regex: metavariable: $AGE regex: ^\D - focus-metavariable: $AGE - patterns: - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age shortlink: https://sg.run/Aj0o0 semgrep.dev: rule: r_id: 291650 rv_id: 1423389 rule_id: X5Uwn1n version_id: K3TgxrW url: https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age origin: community - id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent malicious package updates from downgrading security settings. Added in: v10.21.0 Reference: https://pnpm.io/settings#trustpolicy' languages: - yaml severity: MEDIUM paths: include: - '**/pnpm-workspace.yaml' pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern: | trustPolicy: $VAL - metavariable-regex: metavariable: $VAL regex: ^(?!no-downgrade$).+ - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ metadata: category: security technology: - pnpm cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://pnpm.io/settings#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy shortlink: https://sg.run/B2Kz7 semgrep.dev: rule: r_id: 291651 rv_id: 1423390 rule_id: j2U6J8N version_id: qkTvDQn url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy origin: community - id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age pattern-either: - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern-either: - pattern: | { ..., "matchPackageNames": [...], ... } - pattern: | { ..., "matchPackagePatterns": [...], ... } - pattern: | { ..., "matchDepTypes": [...], ... } - pattern-not: | { ..., "minimumReleaseAge": $AGE, ... } - pattern-not: | { ..., "minimumReleaseAge": false, ... } - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' - metavariable-comparison: metavariable: $AGE comparison: int($AGE) < 7 - focus-metavariable: $AGE - patterns: - pattern-inside: | "packageRules": [ ... ] - pattern: | "minimumReleaseAge": "$AGE" - metavariable-regex: metavariable: $AGE regex: ^(?!\d+ days?$) - focus-metavariable: $AGE message: 'This Renovate configuration does not set a minimum release age. Newly published packages can be malicious or unstable. Add `"minimumReleaseAge": "7 days"` within a `packageRules` entry to wait 7 days before proposing updates to newly published package versions. Set `"minimumReleaseAge": false` to set an exception for minimal release age for the package rule. Added in: v42' languages: - json severity: MEDIUM paths: include: - '**/renovate.json' - '**/renovate.json5' - '**/.renovaterc' - '**/.renovaterc.json' - '**/.renovaterc.json5' metadata: category: security technology: - renovate cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.renovatebot.com/configuration-options/#minimumreleaseage license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age shortlink: https://sg.run/D8l2q semgrep.dev: rule: r_id: 291652 rv_id: 1443454 rule_id: 10UbQrX version_id: jQT1KAX url: https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age origin: community - id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown pattern-either: - patterns: - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) - metavariable-regex: metavariable: $TARGET regex: ^(?![\s\S]*exclude-newer) - focus-metavariable: $TARGET - patterns: - pattern-regex: exclude-newer\s*=\s*"(?P\d+) days?" - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" - metavariable-regex: metavariable: $VAL regex: ^(?!\d+ days?$)(?!\d{4}-\d{2}-\d{2}$)(?!\d{4}-\d{2}-\d{2}T) - focus-metavariable: $VAL message: 'This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' languages: - generic severity: MEDIUM paths: include: - '**/pyproject.toml' - '**/uv.toml' metadata: category: security technology: - uv - python cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown shortlink: https://sg.run/WeY0Z semgrep.dev: rule: r_id: 291653 rv_id: 1423392 rule_id: 9AUo6vE version_id: YDTwLle url: https://semgrep.dev/playground/r/YDTwLle/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown origin: community - id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate pattern-either: - patterns: - pattern-regex: (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) - focus-metavariable: $TARGET - patterns: - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? - metavariable-comparison: metavariable: $DAYS comparison: int($DAYS) < 7 - focus-metavariable: $DAYS - patterns: - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) - metavariable-regex: metavariable: $VAL regex: ^(?!['"]?\d+d['"]?$) - focus-metavariable: $VAL - patterns: - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly published packages can be malicious or unstable. Add `npmMinimalAgeGate: "7d"` to wait 7 days before resolving newly published package versions. Added in: 4.10 Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' languages: - yaml severity: MEDIUM paths: include: - '**/.yarnrc.yml' metadata: category: security technology: - yarn - javascript cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: HIGH likelihood: LOW impact: HIGH subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate shortlink: https://sg.run/0gvNq semgrep.dev: rule: r_id: 291654 rv_id: 1423393 rule_id: yyUBeEz version_id: JdTnXlj url: https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate origin: community - id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age message: "This poetry.toml does not set a dependency cooldown via `solver.min-release-age`. Without a cooldown, Poetry may resolve newly published package versions that have not yet been vetted by the community. Supply chain attacks frequently involve publishing a malicious version of a popular package and waiting for it to be pulled in \u2014 most are detected and removed within days. Set `min-release-age = 7` under `[solver]` to require that package versions are at least 7 days old before they are considered during dependency resolution. Added in: v2.4.0" languages: - generic severity: MEDIUM paths: include: - '**/poetry.toml' - '**/config.toml' pattern-either: - pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z) - pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P"[^"]*"|[0-6](?:\s|#|$)|false) metadata: category: security technology: - poetry - python cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: MEDIUM likelihood: LOW impact: MEDIUM subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://python-poetry.org/docs/configuration/#solvermin-release-age license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age shortlink: https://sg.run/JqnYZ semgrep.dev: rule: r_id: 309390 rv_id: 1443453 rule_id: kxUjBPy version_id: X0TYPX6 url: https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age origin: community - id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown below 7 days) allows Bundler to resolve newly published gem versions immediately, before the community has had time to detect malicious releases. The May 2026 RubyGems supply-chain attack demonstrated that threat actors can push compromised gem versions and have them automatically pulled into builds within minutes. Add `cooldown: 7` to each public source declaration so Bundler ignores gem versions published within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org", cooldown: 7`). If you operate an internal or private registry where the supply-chain risk is lower, use `cooldown: 0` as an explicit bypass. Note: this feature requires Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`; `bundle install` with an existing lockfile is unaffected.' languages: - ruby severity: MEDIUM paths: include: - '**/Gemfile' - '**/gems.rb' exclude: - '**/vendor/**' - '**/.bundle/**' pattern-either: - patterns: - pattern: source "...", ... - pattern-not: 'source "...", ..., cooldown: $N, ...' - patterns: - pattern: 'source "...", ..., cooldown: $N, ...' - metavariable-comparison: metavariable: $N comparison: $N > 0 and $N < 7 - focus-metavariable: $N metadata: category: security technology: - bundler - ruby cwe: - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' owasp: - A08:2021 - Software and Data Integrity Failures confidence: MEDIUM likelihood: LOW impact: MEDIUM subcategory: - audit vulnerability_class: - Insecure Configuration references: - https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license source: https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown shortlink: https://sg.run/5Wlkl semgrep.dev: rule: r_id: 309391 rv_id: 1443455 rule_id: wdUzPbP version_id: 1QTEjAN url: https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown origin: community - id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell languages: - yaml message: "A `run:` step pipes the output of `curl` or `wget` directly into a shell interpreter. This is the \"curl | bash\" install pattern \u2014 if the remote server is compromised or the URL is hijacked, an attacker can execute arbitrary code in your CI runner. Consider downloading the file first, verifying its checksum or signature, and then executing it." metadata: category: security cwe: - 'CWE-78: Improper Neutralization of Special Elements used in an OS Command (''OS Command Injection'')' owasp: - A03:2021 - Injection - A03:2025 - Injection references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ technology: - github-actions - bash - curl cwe2021-top25: true cwe2022-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Command Injection source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell shortlink: https://sg.run/GR8K1 semgrep.dev: rule: r_id: 309392 rv_id: 1443456 rule_id: x8UAgrE version_id: 9lT3zYb url: https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell origin: community patterns: - pattern-inside: 'steps: [...]' - pattern-inside: | - run: ... ... - pattern: 'run: $SHELL' - metavariable-pattern: language: bash metavariable: $SHELL patterns: - pattern-either: - pattern: curl ... | $CMD ... - pattern: wget ... | $CMD ... - metavariable-regex: metavariable: $CMD regex: ^(bash|sh|python3?|ruby|perl)$ severity: ERROR - id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret languages: - yaml message: "A secret is exposed in the workflow-level `env:` block, making it available to every job and step in this workflow \u2014 including any untrusted code run in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level `env:` so the secret is only available where it is actually needed." metadata: category: security cwe: - 'CWE-732: Incorrect Permission Assignment for Critical Resource' owasp: - A01:2021 - Broken Access Control - A01:2025 - Broken Access Control references: - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow technology: - github-actions subcategory: - audit likelihood: LOW impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authorization source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret shortlink: https://sg.run/Rrn12 semgrep.dev: rule: r_id: 309393 rv_id: 1443457 rule_id: OrUnq7z version_id: yeTqX9r url: https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret origin: community patterns: - pattern-inside: | env: ... - pattern-regex: \$\{\{\s*secrets\. - pattern-not-inside: 'jobs: ...' severity: WARNING - id: ruby.rails.security.injection.tainted-sql-string.tainted-sql-string languages: - ruby severity: ERROR message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify contents of the database. Instead, use a parameterized query which is available by default in most database engines. Alternatively, consider using an object-relational mapper (ORM) such as ActiveRecord which will protect your queries. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection category: security technology: - rails references: - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: HIGH confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/Y85o semgrep.dev: rule: r_id: 14714 rv_id: 1263667 rule_id: bwU8gl version_id: YDTZeLL url: https://semgrep.dev/playground/r/YDTZeLL/ruby.rails.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: params - pattern: request pattern-sanitizers: - pattern: | $PARAMS.slice(...) pattern-sinks: - patterns: - pattern-either: - patterns: - pattern-either: - patterns: - pattern: | $RECORD.where($X,...) - pattern: | $RECORD.find(..., :conditions => $X,...) - focus-metavariable: $X - patterns: - pattern: | "$SQLVERB#{$EXPR}..." - pattern-not-inside: | $FUNC("...", "...#{$EXPR}...",...) - focus-metavariable: $SQLVERB - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b - patterns: - pattern-either: - pattern: Kernel::sprintf("$SQLSTR", $EXPR) - pattern: | "$SQLSTR" + $EXPR - pattern: | "$SQLSTR" % $EXPR - pattern-not-inside: | $FUNC("...", "...#{$EXPR}...",...) - focus-metavariable: $EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - id: php.lang.security.injection.tainted-sql-string.tainted-sql-string languages: - php severity: ERROR message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) VALUES (?, ?)");`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://owasp.org/www-community/attacks/SQL_Injection category: security technology: - php cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/lZYG semgrep.dev: rule: r_id: 14757 rv_id: 1263290 rule_id: qNUXdL version_id: gETB7vY url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string origin: community mode: taint pattern-sanitizers: - pattern-either: - pattern: mysqli_real_escape_string(...) - pattern: real_escape_string(...) - pattern: $MYSQLI->real_escape_string(...) pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sinks: - pattern-either: - patterns: - pattern: | sprintf($SQLSTR, ...) - metavariable-regex: metavariable: $SQLSTR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - patterns: - pattern: | "...$EXPR..." - metavariable-regex: metavariable: $EXPR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - patterns: - pattern: | "$SQLSTR".$EXPR - metavariable-regex: metavariable: $SQLSTR regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* - id: php.lang.security.injection.tainted-url-host.tainted-url-host languages: - php severity: WARNING message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with this request. They could also probe internal servers or other resources that the server running this code can access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an allowlist for approved hosts, or hardcode the correct host. metadata: cwe: - 'CWE-918: Server-Side Request Forgery (SSRF)' owasp: - A10:2021 - Server-Side Request Forgery (SSRF) - A01:2025 - Broken Access Control references: - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html category: security technology: - php cwe2022-top25: true cwe2021-top25: true subcategory: - vuln impact: MEDIUM likelihood: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Server-Side Request Forgery (SSRF) source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host shortlink: https://sg.run/Y8no semgrep.dev: rule: r_id: 14758 rv_id: 1263291 rule_id: lBU8K1 version_id: QkTGqRd url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: $_GET - pattern: $_POST - pattern: $_COOKIE - pattern: $_REQUEST pattern-sinks: - pattern-either: - patterns: - pattern: | sprintf($URLSTR, ...) - metavariable-pattern: metavariable: $URLSTR language: generic pattern: $SCHEME://%s - patterns: - pattern: | "...{$EXPR}..." - pattern-regex: | .*://\{.* - patterns: - pattern: | "...$EXPR..." - pattern-regex: | .*://\$.* - patterns: - pattern: | "...".$EXPR - pattern-regex: | .*://["'].* - id: php.lang.security.md5-used-as-password.md5-used-as-password severity: WARNING message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can use `password_hash($PASSWORD, PASSWORD_BCRYPT, $OPTIONS);`. languages: - php metadata: cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures references: - https://tools.ietf.org/html/rfc6151 - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords - https://github.com/returntocorp/semgrep-rules/issues/1609 - https://www.php.net/password_hash category: security technology: - md5 subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password shortlink: https://sg.run/66YL semgrep.dev: rule: r_id: 14759 rv_id: 1263294 rule_id: YGUD1O version_id: PkTR37j url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password origin: community mode: taint pattern-sources: - patterns: - pattern-either: - pattern: md5(...) - pattern: hash('md5', ...) pattern-sinks: - patterns: - pattern: $FUNCTION(...) - metavariable-regex: metavariable: $FUNCTION regex: (?i)(.*password.*) - id: java.spring.security.injection.tainted-sql-string.tainted-sql-string languages: - java severity: ERROR message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use prepared statements (`connection.PreparedStatement`) or a safe library. metadata: cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection references: - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html category: security technology: - spring cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: HIGH impact: MEDIUM confidence: MEDIUM interfile: true license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string shortlink: https://sg.run/9rzz semgrep.dev: rule: r_id: 14767 rv_id: 1409396 rule_id: 10UdRR version_id: 44TbKvr url: https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string origin: community options: taint_assume_safe_numbers: true taint_assume_safe_booleans: true interfile: true mode: taint pattern-sources: - patterns: - pattern-either: - pattern-inside: | $METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) { ... } - pattern-inside: | $METHODNAME(..., @$REQ $TYPE $SOURCE,...) { ... } - metavariable-regex: metavariable: $REQ regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) - metavariable-regex: metavariable: $TYPE regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) - focus-metavariable: $SOURCE pattern-sinks: - patterns: - pattern-either: - pattern: | "$SQLSTR" + ... - pattern: | "$SQLSTR".concat(...) - patterns: - pattern-inside: | StringBuilder $SB = new StringBuilder("$SQLSTR"); ... - pattern: $SB.append(...) - patterns: - pattern-inside: | $VAR = "$SQLSTR"; ... - pattern: $VAR += ... - pattern: String.format("$SQLSTR", ...) - patterns: - pattern-inside: | String $VAR = "$SQLSTR"; ... - pattern: String.format($VAR, ...) - pattern-not-inside: System.out.println(...) - pattern-not-inside: $LOG.info(...) - pattern-not-inside: $LOG.warn(...) - pattern-not-inside: $LOG.warning(...) - pattern-not-inside: $LOG.debug(...) - pattern-not-inside: $LOG.debugging(...) - pattern-not-inside: $LOG.error(...) - pattern-not-inside: new Exception(...) - pattern-not-inside: throw ...; - metavariable-regex: metavariable: $SQLSTR regex: (?i)(select|delete|insert|create|update|alter|drop)\b - id: terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version patterns: - pattern-either: - patterns: - pattern: ssl_policy = $ANYTHING - pattern-not-regex: ELBSecurityPolicy-TLS13-1-[23]-[(Res)0-9-]+ - pattern-not-regex: ELBSecurityPolicy-FS-1-2-[(Res)0-9-]+ - patterns: - pattern: protocol = "HTTP" - pattern-not-inside: | resource $ANYTHING $NAME { ... default_action { ... redirect { ... protocol = "HTTPS" ... } ... } ... } - pattern-inside: | resource $RESOURCE $X { ... } - metavariable-pattern: metavariable: $RESOURCE patterns: - pattern-either: - pattern: | "aws_lb_listener" - pattern: | "aws_alb_listener" message: Detected an AWS load balancer with an insecure TLS version. TLS versions less than 1.2 are considered insecure because they can be broken. To fix this, set your `ssl_policy` to `"ELBSecurityPolicy-TLS13-1-2-Res-2021-06"`, or include a default action to redirect to HTTPS. metadata: category: security technology: - terraform - aws owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-326: Inadequate Encryption Strength' references: - https://www.ietf.org/rfc/rfc5246.txt subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version shortlink: https://sg.run/187G semgrep.dev: rule: r_id: 14966 rv_id: 1263747 rule_id: 2ZUP9K version_id: ExTEx0y url: https://semgrep.dev/playground/r/ExTEx0y/terraform.aws.security.insecure-load-balancer-tls-version.insecure-load-balancer-tls-version origin: community languages: - hcl severity: WARNING - id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli mode: taint pattern-sources: - patterns: - pattern: | (string $X) - pattern-not: | "..." pattern-propagators: - pattern: (StringBuilder $B).$ANY(...,(string $X),...) from: $X to: $B pattern-sinks: - patterns: - pattern-either: - patterns: - pattern: | new $PATTERN($CMD,...) - focus-metavariable: $CMD - patterns: - pattern: | $CMD.$PATTERN = $VALUE; - focus-metavariable: $VALUE - metavariable-regex: metavariable: $PATTERN regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ pattern-sanitizers: - pattern-either: - pattern: | $CMD.Parameters.Add(...) - pattern: | $CMD.Parameters.AddRange(...) - pattern: | $CMD.Parameters.AddWithValue(...) - pattern: | $CMD.Parameters[$IDX].Value = ... by-side-effect: true message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL statement are not properly sanitized. Use a prepared statements instead. You can obtain a PreparedStatement using 'SqlCommand' and 'SqlParameter'. metadata: category: security technology: - csharp owasp: - A01:2017 - Injection - A03:2021 - Injection - A05:2025 - Injection cwe: - 'CWE-89: Improper Neutralization of Special Elements used in an SQL Command (''SQL Injection'')' confidence: MEDIUM references: - https://owasp.org/Top10/A03_2021-Injection cwe2022-top25: true cwe2021-top25: true subcategory: - audit likelihood: LOW impact: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - SQL Injection source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli shortlink: https://sg.run/d2Xd semgrep.dev: rule: r_id: 15078 rv_id: 1262648 rule_id: x8UxeP version_id: RGT0LqW url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli origin: community languages: - csharp severity: ERROR - id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret languages: - scala message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' metadata: category: security cwe: - 'CWE-522: Insufficiently Protected Credentials' owasp: - A02:2017 - Broken Authentication - A04:2021 - Insecure Design - A06:2025 - Insecure Design source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ technology: - jwt confidence: HIGH references: - https://owasp.org/Top10/A04_2021-Insecure_Design cwe2021-top25: true subcategory: - audit likelihood: MEDIUM impact: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret shortlink: https://sg.run/Z40o semgrep.dev: rule: r_id: 15079 rv_id: 1263691 rule_id: OrU6W1 version_id: 7ZTE3kr url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret origin: community pattern-either: - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC256("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET); ... } ... } - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC384("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET); ... } ... } - pattern: | com.auth0.jwt.algorithms.Algorithm.HMAC512("..."); - pattern: | $SECRET = "..."; ... com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); - pattern: | class $CLASS { ... $DECL $SECRET = "..."; ... def $FUNC (...): $RETURNTYPE = { ... com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET); ... } ... } severity: ERROR - id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled message: Enabling authentication ensures that all communications in the application are authenticated. The `auth_settings` block needs to be filled out with the appropriate auth backend settings patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... auth_settings { ... enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... auth_settings { ... enabled = false ... } ... } metadata: cwe: - 'CWE-287: Improper Authentication' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled shortlink: https://sg.run/JxYw semgrep.dev: rule: r_id: 15102 rv_id: 1263755 rule_id: 0oU23p version_id: PkTR3P8 url: https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 message: Use the latest version of HTTP to ensure you are benefiting from security fixes. Add `http2_enabled = true` to your appservice resource block patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... site_config { ... http2_enabled = true ... } ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... site_config { ... http2_enabled = false ... } ... } metadata: cwe: - 'CWE-444: Inconsistent Interpretation of HTTP Requests (''HTTP Request/Response Smuggling'')' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled owasp: - A04:2021 - Insecure Design - A06:2025 - Insecure Design subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Validation source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 shortlink: https://sg.run/5DkA semgrep.dev: rule: r_id: 15103 rv_id: 1263756 rule_id: KxU7LJ version_id: JdTzx98 url: https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 origin: community languages: - hcl severity: INFO - id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only message: By default, clients can connect to App Service by using both HTTP or HTTPS. HTTP should be disabled enabling the HTTPS Only setting. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... https_only = true ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... https_only = false ... } metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only shortlink: https://sg.run/GOKp semgrep.dev: rule: r_id: 15104 rv_id: 1263757 rule_id: qNUXwx version_id: 5PTo1gg url: https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert message: Detected an AppService that was not configured to use a client certificate. Add `client_cert_enabled = true` in your resource block. patterns: - pattern: resource - pattern-not-inside: | resource "azurerm_app_service" "..." { ... client_cert_enabled = true ... } - pattern-either: - pattern-inside: | resource "azurerm_app_service" "..." { ... } - pattern-inside: | resource "azurerm_app_service" "..." { ... client_cert_enabled = false ... } metadata: cwe: - 'CWE-295: Improper Certificate Validation' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled owasp: - A03:2017 - Sensitive Data Exposure - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures subcategory: - vuln likelihood: MEDIUM impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert shortlink: https://sg.run/RX1O semgrep.dev: rule: r_id: 15105 rv_id: 1263758 rule_id: lBU8D6 version_id: GxTkedE url: https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert origin: community languages: - hcl severity: INFO - id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version = "1.2"` in your resource block. patterns: - pattern: min_tls_version = $ANYTHING - pattern-inside: | resource "azurerm_app_service" "$NAME" { ... } - pattern-not-inside: min_tls_version = "1.2" metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy shortlink: https://sg.run/AXRp semgrep.dev: rule: r_id: 15106 rv_id: 1263759 rule_id: YGUDbZ version_id: RGT0L4x url: https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy origin: community languages: - hcl severity: ERROR - id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https message: Detected a Storage that was not configured to deny action by default. Add `enable_https_traffic_only = true` in your resource block. patterns: - pattern-not-inside: | resource "azurerm_storage_account" "..." { ... enable_https_traffic_only = true ... } - pattern-inside: | resource "azurerm_storage_account" "..." { ... enable_https_traffic_only = false ... } metadata: cwe: - 'CWE-319: Cleartext Transmission of Sensitive Information' category: security technology: - terraform - azure references: - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only - https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Mishandled Sensitive Information source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https shortlink: https://sg.run/0y9v semgrep.dev: rule: r_id: 15110 rv_id: 1263805 rule_id: pKUpDA version_id: BjTkZ0A url: https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https origin: community languages: - hcl severity: WARNING - id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind metadata: cwe: - 'CWE-287: Improper Authentication' owasp: - A02:2017 - Broken Authentication - A07:2021 - Identification and Authentication Failures - A07:2025 - Authentication Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS category: security technology: - kotlin references: - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures cwe2022-top25: true cwe2021-top25: true subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Improper Authentication source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind shortlink: https://sg.run/rY2n semgrep.dev: rule: r_id: 15125 rv_id: 1263258 rule_id: v8U9Q7 version_id: WrTqKgJ url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind origin: community message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP statements. Consider enforcing authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html for more information. severity: WARNING pattern: | $ENV.put($CTX.SECURITY_AUTHENTICATION, "none") ... $DCTX = InitialDirContext($ENV, ...) languages: - kt - id: kotlin.lang.security.use-of-sha1.use-of-sha1 message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. languages: - kt severity: WARNING metadata: owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures cwe: - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' category: security technology: - kotlin references: - https://owasp.org/Top10/A02_2021-Cryptographic_Failures subcategory: - vuln likelihood: LOW impact: MEDIUM confidence: MEDIUM license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1 shortlink: https://sg.run/N1pp semgrep.dev: rule: r_id: 15127 rv_id: 1263268 rule_id: ZqUOdd version_id: 2KTv2XZ url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1 origin: community pattern-either: - patterns: - pattern: | $VAR = $MD.getInstance("$ALGO") - metavariable-regex: metavariable: $ALGO regex: (SHA1|SHA-1) - pattern: | $DU.getSha1Digest().digest(...) - id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key message: RSA keys should be at least 2048 bits based on NIST recommendation. languages: - kt severity: WARNING metadata: cwe: - 'CWE-326: Inadequate Encryption Strength' owasp: - A03:2017 - Sensitive Data Exposure - A02:2021 - Cryptographic Failures - A04:2025 - Cryptographic Failures source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE asvs: section: V6 Stored Cryptography Verification Requirements control_id: 6.2.5 Insecure Algorithm control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms version: '4' references: - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms category: security technology: - kotlin subcategory: - audit likelihood: HIGH impact: MEDIUM confidence: HIGH license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license vulnerability_class: - Cryptographic Issues source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key shortlink: https://sg.run/krq7 semgrep.dev: rule: r_id: 15128 rv_id: 1263269 rule_id: nJUZNL version_id: X0TzypE url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key origin: community patterns: - pattern-either: - pattern: | $KEY = $G.getInstance("RSA") ... $KEY.initialize($BITS) - metavariable-comparison: metavariable: $BITS comparison: $BITS < 2048